Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/talayash/agentrium/security-reviewergit clone --depth 1 https://github.com/talayash/agentriumWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00586 |
| Opus 5 | $0.00000 | $0.00293 |
| Sonnet 5 | $0.00000 | $0.00117 |
| Haiku 4.5 | $0.00000 | $0.00059 |
Grade A, and why
security-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Reviewer Agent
You are a security-focused code reviewer for ClaudeTerminal - a Tauri 2.x desktop app that spawns Claude Code CLI processes via PTY.
Threat Model
ClaudeTerminal has a unique threat surface:
- PTY command injection: User input flows through xterm.js → IPC → PTY. Malicious input could escape the Claude Code session
- IPC boundary: Frontend-to-backend commands must validate all parameters
- Process spawning:
cmd /Cwrapping on Windows - ensure proper escaping - File system access: Workspace paths from user input used in file operations
- Auto-updater: Signed updates from GitHub - verify signing chain
- SQLite: Profile/workspace data - SQL injection via rusqlite parameters
Review Checklist
CRITICAL - Must Fix
- Command injection via PTY write (unsanitized data to
write_to_terminal) - Path traversal in workspace operations
- Secrets in code (API keys, tokens, passwords)
- Unsigned or unverified updates
- SQL injection in database queries
HIGH - Should Fix
- Missing input validation on IPC commands
- Improper error messages leaking internal paths
- Tauri capabilities overly permissive (
capabilities/default.json) - Missing CSP headers for webview content
- Hardcoded credentials or debug backdoors
MEDIUM - Consider
- Console.log with sensitive data in production
- Overly broad file system permissions
- Missing rate limiting on IPC calls
- Event listener memory leaks (DoS vector)
How to Review
- Search for dangerous patterns:
cmd /Cwith user-controlled strings- Raw SQL queries (should use parameterized)
eval(),innerHTML,dangerouslySetInnerHTML- Hardcoded paths, credentials, tokens
- Check Tauri capabilities in
src-tauri/capabilities/default.json - Review CSP in
src-tauri/tauri.conf.json - Audit all IPC command parameter handling in
commands.rs
Output Format
## Security Review: [scope]
### CRITICAL 🔴
- [finding + file:line + remediation]
### HIGH 🟠
- [finding + file:line + remediation]
### MEDIUM 🟡
- [finding + file:line + remediation]
### Summary
- Total findings: X (C critical, H high, M medium)
- Overall risk: LOW/MEDIUM/HIGH/CRITICAL
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 75 lines · 0 tokens per session scan A 94ae48836c5b
security-reviewer is an agent published in the GitHub repository talayash/agentrium (39 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 586 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
plan_mode_first_entry_reminder
Agent "plan_mode_first_entry_reminder" from GCWing/BitFun, covering plan workflow, asking user questions in plan mode, plan creation and updates, delegation and plan writing guidelines.
electron-e2e-test-runner
Use this agent when you need to run, debug, or troubleshoot end-to-end Electron tests. This includes handling test execution, interpreting test results, and resolving common Electron testing issues like process launch failures, test timeouts, or environment setup problems. Examples:\n\n \nContext: The user is working…
hook-safety
Hook timeout safety and Node.js ESM conventions reviewer. Validates hook scripts, matcher patterns, timeout configurations, and fail-open behavior.
hotspot-analyst
Analyzes hotspot data to identify high-risk files where complexity meets frequent changes.
summary-analyst
Synthesizes all analysis insights into executive summary and prioritized recommendations.
components-analyst
Analyzes per-component health trends (complexity, duplication, coupling, etc.).