Web Auditor — Security agent for Claude Code
Web application security specialist.
How to install Web Auditor
Installs to ~/.claude/agents/tobiasveiga00-claude-security-audit-web-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/TobiasVeiga00/claude-security-audit/HEAD/agents/web-auditor.md -o ~/.claude/agents/tobiasveiga00-claude-security-audit-web-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Web Auditor does
name: web-auditor description: Web application security specialist. Launched by the audit orchestrator with assigned coverage units and surface-map hotspots; returns compact findings, never prose. tools: Read, Glob, Grep, Bash model: sonnet color: red
You are a web application security specialist working as one domain auditor inside a larger audit. You have your own context window; use it to go deep, and return only compact findings.
Contract
**Read first**, both in ${CLAUDE_PLUGIN
Alternatives in Security
- Wcag Audit Patterns — Comprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation 31.9k ★
- Retool Endpoint Audit — Checks a migration slice against the main app's API surface — whether a local implementation duplicates an exi 7.2k ★
- Claude Code System Prompts — by Piebald AI - All parts of Claude Code's system prompt, including builtin tool descriptions, sub agent promp 6.3k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
LLM Auditor
LLM and agentic application security specialist. Launched by the audit orchestrator with assigned coverage uni
API Auditor
API security specialist. Launched by the audit orchestrator with assigned coverage units and surface-map hotsp
iOS Hunter
Hunts one assigned iOS attack surface (IPC and entry points, data storage, network security, binary and secret
Audit Collector
Read-only subagent that runs an audit skill (default /audit-setup) and returns a compact severity-bucketed fin
Knowledge Base Loader
Phase KB0 intake agent that converts staged, untrusted application documentation into a cited, security-orient
Webvuln Surface
Builds the TESTABLE request surface for the active web-vuln tier from an ingested program. Merges the passive
Related Skills
Hewn
Claude Code CLI wrapper: routes every turn to a compact answer shape (IR, prose+code, findings, polished, cave
Cognitive Load
How much must an engineer hold in their head to change this unit? Measures the inward cost — files to read plu
User Meetings
Shows all meetings assigned to a specific rep for a period — volume, statuses, and no-show rate — to surface r