Artifact Security Reviewer — Security agent for Claude Code
Review a small shipped artifact for security: tool poisoning and instruction injection via descriptions, frontmatter, examples, or returned results; permission and scope minimization against SPEC.md's.
How to install Artifact Security Reviewer
Installs to ~/.claude/agents/koushikeverything-koushik-jr-artifact-security-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/koushikeverything/koushik-jr/HEAD/agents/artifact-security-reviewer.md -o ~/.claude/agents/koushikeverything-koushik-jr-artifact-security-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Artifact Security Reviewer does
name: artifact-security-reviewer description: "Review a small shipped artifact for security: tool poisoning and instruction injection via descriptions, frontmatter, examples, or returned results; permission and scope minimization against SPEC.md's R-IDs; untruthful MCP tool annotations; secrets in the tree or logs; script egress and dependency hygiene; identity claims trusted from message bodies; publish-surface hazards. A capability enforced only by prompt text is an automatic finding. Use
Alternatives in Security
- Claude Code System Prompts — by Piebald AI - All parts of Claude Code's system prompt, including builtin tool descriptions, sub agent promp 6.3k ★
- Vault Librarian — Run vault maintenance: detect orphan notes, find broken wikilinks, validate frontmatter completeness, flag sta 4.6k ★
- Security Code Reviewer — Use this agent when you need to review code for security vulnerabilities, input validation issues, or authenti 2.8k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Audit Skills Agents
Audits plugin skill and agent instruction quality, frontmatter validation, and cross-references. Dispatched by
LLM Sec Review
LLM/agent security review specialist — prompt injection, the Agents Rule of Two, tool-call authorization, mode
Ehs AI Safety
AI, agent and chatbot security specialist for the Ethical Hacker Squad. Reviews the instruction/data boundary,
Debate Prosecutor
L0.97 Adversarial Verification — reads diff + spec + test results, constructs the strongest-case argument that
Code Audit GitHub Workflows
Audits GitHub Actions workflow YAML and composite-action YAML for supply-chain, injection, permission, and sec
Sf Security Reviewer
Read-only Salesforce security review of CRUD and FLS enforcement, sharing, SOQL injection, secret handling, an
Related Skills
Agent Security Super Skill
Comprehensive AI agent security skill — prompt injection defense, skill validation, memory poisoning preventio
Crlf
Test for CRLF / HTTP response-splitting and host-header injection — Set-Cookie injection, cache poisoning, res
Aigis Kr
Deterministic, zero-dependency Python firewall for AI agents — MCP rug-pull, memory poisoning, indirect inject