Config Auditor — Security agent for Claude Code
Security header and server configuration auditor.
How to install Config Auditor
Installs to ~/.claude/agents/h-mmer-pentest-agents-config-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/H-mmer/pentest-agents/HEAD/.claude/agents/config-auditor.md -o ~/.claude/agents/h-mmer-pentest-agents-config-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Config Auditor does
name: config-auditor description: "Security header and server configuration auditor. Use for HTTP security header analysis, CSP evaluation, CORS policy review, TLS configuration assessment, cookie security, and server hardening checks. Provide target URL or list of URLs." tools: Bash, Read, Write, Edit, Grep, WebFetch, mcp__writeup-search__search_writeups, mcp__writeup-search__get_writeup, mcp__writeup-search__search_techniques, mcp__writeup-search__search_payloads color: yellow model: haiku
Alternatives in Security
- API Expert — Use this agent for Output.ai API server design, Express middleware configuration, workflow execution endpoints 434 ★
- Crypto Attacker — Cryptography and TLS security specialist 72 ★
- Network Config Reviewer — Network configuration security and correctness auditor 60 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Kavach Config
KAVACH infrastructure/config/ops-security specialist. Audits security headers, debug/verbose in prod, stack-tr
Gsc Page Experience
Page-experience / security-posture analyst. Pulls Mozilla Observatory, SSL Labs, and a local header probe to g
Network Security Engineer
Network Security Engineer (Tier 3): hardens the network perimeter and runtime — TLS 1.3/HSTS/ACME, nginx/Caddy
Prevent XSS Attacks
add_header X-Content-Type-Options "nosniff"; add_header X-Frame-Options "DENY"; add_header X-XSS-Protection "1
Security Agent.Agent
Use when a change touches permissions, authentication, dependencies, configuration, release surfaces, sensitiv
Security Laravel
Principal security engineer (OWASP, Laravel security, GDPR, Sanctum, RBAC, CSP, encryption, multi-tenancy). Ca
Related Skills
Harden Config
Deployment hardening step 5 — validate runtime/deploy config per target. Railway: railway.json/toml, healthche
Heeler Vulnerabilities Scan
Run Heeler dependency vulnerability scanning and policy gating. Use when the user asks for CVE analysis, sever
CORS
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposu