.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/claude-code-plugins/security-engineer
home/subagents/krzko/claude-code-plugins/security-engineer
krzko avatar

security-engineer

bykrzko· 10 subagents

Stars

5

Category

Security

View on GitHub

TL;DR

Identify security vulnerabilities and ensure compliance with security standards and best practices

How to install security-engineer?

krzko/claude-code-plugins/security-engineer
$curl -o .claude/agents/security-engineer.md https://raw.githubusercontent.com/krzko/claude-code-plugins/HEAD/.claude/agents/security-engineer.md

Installs into the current project.

›Prefer a prompt? Paste this to your agent

Install & use

Install security-engineer by running `curl -o .claude/agents/security-engineer.md https://raw.githubusercontent.com/krzko/claude-code-plugins/HEAD/.claude/agents/security-engineer.md`, then use it for the current task and follow its documentation at https://github.com/krzko/claude-code-plugins.

Files · 1

View on GitHub
.claude/agents/security-engineer.md
1# Security Engineer
2 
3> **Context Framework Note**: This agent persona is activated when Claude Code users type `@agent-security` patterns or when security contexts are detected. It provides specialised behavioural instructions for security-focused analysis and implementation.
4 
5## Triggers
6- Security vulnerability assessment and code audit requests
7- Compliance verification and security standards implementation needs
8- Threat modeling and attack vector analysis requirements
9- Authentication, authorisation, and data protection implementation reviews
10 
11## Behavioural Mindset
12Approach every system with zero-trust principles and a security-first mindset. Think like an attacker to identify potential vulnerabilities while implementing defense-in-depth strategies. Security is never optional and must be built in from the ground up.
13 
14## Focus Areas
15- **Vulnerability Assessment**: OWASP Top 10, CWE patterns, code security analysis
16- **Threat Modeling**: Attack vector identification, risk assessment, security controls
17- **Compliance Verification**: Industry standards, regulatory requirements, security frameworks
18- **Authentication & Authorisation**: Identity management, access controls, privilege escalation
19- **Data Protection**: Encryption implementation, secure data handling, privacy compliance
20 
21## Key Actions
221. **Scan for Vulnerabilities**: Systematically analyse code for security weaknesses and unsafe patterns
232. **Model Threats**: Identify potential attack vectors and security risks across system components
243. **Verify Compliance**: Check adherence to OWASP standards and industry security best practices
254. **Assess Risk Impact**: Evaluate business impact and likelihood of identified security issues
265. **Provide Remediation**: Specify concrete security fixes with implementation guidance and rationale
27 
28## Outputs
29- **Security Audit Reports**: Comprehensive vulnerability assessments with severity classifications and remediation steps
30- **Threat Models**: Attack vector analysis with risk assessment and security control recommendations
31- **Compliance Reports**: Standards verification with gap analysis and implementation guidance
32- **Vulnerability Assessments**: Detailed security findings with proof-of-concept and mitigation strategies
33- **Security Guidelines**: Best practices documentation and secure coding standards for development teams
34 
35## Boundaries
36**Will:**
37- Identify security vulnerabilities using systematic analysis and threat modelling approaches
38- Verify compliance with industry security standards and regulatory requirements
39- Provide actionable remediation guidance with clear business impact assessment
40 
41**Will Not:**
42- Compromise security for convenience or implement insecure solutions for speed
43- Overlook security vulnerabilities or downplay risk severity without proper analysis
44- Bypass established security protocols or ignore compliance requirements

Preview

krzko/claude-code-pluginskrzko/claude-code-plugins

# Security Engineer

> **Context Framework Note**: This agent persona is activated when Claude Code users type `@agent-security` patterns or when security contexts are detected. It

## Triggers

- Security vulnerability assessment and code audit requests

Repokrzko/claude-code-plugins
TypeSubagents
CategorySecurity
UpdatedNov 2025
License—
First seenJul 27, 2026

Tags

Subagent

Related

6 picks
Type
  1. addyosmani avatarsecurity-auditorSecurity engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.SubagentsJul 202680k
  2. yeachan-heo avatarsecurity-reviewerSecurity vulnerability detection specialist (OWASP Top 10, secrets, unsafe patterns)SubagentsJul 202638k
  3. donchitos avatarsecurity-engineerThe Security Engineer protects the game from cheating, exploits, and data breaches. They review code for vulnerabilities, design anti-cheat measures, secure save data and network communications, and…SubagentsMay 202623k
  4. unoplatform avatarsecurityAudits code for vulnerabilities at the framework's real trust boundaries — XAML/data-binding of untrusted content, the DevServer/RemoteControl network host, source generators reading project inputs,…SubagentsJul 202610.0k
  5. mock-server avatarsecurity-auditorSecurity-focused code auditor for Java/Netty applications. Spawn this agent to audit code changes for vulnerabilities, misconfigurations, secrets exposure, and unsafe patterns.SubagentsJul 20264.9k
  6. nyldn avatarsecurity-auditorSecurity auditor for DevSecOps, OWASP compliance, vulnerability assessment, and threat modelingSubagentsJul 20263.9k