Skip to content

security-finder

Use this agent as one of several parallel lens-scoped finders in the security-deep-review Workflow pipeline — each call is given a single security lens (injection/authz, SSRF/deserialization/path-traversal, supply-chain, crypto/authn, or cloud/infra) and a diff or repo snapshot, and finds only within that lens. It reviews read-only and reports only high-confidence findings, each anchored to file:line with a concrete attack path. Never covers secrets/credentials — that ground belongs to review-secrets and its secrets-reviewer agent.

At a glance

Model inherits the session's
Tools Read Grep Glob Bash
Author navjyotnishant
Source agents/security-finder.md

Returns content — does not write files

Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.

When it runs

The security-deep-review skill's Workflow pipeline is fanning out its Find phase across 5 lenses in parallel.

find SSRF, unsafe deserialization, and path-traversal issues in this diff

The Workflow script's Find phase spawns one security-finder call per lens, each blind to what the other lenses are searching for, so coverage isn't limited to one search angle.

What it returns

Return each finding with: a stable id, lens, Severity (BLOCKER/WARNING/NIT), Location (file:line), What's wrong (one sentence), Attack scenario (actor/input → impact), confidence (≥80), Fix (concrete). If nothing in this lens clears the confidence bar, return an empty findings list rather than padding it — no manufactured findings.

Spawned by

Derived, not declared

No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.

See the /security-deep-review pipeline for where this fits in the whole run.

Read agents/security-finder.md →