Security Triage — Security agent for Claude Code
Independently evaluate a single security finding to decide whether it is a real, exploitable vulnerability or a false positive.
How to install Security Triage
Installs to ~/.claude/agents/wrxck-auto-audit-security-triage.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/wrxck/auto-audit/HEAD/agents/security-triage.md -o ~/.claude/agents/wrxck-auto-audit-security-triage.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Triage does
name: security-triage description: "Independently evaluate a single security finding to decide whether it is a real, exploitable vulnerability or a false positive. Reads the finding + surrounding code, then writes a verdict (confirmed/false_positive) with reasoning back into the finding JSON. Invoke this when a finding is in the `discovered` state." tools: "Bash Read Grep Glob" model: "claude-sonnet-4-6"
You are a senior application security engineer doing **triage**. Your one job: for
Alternatives in Security
- Audit Verifier — Adversarially verifies one candidate finding from /bug-audit — tries to REFUTE it by reading the code and, whe 335 ★
- After Confirming A Vulnerability — findings.sh update vuln --status confirmed --confirmed-by "poc-validator" \ --poc-output " " findings.sh updat 213 ★
- Code Reviewer Quality — Use this agent as the second stage of a code review, after spec compliance is confirmed — evaluating code qual 186 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Audit Finding Verifier
Verifies a single reported audit finding against the actual codebase. Determines whether it is confirmed, a fa
Audit Sweep
A read-only audit or survey sweep — reviewing a corpus against a stated rule and reporting what violates it, w
Finding Chain Synthesizer
Chains confirmed audit findings into multi-step, cross-domain exploit candidates and searches for a unique eme
Vuln Verifier
Adjudicates a single candidate security finding produced by the vuln-analyst hunter. Independently re-reads th
Threat Detection Engineer
Principal Threat Detection Engineer with VETO authority over detection-as-code coverage, false-positive-rate d
Web Pentester
Authorized offensive security testing of web applications you own or have written permission to test - finding
Related Skills
False Positive Triage
Use when investigating a suspected false positive in drift detection, reducing false positive rates, or adding
Reviewer Verify
You are the adversarial verifier for the candidate pull-request findings raised against one file. Your only jo
Gov Metrics
Governance metrics — measure whether the gates actually work. Block rate, override/waiver rate, false-block pr