Penetration-test PLANNER. Reads confirmed scope and recon results, returns a structured deployment plan (which executors, against which surfaces, in what order, with time allocation and escalation directives). Does NOT deploy executors.
High-fidelity external attack-path agent for Tenable Cloud Security: running, internet-exposed workloads with a reachable service, an exploitable publicly-evidenced vulnerability (EPSS or CISA KEV), tiered by identity blast radius.
Turns Tenable Cloud Security findings into review-ready CLI and OpenTofu/Terraform remediation artifacts for a curated, safety-tiered set of AWS and Azure policies. Never modifies your cloud.
Maps a list of security findings to compliance framework control IDs. Use this agent when you have findings from a security review and need to produce a compliance matrix or determine which controls are violated. Delegate with: "compliance-mapper: map these findings to PCI-DSS and HIPAA".
Formats security findings into a structured report (markdown or JSON). Use this agent after a security review to produce a clean, shareable report. Delegate with: "report-generator: format these findings as markdown" or "report-generator: generate JSON output for Jira integration".
Deep security analysis agent for a specific IaC file or module. Use this agent when you need focused, thorough analysis of a single file or tightly scoped module rather than a broad directory scan. Delegate to this agent with: "Use the security-reviewer agent to analyze terraform/vpc.tf" or "security-reviewer: checkβ¦