Sdlc Security — Security agent for Claude Code
Runs a full OWASP Top 10 (2025) audit, plus OWASP LLM Top 10 (2025) when AI/LLM components are present, against a diff or branch.
How to install Sdlc Security
Installs to ~/.claude/agents/rafatchanz-sdlc-orchestrator-sdlc-security.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/RafaTchanz/sdlc-orchestrator/HEAD/agents/sdlc-security.md -o ~/.claude/agents/rafatchanz-sdlc-orchestrator-sdlc-security.md Restart Claude Code, or start a new session, for it to be picked up.
What Sdlc Security does
name: sdlc-security description: Runs a full OWASP Top 10 (2025) audit, plus OWASP LLM Top 10 (2025) when AI/LLM components are present, against a diff or branch. Dispatched only by the /sdlc trunk or the /sdlc-security-review skill via Agent(subagent_type: "sdlc-security") — never invoked directly. model: sonnet tools: Read, Bash, Grep, Glob, Write
Viúva Negra — Security Review
You are Natasha Romanoff: you assume you're being watched and you audit accordingly. Every check below get
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Security Audit Analyzer — Комплексный анализ безопасности веб-приложений с JavaScript frontend и PHP backend 571 ★
- Genblaze Maintainer — The Genblaze Maintainer — autonomous guardian of the Genblaze repo 560 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Timps AI Safety Agent
Audit LLM applications against OWASP LLM Top 10 (LLM01-LLM10) with mitigations. Use the timps_ai_safety_agent
Critic Security
Review code for OWASP-style security issues (injection, authn/authz, secrets, supply chain, LLM-specific) in p
Harness Security Reviewer
Security reviewer — self-scoping OWASP Top 10 and STRIDE audit of a pinned diff, covering auth, secrets, input
Timps API Security Tester
Run an OWASP API Security Top-10 (2023) audit against an OpenAPI spec or live endpoint — broken auth, BOLA, ma
Appsec Engineer
Application Security Engineer (Tier 3): reviews and tests code against OWASP Top 10:2025 / ASVS — authenticati
Maintainer Security Reviewer
Use this agent before signing a maintainer Build gate on the sdlc-plugin repo. Reviews the current diff for se
Related Skills
Security Audit Stride
Chạy checklist bảo mật OWASP Top 10 + STRIDE trước bước review cuối của Tech Lead trong WF-REVIEW-CRIT (luôn c
Security Audit
Audit de securite complet d'une web app (OWASP Top 10, CWE/CVE, headers, auth, paywall, infra). Genere un rapp
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat