bro-is-this-safe

bro-is-this-safe is a command for Claude Code from dinnovos/dinnovos-marketplace. It costs 26 tokens per session (2,815 once invoked), scanned A, original, MIT.

A read-only code security scanner that checks selected files or an entire project for vulnerabilities, including possible exposed secrets. It supports multiple programming languages and produces a detailed report.

In plain words
What is it for?
Use it to inspect authentication, payments, APIs, or other parts of a codebase for vulnerabilities and secrets before release or during a security review.
Why use it?
It helps find security problems without changing your files. You can scan a specific folder, feature, or service, or review the whole project.

Command for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: model in frontmatter; mentions CLAUDE.md; positional $N argument.

Part of the bro-code-tools plugin — 8 commands shipped together

Good fit Use it to inspect authentication, payments, APIs, or other parts of a codebase for vulnerabilities and secrets before release or during a security review.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/dinnovos/dinnovos-marketplace/bro-is-this-safe
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/dinnovos/dinnovos-marketplace

Made for: Claude Code.

Or install bro-code-tools, the plugin that ships this one along with the rest of its 8 commands.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for bro-is-this-safe

README.md
[![agentmods](https://agentmods.dev/badge/commands/dinnovos/dinnovos-marketplace/bro-is-this-safe/github.svg)](https://agentmods.dev/commands/dinnovos/dinnovos-marketplace/bro-is-this-safe)
Your own site
<a href="https://agentmods.dev/commands/dinnovos/dinnovos-marketplace/bro-is-this-safe"><img src="https://agentmods.dev/badge/commands/dinnovos/dinnovos-marketplace/bro-is-this-safe/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for bro-is-this-safe

Your own site · 80×15
<a href="https://agentmods.dev/commands/dinnovos/dinnovos-marketplace/bro-is-this-safe"><img src="https://agentmods.dev/badge/commands/dinnovos/dinnovos-marketplace/bro-is-this-safe.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 26 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,815 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00026 $0.02815
Opus 5 $0.00013 $0.01407
Sonnet 5 $0.00005 $0.00563
Haiku 4.5 $0.00003 $0.00281

Measured 12d ago against content hash 115ace161ccd, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

bro-is-this-safe scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

| Python | `os.system(f"ping {h}")` | `subprocess.run(['ping', h])` |
plugins/bro-code-tools/commands/bro-is-this-safe.md · 464 lines

How it starts

The opening of the file, as written. The whole thing — 464 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Scan

Analyze code for security vulnerabilities. Read-only, doesn't modify anything. Multi-language support.

User Input

The user can specify what to scan in various ways:

Exact path:

  • /bro-is-this-safe src/api/
  • /bro-is-this-safe src/auth/authService.ts
  • /bro-is-this-safe app/auth/

Natural language (illustrative examples):

  • /bro-is-this-safe scan the <area> module
  • /bro-is-this-safe check security in <feature>
  • /bro-is-this-safe analyze vulnerabilities in <topic> services
  • /bro-is-this-safe look for secrets in <module>

No arguments:

  • /bro-is-this-safe → scans the entire project

Note: Terms like "authentication", "payments", "API" are just examples. Interpret what the user requests and search for the corresponding files in the project.


Step 1: Interpret the Request

If it's an exact path:

Use directly.

If it's natural language:

Search for files matching the description:

# Explore project structure (includes config files)
find . -type f \( -name "*.ts" -o -name "*.tsx" -o -name "*.js" -o -name "*.jsx" -o -name "*.py" -o -name "*.go" -o -name "*.rs" -o -name "*.php" -o -name "*.rb" -o -name "*.java" -o -name "*.env*" -o -name "*.yml" -o -name "*.yaml" -o -name "Dockerfile*" \) \
  ! -path "*/node_modules/*" ! -path "*/vendor/*" ! -path "*/target/*" ! -path "*/.git/*" ! -path "*/dist/*"

# Search by related name
find . -type f -iname "*<term>*" | grep -v node_modules
find . -type d -iname "*<term>*" | grep -v node_modules

# Search related content
grep -ril "<term>" --include="*.ts" --include="*.tsx" --include="*.js" --include="*.py" --include="*.go" | grep -v node_modules | head -30

Confirm with the user if you find multiple matches.

Limit: Maximum 100 files. If there are more, ask to narrow down or prioritize by risk (auth, api, config first).


Step 2: Project Context

Search and read configuration and standards files:

# Project standards and guides
cat CLAUDE.md 2>/dev/null
cat AGENTS.md 2>/dev/null
cat .cursor/rules.md 2>/dev/null

# Security configuration
cat .env.example 2>/dev/null
cat .gitignore 2>/dev/null

# Detect stack
cat package.json pyproject.toml go.mod Cargo.toml composer.json 2>/dev/null
cat docker-compose.yml 2>/dev/null

Read the full file on GitHub · 464 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 464 lines · 26 tokens per session scan A 115ace161ccd

Subscribe to this mod's changes

bro-is-this-safe is a command published in the GitHub repository dinnovos/dinnovos-marketplace (2 stars, last pushed 7mo ago), licensed MIT. It adds 26 tokens to every session and 2,815 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.