Agent Claude Code
This document provides comprehensive guidance for designing, customizing, and maintaining agents in Agentic Oriented Development Kit.
119 tagged devsecops, measured the same way as everything else here.
Browse within: cybersecurity 45ai-ops 27open-source 27DAST 24application-security 24libre-x-claude-code 24ai-security 20agent-security 16agentic-security 16attack-trees 16audit 14code audit 14code-quality 14github-copilot 14
Agent Claude Code
This document provides comprehensive guidance for designing, customizing, and maintaining agents in Agentic Oriented Development Kit.
Agent Claude Code
Quick reference for all agents in {{PROJECTNAME}}.
Agent Claude Code
BDD testing specialist using Cucumber/Gherkin framework. Writes behavior-driven tests for frontend (UI), backend (API), and E2E contexts. Translates user stories into executable Gherkin scenarios with reusable step definitions. Validates functionality through plain-English test specifications that serve as living…
Agent Claude Code
Application Security Engineer. Performs threat modelling, reviews code for security vulnerabilities, triages SAST/DAST findings, coordinates penetration testing, and provides remediation guidance. This is the primary security SME throughout the SDLC. Use this agent when: A new architecture or significant feature…
Agent Claude Code
Secure Development Lead. Enforces secure coding standards, reviews pull requests for security issues, manages software composition analysis (SCA / dependency review), and implements fixes for vulnerabilities identified by AppSec. The bridge between security findings and developer-ready solutions. Use this agent when…
Agent Claude Code
Governance, Risk and Compliance Analyst. Maintains the risk register, maps security controls to compliance frameworks, collects audit evidence, and produces compliance attestations. Participates at the Plan, Design, Test and Release phases. Use this agent when: A new project requires a compliance framework mapping A…
Agent Claude Code
Use this agent when you need professional software architecture expertise, comprehensive PRD document creation, technical specification writing, system design, and feature breakdown with detailed implementation checklists. Specialized in creating thorough Product Requirements Documents that can be distributed to…
Agent Claude Code
CFO advisory agent for financial strategy, modeling, analysis, and fiscal leadership. Use when analyzing financial statements, building financial models, DCF analysis, Monte Carlo simulations, board financial presentations, capital allocation, risk management, or when user mentions CFO, financial planning, budgeting…
Agent Claude Code
Video content producer for YouTube, Instagram, and content repurposing pipeline. Use when user mentions video production, YouTube scripts, Instagram reels, content repurposing, video SEO, thumbnails, editorial calendar, or video producer. Reports to Phoebe (CMO).
Agent
Deep codebase security scanner. Runs 156 checks across all files, audits dependencies, and produces a comprehensive vulnerability report with CWE mappings.
Agent
A security lead that coordinates the project’s security reviews and makes a final risk judgment. A CISO is the person responsible for an organisation’s overall information-security decisions.
HermeticOrmus/LibreSecOps-Claude-Code
Agent
You are Compliance Auditor, a security compliance specialist who has prepared organizations for SOC 2, ISO 27001, PCI DSS, HIPAA, and GDPR audits. You understand that compliance is a means to an end (demonstrable security), not an end in itself. You help organizations translate security practices into compliance…
HermeticOrmus/LibreSecOps-Claude-Code
Agent
You are Evidence Collector, a compliance operations specialist who bridges the gap between security engineering and audit preparation. You know that the hardest part of compliance is not implementing controls -- it's proving you implemented them. Auditors need evidence: screenshots, configuration exports, log samples…
HermeticOrmus/LibreSecOps-Claude-Code
Agent
You are the Digital Forensics Examiner, a methodical investigator who extracts facts from digital evidence using scientifically sound, reproducible procedures. You understand that forensics is not about finding what you expect to find -- it is about following the evidence wherever it leads while maintaining the…
Agent
This guide provides instructions for creating cs- prefixed agents that orchestrate the USAP skill packages.
Connected-Mate/corporate-launcher
Agent
Subagent that probes the corporate AI gateway during Phase 1.5 — verifies URL reachable, models catalog available, auth token valid, TLS cert acceptable. Returns concise pass/fail report to the main conversation.
Connected-Mate/corporate-launcher
Agent
Subagent that runs scripts/audit-launcher.py on a freshly-rendered launcher tree and returns a concise pass/fail report. Use when Phase 3.5 of the corporate-launcher skill needs to verify the generated launcher meets the 30-rule cyber baseline before declaring success.
Connected-Mate/corporate-launcher
Agent
Subagent that scans a rendered launcher for leaked vendor URLs (api.anthropic.com, api.openai.com, etc.) outside the explicit deny lists. Use when Phase 3.6 needs defense-in-depth verification.
Agent Claude Code
Security code review agent and penetration tester. Detects vulnerabilities, hardcoded secrets, and CVEs by running CodeQL (deep dataflow SAST), Semgrep (5,000+ rules), bandit, ruff, detect-secrets, osv-scanner/dependabot (OSV/GHSA advisory DB), pip-audit, and npm-audit in parallel, then delivers a prioritized…
Agent Claude Code
Use PROACTIVELY when starting a new feature, service, or MVP, or when a design decision needs to be made before code is written. Designs system architecture, data flow, API contracts, database schema, and a minimal-but-scalable implementation plan. Invoke for "design", "architecture", "how should we structure", "new…
Agent Claude Code
Use when something is broken, failing, flaky, or behaving unexpectedly, and the cause isn't obvious. Reproduces the issue, traces the real root cause, explains why it fails, surfaces hidden edge cases, and proposes the most robust fix. Invoke for "bug", "error", "crash", "failing test", "works locally but not in…
Agent Claude Code
Use to prepare an app for production deployment or improve its operational setup. Designs deployment architecture, CI/CD pipelines, containerization, monitoring and logging, and reliability/scaling. Invoke for "deploy", "CI/CD", "Docker", "Kubernetes", "pipeline", "monitoring", "logging", "infrastructure", "uptime"…
uttej-badwane/secure-cloud-prompt-engineering
Agent
Maps a list of security findings to compliance framework control IDs. Use this agent when you have findings from a security review and need to produce a compliance matrix or determine which controls are violated. Delegate with: "compliance-mapper: map these findings to PCI-DSS and HIPAA".
uttej-badwane/secure-cloud-prompt-engineering
Agent
Formats security findings into a structured report (markdown or JSON). Use this agent after a security review to produce a clean, shareable report. Delegate with: "report-generator: format these findings as markdown" or "report-generator: generate JSON output for Jira integration".