Cavet Security — Security agent for Claude Code
Runs a cavet security scan for the given scope and phase, triages every finding, and returns the CLI's structured output verbatim.
How to install Cavet Security
Installs to ~/.claude/agents/chaoschild-cavet-cavet-security.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/ChaosChild/cavet/HEAD/agents/cavet-security.md -o ~/.claude/agents/chaoschild-cavet-cavet-security.md Restart Claude Code, or start a new session, for it to be picked up.
What Cavet Security does
name: cavet-security description: Runs a cavet security scan for the given scope and phase, triages every finding, and returns the CLI's structured output verbatim. Use for review-time scans and pre-commit triage. tools: Read, Bash
You are the cavet security subagent. You have read access to the repository and the `cavet` command, and nothing else — by design. Your job is triage and deduplication, not narration and not remediation. Run the scan for the scope and phase you were given. Fo
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Audit Deep — Deep single-subsystem audit that reasons about state over time (caches, upserts, migrations, concurrent scans) 335 ★
- Project Auditor — Read-only health audit of the VibeFrame monorepo 165 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Dual Channel Drift Auditor
Cold pairwise audit of a declared @dual-pair anchor group. Given ONLY an anchor (never the PR diff or narrativ
Cloud Auditor
Authenticated AWS cloud-configuration audit for a contracted engagement. Given an AWS CLI profile + slug, runs
Sec Orchestrator
Coordinates multi-agent ClaudeSec security workflows — triages scan findings by severity, assigns work to sec-
Code Security Reviewer
Performs structured code security and quality audits with restricted tool access. Supports tiered review (T1 p
POC Engineer
Given a confirmed finding + its context worksheet, produces the smallest self-contained crate that reproduces
Finding Skeptic
Read-only adversarial verifier for audit findings. Given one finding and one skeptic lens, actively tries to r
Related Skills
Power Coding
Mindful-coding OS for any LLM coding agent (Claude Code, Codex, Gemini CLI) — the Five Forces: session handoff
Claude Code Secret Gate
The pre-commit secret gate for AI coding agents — content-scans staged changes and blocks any commit containin
V Triage
Classify one change request before any work starts — resolve, score, and write plus COMMIT the pre-eval triage