Security
Threat modelling, secure review, hardening and supply-chain safety.
Download all 29
- Respond to a leaked secret
Produces an ordered response plan for an exposed key, token or password - revoke and rotate, audit use, clean up copies, notify and prevent. Use right after a secret is committed, logged or shared.
- Review an API against the OWASP API Top 10
Reviews an API design or implementation against the OWASP API Security Top 10, from object-level authorization and mass assignment to rate limits and SSRF, with attack paths and fixes.
- Review a cloud IAM policy
Reviews AWS, GCP or Azure IAM policies for over-broad permissions, privilege-escalation paths, wildcard resources and missing conditions, and proposes least-privilege versions.
- Review a pull request for security
Reviews a diff for exploitable vulnerabilities and reports only findings with a concrete attack path. Use before merging changes to input handling, auth, data access or dependencies.
- Threat model a feature
Builds a threat model for one feature or change, mapping data flows and trust boundaries to ranked threats and mitigations. Use during design, before the code is written or merged.
- Triage a vulnerability report
Triages an external vulnerability or bug bounty report by checking the claim, rating severity with CVSS, deciding valid, duplicate or out of scope, and drafting the reply. Use for security inboxes.
- Vet a dependency before adding it
Checks a third-party package for supply-chain risk, maintenance health, license fit and real need before it is added or upgraded. Use when a PR adds a new dependency or bumps one.
- Audit a web application's security
Audits a whole web application codebase against the OWASP Top 10, tracing each finding from an entry point to the flaw with a reproducible proof and a fix. Use before launch or an external pentest.
- Audit a codebase's compliance controls
Checks a codebase against the technical controls behind SOC 2, GDPR or HIPAA, like encryption, audit logging, access control, retention and deletion, and marks each pass, partial or fail with a fix.
- Triage dependency vulnerabilities
Triages dependency scan findings by reachability and exploitability, gives the upgrade path, and justifies anything safe to defer. Use when a scanner reports more than the team can fix at once.
- Audit the licences of every dependency
Inventories the licences of all direct and transitive dependencies, flags conflicts with the project's licence or policy, and lists packages for legal review. Use before a release or due diligence.
- Audit how an app handles untrusted input
Inventories every place untrusted input enters a codebase and follows each to its sinks, checking for injection, XSS, path traversal and type confusion, with a fix per input vector.
- Audit a repository and its history for secrets
Scans a repository and its git history for committed secrets, triages real ones, reports exposure windows and rotation steps, never printing a value. Use before open-sourcing or after a scare.
- Data privacy engineer
Acts as a privacy engineer who designs minimisation, retention, consent and deletion into systems, keeps the data map current, reviews features for personal data risk and knows when to ask legal.
- Dependency hygiene rules
Standing rules for adding or upgrading dependencies, so each one is justified, verified to exist, maintained, pinned through the lockfile and checked for licence and advisories.
- Harden IoT device firmware
Plans prioritised hardening for a connected device with unique credentials, secure boot, signed updates, debug lockdown, secret storage, TLS and a disclosure path, sized for a small team.
- Harden a Linux server
Hardens a Linux server in a safe order (SSH, users, firewall, updates, unused services, logging, mandatory access control) with a check and rollback per step. Use on new or inherited servers.
- Harden web app headers and cookies
Produces hardened HTTP security headers, a Content Security Policy, CORS and cookie settings for a web app, rolled out first in report-only mode. Use before launch or after a security scan.
- Harden a small Windows domain
Plans hardening for a small Windows Active Directory domain in priority order - admin tiering, passwords and MFA, legacy protocols, logging and backup protection - with a check and rollback per step.
- Plan secrets management
Plans secrets management for a stack, covering inventory, storage, runtime injection, rotation, access control and leak detection. Use when secrets live in env files, CI variables and chat.
- Plan a security incident response
Plans the response to a suspected security incident with triage, evidence preservation, containment options, communication, eradication and recovery. Use in the first hours of a breach or compromise.
- Review an authentication flow
Reviews an authentication or session design (OAuth or OIDC, tokens, cookies, MFA, password reset) for known flaws, with attack paths and fixes. Use before building or shipping login and session code.
- Review a diff for personal data
Reviews a code change for new personal data flows (fields collected, PII in logs and analytics, retention, third parties, consent) and lists data map updates and questions for privacy or legal.
- Review an LLM app for security
Reviews an LLM app for prompt injection, data exfiltration through tools, excessive agency and unsafe output handling, mapped to the OWASP LLM Top 10. Use before shipping an agent or RAG feature.
- Review a mobile app's security
Reviews an iOS or Android app against OWASP MASVS areas (storage, crypto, auth, network, platform, code, resilience, privacy) and returns ranked findings with fixes. Use before release or an audit.
- Secure coding rules
Makes the assistant write code that validates untrusted input, avoids injection, protects secrets and checks authorization by default. Use as always-on rules in any codebase.
- Security auditor
Reviews code for exploitable weaknesses and reports only issues with a concrete attack path. Use as a reviewer persona or subagent for security-sensitive changes.
- Write a security policy and disclosure process
Writes a SECURITY.md and the disclosure process behind it, with supported versions, how to report, response times and safe harbour. Use when a project has no clear way to report vulnerabilities.
- Write a custom Semgrep rule
Writes a custom Semgrep static analysis rule for a risky code pattern in your codebase, with pattern logic, message, fix suggestion and passing and failing test snippets.
Wins every tie inside software-engineering. Not: legal compliance drafting (compliance).