Forensic Specialist — Security agent for Claude Code
Use PROACTIVELY for security audits or when suspicious patterns detected.
How to install Forensic Specialist
Installs to ~/.claude/agents/joaoariedi-hefesto-forensic-specialist.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/joaoariedi/hefesto/HEAD/agents/forensic-specialist.md -o ~/.claude/agents/joaoariedi-hefesto-forensic-specialist.md Restart Claude Code, or start a new session, for it to be picked up.
What Forensic Specialist does
model: fable name: forensic-specialist description: Use PROACTIVELY for security audits or when suspicious patterns detected. Cybersecurity specialist for defensive forensics, threat hunting, malware investigation, and IOC generation with proper chain of custody. Examples: Context: Suspected compromise. user: 'System may be compromised, analyze it' assistant: 'I'll use forensic-specialist for IOC analysis' Defensive security analysis. Cont
Alternatives in Security
- Django Reviewer — Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi 243.5k ★
- Gitnexus Security Boundary Reviewer — GitNexus security and trust-boundary reviewer 45.8k ★
- Malware Analyst — You are an elite malware analyst focused on defensive security research 31.9k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
PR Security Review
Use this agent to perform a security analysis of a pull request BEFORE checking out or running any code locall
Chain
Supply chain security — SBOM generation, dependency scanning, third-party risk, license compliance
Supply Chain Analyst
Software supply-chain security expert. Deep on Socket.dev (behavioral package analysis), Syft (SBOM generation
Observability Purist
The divine bringer of light into the darkness of unobservable code. Use this agent to audit and enforce proper
ForensicAgent
Forensic security analyst — PII detection, secret scanning, identity leak auditing across git history, staged
Kavach History
KAVACH git-history forensics specialist. Mines commit history for security-relevant commits with no CVE/GHSA l
Related Skills
Threat Report Killchain
Claude skill to convert CTI reports into cyber kill chain, Diamond Model views and create a TTP-to-ATT&CK/ATLA
Static Malware Analysis For Claude Code
A Skill for Claude Code to perform static malware analysis on a suspicious file.
Heeler Malicious Package Scan
Detect suspicious or malicious dependencies using Heeler package-risk intelligence. Use when a new dependency