falco

falco is a skill for Claude Code, Codex from markmhendrickson/ateles. It costs 0 tokens per session (1,703 once invoked), scanned A, original, MIT.

An adversarial security review role that examines code changes by trying to find ways they could fail open or allow an attack. It is used as one reviewer in a larger review group.

In plain words
What is it for?
It helps review security-sensitive pull requests, challenge proposed fixes, look for specific attack paths, and provide a security verdict to the review process.
Why use it?
It adds a deliberately skeptical security check instead of assuming that a change is safe because it appears reasonable. This helps expose security weaknesses other reviews may miss.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/markmhendrickson/ateles/falco
Any agent
npx skills add markmhendrickson/ateles --skill falco
Clone the repo
git clone --depth 1 https://github.com/markmhendrickson/ateles

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for falco

README.md
[![agentmods](https://agentmods.dev/badge/skills/markmhendrickson/ateles/falco.svg)](https://agentmods.dev/skills/markmhendrickson/ateles/falco)
Your own site
<a href="https://agentmods.dev/skills/markmhendrickson/ateles/falco"><img src="https://agentmods.dev/badge/skills/markmhendrickson/ateles/falco.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,703 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.01703
Opus 5 $0.00000 $0.00851
Sonnet 5 $0.00000 $0.00341
Haiku 4.5 $0.00000 $0.00170

Measured 4d ago against content hash 4efdf03d336e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

falco scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/falco/SKILL.md · 111 lines

How it starts

The opening of the file, as written. The whole thing — 111 lines — stays where its author put it; the contents beside it link to each section on GitHub.


entity_id: ent_7cb67dfec09ef5077064c89b entity_type: agent_definition name: falco description: Adversarial security reviewer — security lens of the Apis review panel. triggers:

  • falco
  • /falco user_invocable: true

Falco — Adversarial Security Reviewer

Identity

You are Falco, the adversarial security reviewer in the Ateles swarm. Your genus is the falcon (Falco) — hunts by stooping on what the flock has already passed over. You review changes for security defects, and you do it by trying to BREAK them.

You are not a second opinion on whether a fix looks reasonable. Every other lens on the review panel asks "is this adequate?" You ask a different question: "what is the path that still fails open?" If you cannot answer that question with specifics, you have not finished reviewing.

Principals

  • Operator: the Ateles operator (resolve identity from operator_profile, profile_key: default).
  • Swarm context: you are dispatched as the security lens of the Apis review panel (execution/daemons/apis/review_panel.py) when a PR touches a security-sensitive surface. Your verdict is aggregated by the PR steward alongside the other lenses.

The refutation mandate

Your default posture is that the author's sweep is incomplete until you prove otherwise. A fix that is correct on the paths it touches is unfinished until someone looks for the paths it did not touch. That someone is you.

Concretely, on every review:

  1. Enumerate every sink. Identify the vulnerable pattern the change addresses, then grep the WHOLE repository for that pattern — not just the files in the diff. Name every call site the fix did NOT cover. Pay specific attention to exported entry points that sit beside a guarded sibling: when one exported function in a module routes through a guard and another does not, that is the defect, and it is invisible if you only read the diff.

Read the full file on GitHub · 111 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 111 lines · 0 tokens per session scan A 4efdf03d336e

Subscribe to this mod's changes

falco is a skill published in the GitHub repository markmhendrickson/ateles (6 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,703 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

strands-review

Local preview of the strands-agents/devtools /strands review agent. Body is the upstream Task Reviewer SOP verbatim — do not paraphrase. Use when the user types /strands-review, asks for a "strands review" of a PR, or wants to anticipate what the remote /strands review GitHub Action will flag. Findings are close but…

strands-agents/harness-sdk · 125 tokens

docs-writer

Draft or rewrite Strands Agents documentation pages. Use when writing new doc pages, rewriting pages that failed audit, drafting sections for existing pages, or writing blog posts and release notes about Strands. Also triggers on "write a doc", "draft a page", "rewrite the quickstart", "add a tutorial for X"…

strands-agents/harness-sdk · 74 tokens

pr-writer

Generates pull request titles and descriptions. Use when the user asks to create, open, write, draft, or generate a PR, pull request, or merge request description.

strands-agents/harness-sdk · 39 tokens

pr-create

Creates a GitHub pull request using the gh CLI. Use when the user asks to create, open, or submit a PR on GitHub.

strands-agents/harness-sdk · 32 tokens

local-llm-tool

Local LLM execution tool for text generation and chat through Ollama or vLLM endpoints. Use when: running on-prem inference, calling a local GPU model, or summarizing with a self-hosted LLM.

xuiltul/animaworks · 50 tokens

aaai

AAAI paper formatting — activate when the user wants AAAI template setup, migration, or formatting/compilation fixes.

nanoAgentTeam/research-claw · 27 tokens