This registry provides a single portfolio-facing inventory of agents for MCP Sentinel — Agent Trust Broker. Each agent is designed to be independently understandable by a reviewer while also functioning as part of a larger governed agentic security system.
Bugbot-class logic-bug and vulnerability hunter for the current diff. Traces attacker-controlled input to real sinks and finds production-real bugs in state, control flow, concurrency, contracts, and callers the diff did not touch. Use when the user asks for /hunter, /meta, a bug hunt, a security pass, or a review of…
Corp governance gateway. Single entry point: instruments telemetry, opens the parent case span, runs scenario-3/src/corp.py and delegates the analysis to @fraud-analyst and @legal-counsel. Never answers the case itself. USE WHEN: governed fraud + legal analysis, telemetry-instrumented case run, corp telemetry, run…
Validates task files against task template and task-creator rules. Reads sources of truth, checks structure, content quality, and consistency. Triggers: after task-creator generates files, on re-validation after fixes. Not for: security (security-auditor), spec coverage (completeness-validator).
Read-only auditor that checks a note, file, or diff for cross-scope leaks before publishing, sharing, or committing. Only applicable when the OPTIONAL wall is enabled — i.e. some scope in AIOS/Systems/layers.tsv declares identifying tokens. Use before any external-facing action (publish, post, send, apply) or when…
Review code changes (staged diff, branch range, or specific files) for correctness, security, style consistency, and rule compliance. Use before large commits or before deploying to prod. Returns issue list + severity.
Use this agent to predict how users will creatively misuse and weaponize features for social manipulation, fraud, or unintended behavioral cascades. This agent understands that every feature becomes a tool for gaming the system and unintended consequences.
Reviews code changes for security vulnerabilities, credential leaks, and injection risks. Use when modifying authentication, authorization, data handling, or API endpoints.
Use this agent when you need expert code review for Ruby on Rails or Next.js applications, focusing on best practices, DRY principles, Clean Code standards, security vulnerabilities, database optimization, and Test-Driven Development. This agent should be invoked after writing or modifying code to ensure it meets…
A read-only quality-audit agent that treats “finished” as something to test rather than assume. It checks a system through several independent lenses, including security, data quality, operations, performance, and error handling.
Security-focused code review. Use when the user asks to "audit for security", "check for vulnerabilities", review auth/authz/crypto/input handling code, or before shipping anything that touches secrets, user input, or external services. Also use proactively when reviewing dependency additions.
Senior VBA code review specialist. Use after writing or modifying VBA to review for security, quality, performance, and best practices before committing or releasing.
Expert TypeScript/JavaScript code reviewer specializing in type safety, async correctness, Node/web security, and idiomatic patterns. Use for all TypeScript and JavaScript code changes. MUST BE USED for TypeScript/JavaScript projects.
Alternate pentest report renderer in "operator casebook" style — a single self-contained HTML deliverable with phosphor-green CRT aesthetic, dossier hero, executive briefing, master timeline, attack graph, per-act chapters, host grid, TTP matrix, attack chains, dead-ends, and close stamp. Coexists with the markdown…
Independent OWASP security reviewer. Invoke (proactively or on request) to run a security-only pass over a diff, endpoint, or file before it merges. Reports vulnerabilities with file:line, exploit, and fix; never modifies code.
Threat modeling, secure-by-default review, secret hygiene, and security audits of specific changes. Use for a security-focused pass on a diff, file, or design.
Senior Security Engineer specialized in threat modeling, vulnerability analysis, authentication/authorization patterns, secure coding practices, and ensuring application and infrastructure security across the full stack.
Senior code reviewer that evaluates changes across five dimensions — correctness, readability, architecture, security, and performance. Use for thorough code review before merge.
Expert code reviewer specializing in code quality, security vulnerabilities, and best practices across multiple languages. Masters static analysis, design patterns, and performance optimization with focus on maintainability and technical debt reduction.
Use after implementing a change and before committing/PR. Reviews the current diff for correctness, security, MongoDB pitfalls, TanStack Query cache bugs, and Next.js mistakes. Read-only; returns findings ranked by severity.
★not rated 3 yesterdayA48 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: