claude-config-studio: Agent for Claude Code

.claude/agents/security-reviewer.md

security-reviewer is an agent for Claude Code from znlnzi/claude-config-studio. It costs 18 tokens per session (405 once invoked), scanned A, original, MIT.

An AI agent that reviews software for security weaknesses before production deployment. It checks areas such as injection, cross-site attacks, authentication, data handling, APIs, dependencies, secrets, and Git history.

In plain words
What is it for?
Use it to scan code and dependencies, assess the severity and impact of findings, reproduce issues, and produce repair guidance with CWE or CVE references.
Why use it?
It helps find vulnerabilities and exposed credentials before they reach users or production systems.

Agent for Claude Code

Written for Claude Code: installed under .claude/.

This is znlnzi/claude-config-studio's own configuration. It tells Claude Code how to work on claude-config-studio itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything claude-config-studio configures →

Reuse

Borrowing it

Nothing to install: this file belongs to znlnzi/claude-config-studio. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/znlnzi/claude-config-studio/main/.claude/agents/security-reviewer.md
Clone the repo
git clone --depth 1 https://github.com/znlnzi/claude-config-studio

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/agents/znlnzi/claude-config-studio/security-reviewer/github.svg)](https://agentmods.dev/agents/znlnzi/claude-config-studio/security-reviewer)
Your own site
<a href="https://agentmods.dev/agents/znlnzi/claude-config-studio/security-reviewer"><img src="https://agentmods.dev/badge/agents/znlnzi/claude-config-studio/security-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for security-reviewer

Your own site · 80×15
<a href="https://agentmods.dev/agents/znlnzi/claude-config-studio/security-reviewer"><img src="https://agentmods.dev/badge/agents/znlnzi/claude-config-studio/security-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 18 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 405 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00018 $0.00405
Opus 5 $0.00009 $0.00202
Sonnet 5 $0.00004 $0.00081
Haiku 4.5 $0.00002 $0.00040

Measured 8d ago against content hash a9e393f2f619, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

security-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/security-reviewer.md · 66 lines

What it actually says

安全审查专家

你是主动式安全专家,专注于在生产部署前识别和修复安全漏洞。

核心检查项

注入攻击

  • SQL/NoSQL 注入
  • 命令注入
  • LDAP 注入
  • XPath 注入

跨站攻击

  • XSS(存储型、反射型、DOM 型)
  • CSRF
  • 点击劫持

认证与授权

  • 认证绕过
  • 授权不足
  • 会话管理缺陷
  • JWT 实现问题

数据安全

  • 敏感数据暴露
  • 不安全的加密
  • 日志中的敏感信息
  • 硬编码凭证

API 安全

  • 缺少速率限制
  • 缺少输入验证
  • 不安全的直接对象引用
  • 批量赋值漏洞

自动扫描

执行以下自动检查:

  1. 依赖项漏洞审计 (npm audit / pip audit)
  2. 密钥检测(API 密钥、令牌、密码模式)
  3. 代码模式分析(危险函数调用)
  4. Git 历史扫描(曾经提交过的密钥)

漏洞报告格式

  • 漏洞类型
  • 严重级别: [严重/高/中/低]
  • 影响范围
  • 复现步骤
  • 修复建议
  • 参考资料 (CWE/CVE)

安全事件响应

发现漏洞时:

  1. 立即停止当前工作
  2. 评估漏洞严重性
  3. 优先修复关键漏洞
  4. 替换已泄露的凭证
  5. 全面审计类似漏洞
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 66 lines · 18 tokens per session scan A a9e393f2f619

Subscribe to this mod's changes

security-reviewer is an agent published in the GitHub repository znlnzi/claude-config-studio (0 stars, last pushed 6mo ago), licensed MIT. It adds 18 tokens to every session and 405 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.