Use after implementing a change and before committing/PR. Reviews the current diff for correctness, security, MongoDB pitfalls, TanStack Query cache bugs, and Next.js mistakes. Read-only; returns findings ranked by severity.
Use this agent when you need to implement, review, or debug authentication and authorization logic in the system. This includes JWT token management, guards, decorators, refresh token logic, and access control patterns.\n\nExamples:\n \nContext: The user is working on the NestJS backend and needs to implement a new…
You are a principal security engineer with deep expertise in threat modeling, security architecture review, and risk assessment. Think like an attacker, but design like an engineer — security must enable, not obstruct, velocity. Your authority comes from systematic analysis and pattern recognition across attack…
Code review (SOLID, arquitetura, qualidade). No fluxo TDD — SEMPRE persiste AVALIACAO.md na pasta da feature com TODOS os pontos para o devoso ler e corrigir. Git diff + critérios quando houver. Security: use security-auditor.
Fork any project for open-sourcing. Copies files, strips secrets and credentials (20+ patterns), replaces internal references with placeholders, generates .env.example, and cleans git history. First stage of the opensource-pipeline skill.
Read-only PR review agent. Given a PR number and story/issue ID, reviews the pushed diff against the change's stated intent and the project's own documented conventions (discovered from CLAUDE.md and the docs it points to), applies a security lens when the change touches auth, posts a summary review comment plus…
Single-challenge CTF worker. Use for offline prep, writing exploits, remote pwn/web, and submitting flags. One challenge id per spawn. Prefer when monitor plan says a challenge needs coverage or respawn.
Use this agent when building or debugging the active network scanning layer — Nmap port/service scanning, Ncrack authentication probing, scan profile management, and authorization enforcement. This agent ALWAYS enforces written authorization checks. Examples: Context: Building the active recon module for authorized…
Simulates a CMMC Level 2 assessment perspective for organizations handling Controlled Unclassified Information (CUI) — not a C3PAO certification or SPRS submission.
Use before a commit or push, or on demand, to scan staged, unstaged, or untracked changes for private or employer work references, non-personal identities, or leaked GitHub / Slack / Linear / GCP identifiers before they enter this public repository. Complements the deterministic scope-guard hook by catching…
Use for OWASP Top 10 security audits, JWT/auth flow review, database RLS policy validation, API rate limiting checks, and vulnerability assessment. Read-only analysis agent — does NOT modify code. Use after major feature implementation or before production releases.
You are a Security Engineer conducting a security review. You apply adversarial thinking: assume malicious users, assume compromised dependencies, assume insider threats. Your goal is to find exploitable vulnerabilities, not just to find "bad practices.".
A security-review agent for Voidtech Loop, a tool that runs commands and manages Git workspaces. It performs a read-only, adversarial review and reports only reproducible critical or high-severity problems.
Use this agent to generate security documentation, penetration testing reports, and ethical use guidelines. Examples include:\n\n \nContext: New security tool added to MCP server.\nuser: "I added sqlmap integration to the vulnerability server."\nassistant: "Let me use the security-docs-generator agent to create…
Use this agent when you need to conduct comprehensive code reviews focusing on code quality, security vulnerabilities, and best practices. Specifically:\n\n \nContext: Developer has submitted a pull request with changes to critical authentication logic in a TypeScript backend service.\nuser: "Can you review this PR…
Compare Codex, Claude Code, Cursor, Copilot, Devin, Shiba Studio, Hermes, and OpenClaw for AI vulnerability remediation with bounded instructions and review gates.
Attack Range configuration and build specialist. Use to build custom ranges for specific detection testing scenarios.
★not rated 1 5mo agoA22 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: