Devsecops Reviewer — Security agent for Claude Code
Infrastructure and CI/CD security reviewer — scans Terraform, Dockerfiles, Kubernetes manifests, GitHub Actions workflows, and dependency lockfiles for misconfigurations, supply chain risks, and pipel.
How to install Devsecops Reviewer
Installs to ~/.claude/agents/marvinrichter-clarc-devsecops-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/marvinrichter/clarc/HEAD/agents/devsecops-reviewer.md -o ~/.claude/agents/marvinrichter-clarc-devsecops-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Devsecops Reviewer does
name: devsecops-reviewer description: Infrastructure and CI/CD security reviewer — scans Terraform, Dockerfiles, Kubernetes manifests, GitHub Actions workflows, and dependency lockfiles for misconfigurations, supply chain risks, and pipeline vulnerabilities. For application-code OWASP/injection/auth issues, use security-reviewer instead. model: sonnet tools: ["Read", "Glob", "Grep", "Bash"] uses_skills:
- supply-chain-security
- security-review
You are an automated DevSecOps securit
Alternatives in Security
- Django Reviewer — Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi 243.5k ★
- Gitnexus Security Boundary Reviewer — GitNexus security and trust-boundary reviewer 45.8k ★
- Aegis — You are a specialized security agent 3.6k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Ehs Infra Cloud
Infrastructure and cloud security specialist for the Ethical Hacker Squad. Reviews Terraform and other IaC, Do
DevOps Senior
[zakr] Senior DevOps engineer. Use for Dockerfile review, Kubernetes manifest audit, Terraform plan review, Gi
Pipeline Hardener
Durcissement de la chaîne de livraison — Dockerfile, docker-compose, workflows GitHub Actions (security gates
Dep Cve Auditor
Audits dependency manifests for CVEs (npm/pip/cargo/govulncheck) to disk. Manifests only — security-audit-work
Code Audit GitHub Workflows
Audits GitHub Actions workflow YAML and composite-action YAML for supply-chain, injection, permission, and sec
Security Currency
Application & supply-chain security currency expert. Checks pinned dependencies against advisory databases, au
Related Skills
Lockdown
Per-repo supply-chain hardening — detects the package managers, Dockerfiles, and CI in use, then guides you th
Review Dependency Risk
Audit dependency manifests for supply-chain risk: unmaintained or typosquatted packages, license conflicts, un
J DevOps
DevOps consultation — CI/CD, containers, IaC, and observability. Use when configuring Docker, Kubernetes, Terr