Manifest Curator — Security agent for Claude Code
Review the actual Claude or Codex manifests, catalogs and pinned revisions against their own schemas.
How to install Manifest Curator
Installs to ~/.claude/agents/v-songbird-foundry-manifest-curator.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/V-Songbird/foundry/HEAD/.claude/agents/manifest-curator.md -o ~/.claude/agents/v-songbird-foundry-manifest-curator.md Restart Claude Code, or start a new session, for it to be picked up.
What Manifest Curator does
name: manifest-curator description: Review the actual Claude or Codex manifests, catalogs and pinned revisions against their own schemas. Audit by default; report evidence and uncertainty. model: sonnet maxTurns: 30 tools: Read, Edit, Glob, Grep, WebFetch
Manifest review for Foundry
Audit by default. Fix mode permits only the mechanical corrections explicitly within the task's scope; it does not authorize changing plugin behavior, publishing a release or rewriting unrelated local wor
Alternatives in Security
- Rust-claude-code-api V0.6.0 Quality Audit Report — Date: 2026-02-11 Auditors: Claude Code (team lead) + Codex (security) + Gemini CLI (API ergonomics) Method: 3 152 ★
- Finding Reporter — Phase 14 per-finding report authoring agent 125 ★
- Issue Claim Auditor — PRFlow's implement-phase Issue-Claim Audit agent 115 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Principal Code Reviewer
Review non-trivial Kotlin/Java changes, crash/file/auth/navigation/lifecycle/security fixes, or multi-file dif
Pov Curator
Load when the installer wants to fork pov.md for their own taste, append a one-liner to gotchas.md after a rea
Doc Consistency Reviewer
Audit plugin README parity, platform-specific benchmark evidence and community documentation against Foundry's
Worker Review
Reviews an existing PR. Runs /review (plus /cso if security-adjacent); /codex review is opt-in (OFF by default
Deep Repo Auditor
Cross-validated deep repository audit — dual AI models (Sonnet + Codex) in parallel, consolidated report with
Security Currency
Application & supply-chain security currency expert. Checks pinned dependencies against advisory databases, au
Related Skills
Check Updates
Check our pinned flake inputs + packages against upstream and report what's ready to update
Synapse Ingest
Ingest a new monthly batch of academic papers into Synapse — runs the full pipeline (populate_manifest → lint_
Ke Test
Select and run risk-based verification checks, then record exact evidence and remaining uncertainty.