Sourcery Triager — Security agent for Claude Code
Read-only Sourcery findings triage.
How to install Sourcery Triager
Installs to ~/.claude/agents/abyssbugg-labs-sourcery-agent-bundle-sourcery-triager.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/abyssbugg-labs/sourcery-agent-bundle/HEAD/agents/sourcery-triager.md -o ~/.claude/agents/abyssbugg-labs-sourcery-agent-bundle-sourcery-triager.md Restart Claude Code, or start a new session, for it to be picked up.
What Sourcery Triager does
name: sourcery-triager description: Read-only Sourcery findings triage. Use to summarize security findings, prioritize what to fix first, and prepare remediation plans without modifying code. disallowedTools: Write, Edit
You are a read-only security triage agent for Sourcery findings. You never modify code — produce reports and plans only.
Follow the `sourcery-triage` skill workflow using the `sourcery` MCP tools:
- Start with
sourcery_security_snapshotfor counts by status/severit
Alternatives in Security
- Electron Ipc Engineer — Use this agent for any change that touches Electron IPC — adding/removing channels, modifying main.ts ↔ preloa 204 ★
- Evaluator Physical Agent — Provider-neutral physical-security evaluator — plans bounded coverage and records opaque evidence references w 97 ★
- Adversary — Pre-implementation red-team analysis 85 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Vuln Patcher
Writes minimal, verified fix patches for confirmed vulnerabilities as diff files under reports/, without modif
Ddw Sec Auditor
Security auditor. Spawn it in CODE when a SAST scan reports findings, to triage them before anyone starts fixi
Daw Sec Auditor
Security auditor. Spawn it in CODE when a SAST scan reports findings, to triage them before anyone starts fixi
Application Security Auditor
Local-only, static-first application-security auditor that threat-models a repository or subsystem and returns
Frontend Auditor
Read-only frontend audit agent that critiques UI quality, accessibility, responsiveness, and product-specific
Delforge QA Breaker
Use for adversarial QA — actively trying to break an application to find bugs, edge cases, and security gaps i
Related Skills
AWS Findings Triage Skill
Triage AWS Security Hub, GuardDuty, Inspector, and Config findings for the MacMountain account by real exploit
Threat Model Skill
Claude Code skill: write the project's security constitution (assets, roles, trust boundaries, invariants, ent
Remediate
Generate remediation plans for all findings or a specific domain