Skip to content

security-verifier

Use this agent as an independent adversarial verifier in the security-deep-review Workflow pipeline — given one candidate finding from security-finder, it actively tries to REFUTE it (is the input actually reachable/untrusted, does an existing check elsewhere neutralize it, do the cited lines still match) rather than confirm it. Read-only, verify-only — never invents new findings, so majority-vote semantics across independent verifiers stay meaningful.

At a glance

Model inherits the session's
Tools Read Grep Glob
Author navjyotnishant
Source agents/security-verifier.md

Returns content — does not write files

Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.

When it runs

The security-deep-review skill's Workflow pipeline has a candidate finding from the injection-authz lens and needs 3 independent verifiers to weigh in before it survives to the report.

verify this SQL injection finding at db/query.py:42

The Workflow script's Verify phase spawns N=3 independent security-verifier calls per finding, each blind to the others' votes; majority-refute kills the finding before it reaches synthesis.

Spawned by

Derived, not declared

No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.

See the /security-deep-review pipeline for where this fits in the whole run.

Read agents/security-verifier.md →