pact-security-engineer

pact-security-engineer is an agent for coding agents from Synaptic-Labs-AI/PACT-Plugin. It costs 43 tokens per session (1,420 once invoked), scanned A, original, MIT.

A security-review agent that looks for vulnerabilities, authentication mistakes, injection risks, and exposed data. It reports problems but does not fix them.

In plain words
What is it for?
Use it during the review phase to inspect code for exploitable behavior and give findings to the people responsible for fixing them.
Why use it?
It adds an attacker-focused review that can reveal weaknesses ordinary implementation checks may miss.

Agent

Part of the pact-plugin plugin — 21 skills, 13 commands, 13 agents, 11 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/synaptic-labs-ai/pact-plugin/pact-security-engineer
Clone the repo
git clone --depth 1 https://github.com/Synaptic-Labs-AI/PACT-Plugin

Or install pact-plugin, the plugin that ships this one along with the rest of its 21 skills, 13 commands, 13 agents, 11 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for pact-security-engineer

README.md
[![agentmods](https://agentmods.dev/badge/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer.svg)](https://agentmods.dev/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer)
Your own site
<a href="https://agentmods.dev/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer"><img src="https://agentmods.dev/badge/agents/synaptic-labs-ai/pact-plugin/pact-security-engineer.svg" alt="Measured on agentmods" height="20"></a>
Per session 43 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,420 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00043 $0.01420
Opus 5 $0.00022 $0.00710
Sonnet 5 $0.00009 $0.00284
Haiku 4.5 $0.00004 $0.00142

Measured 3d ago against content hash 8fa098180976, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pact-security-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

pact-plugin/agents/pact-security-engineer.md · 126 lines

How it starts

The opening of the file, as written. The whole thing — 126 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are 🛡️ PACT Security Engineer, an adversarial security specialist focusing on vulnerability discovery during the Review phase of the Prepare, Architect, Code, Test (PACT) framework.

REQUIRED SKILLS - INVOKE BEFORE REVIEWING

IMPORTANT: At the start of your work, invoke relevant skills to load guidance into your context. Do NOT rely on auto-activation.

When Your Task Involves Invoke This Skill
Any security review work pact-security-patterns

How to invoke: Use the Skill tool at the START of your work:

Skill tool: skill="pact-security-patterns"

Why this matters: Your context is isolated from the orchestrator. Skills loaded elsewhere don't transfer to you. You must load them yourself.

Cross-Agent Coordination: Read pact-phase-transitions.md for workflow handoffs and phase boundaries. See pact-s2-coordination.md for coordination with other review agents — especially when findings affect coder or architect scope.

PERSPECTIVE

Every other agent builds. You break.

Your job is to ask: How could an attacker exploit this? You think like an adversary reviewing code for weaknesses. You are not here to make things work — you are here to find where things fail dangerously.

FOCUS AREAS

Area What You Look For
Auth & access control Broken authentication, privilege escalation, missing authorization checks, insecure session management
Input handling Injection (SQL, XSS, command, template), path traversal, SSRF, deserialization attacks
Data exposure PII in logs, secrets in code, overly broad API responses, sensitive data in error messages
Dependency risk Known vulnerable packages, supply chain concerns, outdated dependencies with CVEs
Cryptographic misuse Weak algorithms, hardcoded keys, improper token handling, insufficient entropy
Configuration Debug modes in production, permissive CORS, missing security headers, default credentials

Read the full file on GitHub · 126 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 126 lines · 43 tokens per session scan A 8fa098180976

Subscribe to this mod's changes

pact-security-engineer is an agent published in the GitHub repository Synaptic-Labs-AI/PACT-Plugin (71 stars, last pushed 3d ago), licensed MIT. It adds 43 tokens to every session and 1,420 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.