Ciso — Security agent for Claude Code
Evaluates security implications — attack surfaces, data exposure, credential handling, supply chain.
How to install Ciso
Installs to ~/.claude/agents/renozoic-foundry-forge-public-ciso.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Renozoic-Foundry/forge-public/HEAD/.claude/agents/ciso.md -o ~/.claude/agents/renozoic-foundry-forge-public-ciso.md Restart Claude Code, or start a new session, for it to be picked up.
What Ciso does
description: "Evaluates security implications — attack surfaces, data exposure, credential handling, supply chain" model: sonnet effort: high tools: Read, Grep, Glob, WebSearch disallowedTools: [Write, Edit, NotebookEdit]
FORGE Role: CISO (Chief Information Security Officer)
Your Role
You evaluate security implications — attack surfaces, data exposure, credential handling, and supply chain risks. You think like an attacker assessing this change.
Key Questions
- What new attac
Alternatives in Security
- Review Security — Reviews code changes for security vulnerabilities including injection attacks, sensitive data exposure, insecu 432 ★
- Offensive Security Engineer — Red-team the verification engine 179 ★
- Chain — Supply chain security — SBOM generation, dependency scanning, third-party risk, license compliance 73 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Audit Security
Use this agent to conduct a security audit (CISO perspective) of a codebase: auth bypasses, CSRF, prompt injec
Deep Security Auditor
Adversarial red-team and security compliance specialist. Inspects ASTs for prompt injections, credential leaks
Tux
Security hardening agent for auditing and fortifying MAGI's attack surface — the proxy layer, Electron securit
Testing Pentester
⚡ Use this agent for authorized infrastructure-focused security testing - dependency and CVE scanning, CI/CD p
Code Audit GitHub Workflows
Audits GitHub Actions workflow YAML and composite-action YAML for supply-chain, injection, permission, and sec
Executor Security Reviewer
Security reviewer — evaluates implementation against OWASP Top 10, injection, authorization, race conditions,
Related Skills
Agentshield
Scan the plugin's own agent-config surfaces (MCP, hooks, skills, CLAUDE.md, supply chain) for known attack pat
Coding Agent Security Checklist
Stop your AI coding agent (Claude Code, Cursor, Codex) from installing malware straight out of llms.txt docume
Skill Lint
Security scanner for Claude Code / agent skills. Catches prompt injection, obfuscation, credential exfiltratio