Claudehut Security Auditor — Security agent for Claude Code
Spring-security review of the diff — authn/authz, filter chain, injection, secrets, deserialization, data exposure.
How to install Claudehut Security Auditor
Installs to ~/.claude/agents/taipt1504-claudehut-claudehut-security-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/taipt1504/claudehut/HEAD/agents/claudehut-security-auditor.md -o ~/.claude/agents/taipt1504-claudehut-claudehut-security-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Claudehut Security Auditor does
name: claudehut-security-auditor description: Spring-security review of the diff — authn/authz, filter chain, injection, secrets, deserialization, data exposure. Spawned by claudehut:review when a hunk touches auth, filters, secrets or deserialization. model: opus effort: high tools: Read, Grep, Glob, Bash maxTurns: 40 color: red
You are a senior application-security engineer acting as ClaudeHut's security lane, spawned by `claudehut:review`. You hunt exploitable defects, not style. App
Alternatives in Security
- Review Security — Reviews code changes for security vulnerabilities including injection attacks, sensitive data exposure, insecu 432 ★
- Electron Ipc Engineer — Use this agent for any change that touches Electron IPC — adding/removing channels, modifying main.ts ↔ preloa 204 ★
- Authz Auditor — Phase 6 authorization and access-control audit agent that enumerates every route/handler/consumer across the c 125 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Critic Security
Review code for OWASP-style security issues (injection, authn/authz, secrets, supply chain, LLM-specific) in p
Lens Security
Security lens of the production readiness audit. Attacks the codebase on paper - injection, SSRF, path travers
Maintainer Security Reviewer
Use this agent before signing a maintainer Build gate on the sdlc-plugin repo. Reviews the current diff for se
Health Check
Adversarial audit of a delivered diff — checks whether it satisfies every acceptance criterion and whether eve
Cybersecurity Expert
Threat-models code and architecture changes across trust boundaries, authn/authz flows, secrets handling, and
Psychodrama Security
Use ONLY by psychodrama-protocol skill orchestrator. Evaluates theses through threat model / attack surface /
Related Skills
Security Auditor
Audits code for OWASP-class vulnerabilities — injection, auth flaws, secret leaks, unsafe deserialization.
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat