audit agents

128 tagged audit, measured the same way as everything else here.

Browse within: compliance 18cmmc 14code audit 14code-quality 14devsecops 14fedramp 14github-copilot 14automation-framework 10compliance-as-code 10continuous-delivery 10devops-platform 10admin-dashboard 9authentication 9authorization 9

security-reviewer

01

rohitg00/skillkit

Agent

Security vulnerability detection and remediation specialist. OWASP Top 10, secrets, injection.

1.5k 3mo ago A 20 tokens original Apache-2.0

agent-review

02

stencila/stencila

Agent

Critically review a Stencila agent and suggest improvements. Use when asked to review, audit, critique, evaluate, or improve an agent directory or AGENT.md file. Covers frontmatter validation, system instruction quality, configuration correctness, and adherence to the Agent schema.

900 2d ago A 54 tokens original Apache-2.0

yonatangross/orchestkit

Agent

Code quality reviewer: bug detection, security vulnerabilities, performance issues, linting, type checking, test coverage.

224 yesterday A 27 tokens original MIT

learning-curator

04

tacoda/keystone

Agent

Captures a learning candidate from a surprise, incident, or review finding into .charter/learning/inbox/.

44 2mo ago A 23 tokens original MIT

go-cli-ux

05

ready-to-release/eac

Agent Claude Code

Design and implement CLI user experience, commands, flags, and output formatting.

28 today A 19 tokens

go-debugger

06

ready-to-release/eac

Agent Claude Code

Debug Go code, investigate failures, trace issues, analyze performance.

28 today A 16 tokens

compliance-advisor

08

airblackbox/airblackbox

Agent

EU AI Act compliance advisor that analyzes scan results, prioritizes remediation, and helps implement fixes. Invoke when reviewing AIR Blackbox output or planning compliance work.

22 2d ago A 36 tokens original Apache-2.0

bundle_audit_agent

09

rubyroidlabs/rails-audit-skill

Agent

You are a subagent responsible for scanning a Rails application's Gemfile.lock for known security vulnerabilities using bundler-audit. Follow the steps below in order. Return the results as described in the Output section.

14 20d ago A 0 tokens original MIT

debride_agent

10

rubyroidlabs/rails-audit-skill

Agent

You are a subagent responsible for detecting potentially dead (uncalled) methods in a Rails application using Debride. Debride is a static analysis tool — it finds methods that appear to never be called. Follow the steps below in order. Return the results as described in the Output section.

14 20d ago A 0 tokens original MIT

gitleaks_agent

11

rubyroidlabs/rails-audit-skill

Agent

You are a subagent responsible for scanning a project's git history for secrets (passwords, API keys, tokens, etc.) using Gitleaks. Gitleaks is a system-level tool, not a Ruby gem — it's installed via package manager or direct binary download. Follow the steps below in order. Return the results as described in the…

14 20d ago A 0 tokens original MIT

builder

12

enmanuelmag/heimdall-mcp

Agent Claude Code

Use this agent to implement code changes for a task that has already been planned by lead and analyzed by explorer. The builder writes, edits, and creates files based on the plan and the explorer's analysis. Invoke only after the explorer has completed its action. Never invoke without a lead plan and explorer analysis…

11 1mo ago A 69 tokens

lead

13

enmanuelmag/heimdall-mcp

Agent Claude Code

Use this agent to orchestrate a full task from the harness backlog: decompose it into a plan, delegate to explorer, builder, and reviewer in sequence, and close the session correctly. Invoke when starting a new work session, picking up a pending task, or when another agent reports a blocker that requires…

11 1mo ago A 67 tokens

reviewer

14

enmanuelmag/heimdall-mcp

Agent Claude Code

Use this agent to verify that a completed implementation meets all acceptance criteria for the current task. The reviewer reads the full action history, checks the builder's changes against each criterion, runs the health check, and either approves or blocks with specific, actionable feedback. Invoke only after the…

11 1mo ago A 64 tokens

a11y-auditor

15

berrzebb/quorum

Agent

Accessibility Auditor — performs static code analysis for WCAG 2.1 AA compliance, aria attributes, semantic HTML, and keyboard support. Activated when accessibility domain is detected. NOTE — this is STATIC analysis only; runtime browser testing is handled by ui-reviewer.

10 4mo ago A 59 tokens original MIT

scout

16

berrzebb/quorum

Agent

Read-only RTM generator — reads all track work-breakdowns, verifies each requirement against the actual codebase using deterministic tools, and produces 3 Requirements Traceability Matrices (Forward, Backward, Bidirectional). Use when the orchestrator needs to establish or update the RTM before distributing work.

10 4mo ago A 63 tokens original MIT

ui-reviewer

17

berrzebb/quorum

Agent

Find UI issues that code-level analysis (scout, codemap, dependencygraph) cannot detect. Launches a real browser to check rendering, visual states, interactions, a11y, and runtime errors. Use after FE implementation to catch issues invisible to static analysis.

10 4mo ago A 58 tokens original MIT

codex

18

Stahl-G/briefloop

Agent

The active Codex ControlStore runtime kit lives in src/multiagentbrief/runtimekits/codex/ and is installed into workspaces by briefloop runtime install --runtime codex. Its agent inventory is hash-bound into the Store adapter binding.

9 3d ago A 0 tokens original MIT

harness-subagents

19

Stahl-G/briefloop

Agent

Agent "harness-subagents" from Stahl-G/briefloop, covering harness subagents, 1. draft audit harness, 2. final delivery harness and rule.

9 3d ago A 0 tokens original MIT

manifest

20

Stahl-G/briefloop

Agent

Agent "manifest" from Stahl-G/briefloop, covering agent roles manifest, schema, structure, subagent workflow and subagent workflow roles.

9 3d ago A 0 tokens original MIT

skill-analyzer

21

VersoXBT/skill-manager

Agent

Deep analysis agent for skill quality review. Reviews skill content, instruction clarity, trigger phrase effectiveness, and provides actionable improvement suggestions.

6 4mo ago A 29 tokens original MIT

release-manager

22

nerviq/nerviq

Agent Claude Code

Checks release readiness and packaging consistency.

6 1mo ago A 9 tokens original MIT

openrouter

24

l-agence/agence

Agent

Describe what this custom agent does and when to use it.

4 3mo ago A 15 tokens