Bulkhead Reviewer — Security agent for Claude Code
Reviews a change set for security risk — what it exposes, to whom, and whether the control between an attacker and it actually holds.
How to install Bulkhead Reviewer
Installs to ~/.claude/agents/bigin-io-firebreak-bulkhead-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/bigin-io/firebreak/HEAD/agents/bulkhead-reviewer.md -o ~/.claude/agents/bigin-io-firebreak-bulkhead-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Bulkhead Reviewer does
name: bulkhead-reviewer description: Reviews a change set for security risk — what it exposes, to whom, and whether the control between an attacker and it actually holds. Reports reachability rather than severity ratings. Read-only. Spawn with a repository path and a change set (a branch, a commit range, or "working tree"). Use for "review this branch for security", "is this safe to merge", "can this be exploited", or when a change touches auth, outbound requests, file paths, deserialisation
Alternatives in Security
- Retool Parity Audit — Audits the Retool parity checklist against what is actually built, using the export inventories and the Retool 7.2k ★
- Patina Fidelity Auditor — Triggers to audit whether a patina rewrite preserved meaning versus the original text 352 ★
- Audit Deep — Deep single-subsystem audit that reasons about state over time (caches, upserts, migrations, concurrent scans) 335 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Engine QA Review Security Governance
After a change you've asked for is built, checks whether it is safe to release — how it could be attacked or m
Meldom Reviewer
Reviews code changes for security, quality, correctness, reuse, efficiency, and consistency. Read-only - does
Vuln Reach
Decides whether a target actually reaches the vulnerable code of a vulnerable dependency (OSV advisory), citin
Thermo Bugs
Thermo-nuclear correctness audit of a diff — bugs, breaking changes, security, devex, feature-flag leaks, and
Cortex Role Reviewer
Reviews a change from ONE named expert angle — security, performance, accessibility, data integrity, operabili
Ticketmill Test Validator
Test integrity auditor for the ticketmill plugin repo itself. Use after implementation to audit whether tests
Related Skills
AWS Findings Triage Skill
Triage AWS Security Hub, GuardDuty, Inspector, and Config findings for the MacMountain account by real exploit
Lorenzini
Claude Code skills that wait for a third-party PR reviewer and decide whether its verdict actually means pass
Detailed Review
Structured code review with checklist and severity ratings