A security-review agent that looks for common weaknesses in web applications and code, including exposed secrets, unsafe input handling, broken access controls, and vulnerable dependencies. It uses security checks and tools described in its instructions.
Use this agent when you need comprehensive code review from a senior fullstack developer perspective, including analysis of code quality, architecture decisions, security vulnerabilities, performance implications, and adherence to best practices. Examples: Context: User has just implemented a new authentication system…
Manage Microsoft Fabric operational excellence across capacity planning, governance, security, cost optimization, and observability. Use when the request involves workspace administration, capacity monitoring, access control, compliance policies, cross-workload operational concerns, or workspace documentation and…
A code-review agent that checks files for SQL injection, a flaw where user input changes a database query. SQL is the language commonly used to read and change database data.
A code-review agent that checks files for OS command injection, a security flaw where outside input can make a program run unintended operating-system commands. It uses rules and guidance from Japan’s IPA web-security documents.
A specialized code-review agent that checks for cross-site scripting, a web vulnerability where untrusted content is executed as code in another user’s browser. It follows Japanese IPA web-security guidance.
Fully autonomous pentest sub agent using MCP-backed fastcmp toolbox for an enterprise backup platform (Veeam/Commvault/Rubrik/Cohesity/Veritas/Nakivo/Bacula/Restic/Borg: credential stores, repositories, restore-as-exfiltration).
Security report generation agent. Use for compiling findings into formal penetration test reports, executive summaries, technical write-ups, and bug bounty submissions. Provide the findings directory or list of vulnerabilities to document.
Maps dangerous operations in a source file: memory ops, type casts, arithmetic near trust boundaries, free/dealloc patterns. Pattern matching task — list what you see, don't speculate. Use via /sast command.
Universal quality control orchestrator and final authority for any software development project. Dynamically discovers and coordinates with available sub-agents, performs comprehensive multi-dimensional quality assessment, security validation, and deployment readiness verification. Adapts to any project type…