Fleet Security Auditor — Security agent for Claude Code
Fleet-specific security analysis covering MDM, osquery, API auth, and device management threat models.
How to install Fleet Security Auditor
Installs to ~/.claude/agents/fleetdm-fleet-fleet-security-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/fleetdm/fleet/HEAD/.claude/agents/fleet-security-auditor.md -o ~/.claude/agents/fleetdm-fleet-fleet-security-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Fleet Security Auditor does
name: fleet-security-auditor description: Fleet-specific security analysis covering MDM, osquery, API auth, and device management threat models. Use when touching auth, MDM, enrollment, or user data. tools: Read, Grep, Glob, Bash model: opus
You are a security engineer specializing in the Fleet codebase. Think like an attacker targeting a device management platform that controls thousands of endpoints.
Fleet-Specific Threat Categories
API Authorization
- Missing `svc.authz.Auth
Alternatives in Security
- Firmware Analyst — You are an elite firmware analyst with deep expertise in embedded systems security, IoT device analy 31.9k ★
- GraphQL Audit — GraphQL API security specialist 812 ★
- Aspm Correlator — Application Security Posture Management persona 548 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Safeguard
Security audit specialist. Use proactively before release, after touching auth, payments, file upload, or user
Senior Security Engineer
Senior security engineer covering application security (OWASP-style threat modeling, secure coding, auth desig
Detection Engineer
Delegates to this agent when the user asks about detection rules, SIEM queries, threat hunting, indicator anal
AI Eng Warden
AI Engineering review of code touching LLM interactions, prompt construction, context management, agent archit
API Security Tester
Generates and runs comprehensive API security tests covering OWASP Top 10, injection attacks, auth bypass, mal
Rondoflow Reviewer
Reviews a RondoFlow code change against this project's specific conventions and security rules (child_process
Related Skills
Security Sweep
Comprehensive security scanner covering OWASP Top 10 (2025), Mobile Top 10 (2024), and LLM Top 10 (2025). Scan
Security Threat Model
Generate repo-specific threat models identifying trust boundaries
Secure LLM Gateway
Security-focused gateway in front of an LLM API — auth, prompt-injection defense, output filtering, audit logg