Security Devils Advocate — Security agent for Claude Code
Adversarial security review of infrastructure, architecture, and code changes.
How to install Security Devils Advocate
Installs to ~/.claude/agents/stefanwb-claude-shared-security-devils-advocate.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/stefanwb/claude-shared/HEAD/agents/security-devils-advocate.md -o ~/.claude/agents/stefanwb-claude-shared-security-devils-advocate.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Devils Advocate does
name: security-devils-advocate description: "Adversarial security review of infrastructure, architecture, and code changes. Use before merging changes to Terraform/IaC, secrets management, networking, IAM policies, container definitions, or anything touching authentication, authorization, or data handling. Reasons from both attacker and defender perspectives and states whether the change improves, maintains, or degrades security posture. NOT for cost review (use cost-control-reviewer) or gen
Alternatives in Security
- Dashclaw Security Reviewer — Read-only security reviewer specialized for the DashClaw stack (Next.js 16 App Router, Neon/Postgres via repos 297 ★
- Finding Reporter — Phase 14 per-finding report authoring agent 125 ★
- Audit — Comprehensive 8-dimension project health audit — dependencies, security, code quality, architecture, performan 85 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Ehs Infra Cloud
Infrastructure and cloud security specialist for the Ethical Hacker Squad. Reviews Terraform and other IaC, Do
Cloud Security Reviewer
Cloud and infrastructure security specialist. Use proactively when reviewing AWS infrastructure, IAM policies,
Cloud Security
Delegates to this agent when the user asks about cloud security testing, AWS/Azure/GCP penetration testing, cl
Testing Pentester
⚡ Use this agent for authorized infrastructure-focused security testing - dependency and CVE scanning, CI/CD p
Devsecops Reviewer
Infrastructure and CI/CD security reviewer — scans Terraform, Dockerfiles, Kubernetes manifests, GitHub Action
Infra Platform Reviewer
Reviewer for infrastructure-as-code and platform — Terraform/Bicep quality, state, containers, drift, and blas
Related Skills
Review Iac Consistency
Audit infrastructure-as-code for per-environment drift, over-permissive IAM policies, unencrypted resources, a
Devils Advocate
REQUIRED after completing ANY spec or plan. You MUST challenge assumptions — unchallenged plans fail in produc
Claude Devils Advocate
Claude Code slash command that simulates a multi-round code review between an Author and Reviewer before openi