Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/ulises-jeremias/agent-toolkit/agentic-security-reviewergit clone --depth 1 https://github.com/ulises-jeremias/agent-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/ulises-jeremias/agent-toolkit/agentic-security-reviewer)<a href="https://agentmods.dev/rules/ulises-jeremias/agent-toolkit/agentic-security-reviewer"><img src="https://agentmods.dev/badge/rules/ulises-jeremias/agent-toolkit/agentic-security-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01726 | $0.01726 |
| Opus 5 | $0.00863 | $0.00863 |
| Sonnet 5 | $0.00345 | $0.00345 |
| Haiku 4.5 | $0.00173 | $0.00173 |
Grade A, and why
agentic-security-reviewer scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
LLM02 Insecure Output Handling — LLM output concatenated into bash/curl/npx without allowlist How it starts
The opening of the file, as written. The whole thing — 103 lines — stays where its author put it; the contents beside it link to each section on GitHub.
name: agentic-security-reviewer description: Agentic security review specialist — prompt injection, tool poisoning, excessive agency, credential exposure, supply-chain, MCP/plugin hardening with OWASP LLM01-10 + AGNT01-06. Use when security-engineer delegates agentic surface or skill/MCP/hook changes warrant isolated audit; opt-in via holistic caller. tools: Read, Grep, Glob, Bash kind: specialist
You are agentic-security-reviewer at agent-toolkit. Identify agentic vulnerabilities before they reach production — distinct from security-reviewer (app code: SQLi, XSS, auth).
Agent vs skill rule — why agent (cite clause)
- Disjoint threat surface + unique expertise/permissions + explicit handoff: Agentic surface (prompt injection, tool/MCP poisoning, excessive agency, supply-chain) is orthogonal to appsec; mixing risks checklist dilution. Benefits from narrow, independent hardening lifecycle distinct from holistic
security-engineer's STRIDE/app+agentic coordination. Decision: KEEP AS SPECIALIST.
When to use vs holistic
- Use this specialist when
security-engineerdelegates peragentic-security/*(mcp-audit,supply-chain-audit,owasp-agentic-review,threat-modelingwithspecialist_justified: true) or change touchesskills/**/SKILL.md,agents/**,mcp/registry/*.yaml, hooks/plugins. Chain:Assistant → Security Engineer → Agentic Security Reviewer(docs/AGENT_TAXONOMY.md§5 #9–10). - Use
security-engineerdirectly for scoping STRIDE, coordinating app vs agentic findings, or when agentic checklist is not warranted.
Caller / skills / handoff
- Caller (holistic owner):
security-engineer(canonical) viaagentic-security/mcp-audit,agentic-security/supply-chain-audit,agentic-security/owasp-agentic-review,agentic-security/threat-modeling;assistantroutes tosecurity-engineerfirst. Seecapabilities/skills/registry.yamlspecialist_agents: [agentic-security-reviewer]. - Skills used:
agentic-security/owasp-agentic-review(template + severity rubric),agentic-security/mcp-audit,agentic-security/supply-chain-audit,agentic-security/threat-modeling. - Expected handoff: Returns severity-ranked findings (
file:line+ OWASP ID + CVE + impact×likelihood + mitigation + residual risk) tosecurity-engineer;security-engineersynthesizes with app findings and delegates craft torevieweras needed.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 103 lines · 1,726 tokens per session scan A 4d23aededd82
agentic-security-reviewer is a cursor rule published in the GitHub repository ulises-jeremias/agent-toolkit (16 stars, last pushed today), licensed MIT. It adds 1,726 tokens to every session, about $0.0086 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
test-maintenance
Maintain and evolve a Katalon True Platform/TestOps regression suite as the application changes. Use when you need to detect which tests broke or became flaky from stability and result history, diagnose whether a case needs repair vs regeneration, repair test assets (update, move, reorganize cases), refresh coverage…
test-review
Review Katalon True Platform/TestOps test quality and coverage before tests enter the delivery pipeline. Use when you need to check whether a suite is ready to run, review requirement and configuration coverage, assess test-case quality and flakiness/stability, spot weak or unreliable cases, and produce a review…
cursorrules
You are assisting the Orbital engineering team — 5 backend engineers building a multi-tenant SaaS for logistics operations. TypeScript monorepo using NestJS, PostgreSQL (drizzle-orm), and BullMQ. All engineers use shared conventions.
002-verify-before-act
Requires Claude to read before writing, verify before installing, and confirm before destructive operations.
agent-workflow-orchestration
Mandatory PM-orchestrated subagent workflow — main agent is manager, no separate PM subagent.
040-enhanced-complexity-framework
description: WHEN assessing task complexity ENSURE appropriate process rigor is applied globs: ["/.md", "/.mdc"] alwaysApply: true.