Canvas To Code Auditor — Security agent for Claude Code
Read-only codebase audit for the target surface declared in Gate 0. Returns route status, components/hooks/lib used, sub-routes, and behaviors to port.
How to install Canvas To Code Auditor
Installs to ~/.claude/agents/opensesh-canvas-to-code-canvas-to-code-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/opensesh/canvas-to-code/HEAD/agents/canvas-to-code-auditor.md -o ~/.claude/agents/opensesh-canvas-to-code-canvas-to-code-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Canvas To Code Auditor does
name: canvas-to-code-auditor description: Read-only codebase audit for the target surface declared in Gate 0. Returns route status, components/hooks/lib used, sub-routes, and behaviors to port. model: sonnet tools: Read, Grep, Glob
Design-to-Code Auditor
You audit the consumer's codebase for the target surface. Read-only — you never edit anything.
Inputs
targetRoutefromstatus.json(e.g./brand-hub).isExistingRouteboolean.- Consumer config (`.canvas-to-code/confi
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Retool Endpoint Audit — Checks a migration slice against the main app's API surface — whether a local implementation duplicates an exi 7.2k ★
- Claude Code System Prompts — by Piebald AI - All parts of Claude Code's system prompt, including builtin tool descriptions, sub agent promp 6.3k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Authz Auditor
Phase 6 authorization and access-control audit agent that enumerates every route/handler/consumer across the c
Canvas To Code PM
Conversational PM orchestrator for Canvas-to-Code. Runs the eleven gates (intake → materials → DS-alignment →
Infrastructure Master
Use this agent when managing infrastructure components, system stability, process persistence, health monitori
Amm Specialist
AMM-specific audit specialist. Uniswap V2/V3/V4, Curve, Balancer, Berachain BEX, custom AMMs. Use when the tar
Worktree Agent Security
Implementer agent specialized in security/hardening, working in ITS OWN git worktree. Launched by the orchestr
Intent Cartographer
Scans repo-local security documentation (SECURITY.md, README, docs/, threat-model files, inline pragmas) and p
Related Skills
Canvas To Code Guardrails
Editor-time lint reminders for projects using Canvas-to-Code. Auto-activates when the repo contains .claude-de
Gsd Ruleset Drift
Surface drift between declared .github/rulesets/ and live branch protection; --apply runs the LIVE remediation
Design Brief
Use when a design request is broad or unclear and you do not know which specialist it needs. Reads the brief,