feat: sync content definitions from core repo
Copy all TOML content definitions from librefang core repo: - 33 agent definitions (agents/*/agent.toml) - 14 hand definitions with docs (hands/*/HAND.toml + SKILL.md) - 25 integration templates (integrations/*.toml) - 2 example skill definitions (skills/custom-skill-*) - 1 new provider (providers/vertex-ai.toml) Part of the framework-vs-content registry split (RFC v0.7).
This commit is contained in:
1 parent
ded26ce300
commit
17d32ed4a7
90 files changed
+13549
No files matched your search
@@ -0,0 +1,58 @@
|
||||
name = "security-auditor"
|
||||
version = "0.4.3-beta3-20260314"
|
||||
description = "Security specialist. Reviews code for vulnerabilities, checks configurations, performs threat modeling."
|
||||
author = "librefang"
|
||||
module = "builtin:chat"
|
||||
tags = ["security", "audit", "vulnerability"]
|
||||
|
||||
[metadata.routing]
|
||||
aliases = ["security audit", "vulnerability review", "threat model", "security review", "attack surface review"]
|
||||
weak_aliases = ["security", "vulnerability", "owasp", "audit"]
|
||||
|
||||
[model]
|
||||
provider = "default"
|
||||
model = "default"
|
||||
api_key_env = "DEEPSEEK_API_KEY"
|
||||
max_tokens = 4096
|
||||
temperature = 0.2
|
||||
system_prompt = """You are Security Auditor, a cybersecurity expert running inside the LibreFang Agent OS.
|
||||
|
||||
Your focus areas:
|
||||
- OWASP Top 10 vulnerabilities
|
||||
- Input validation and sanitization
|
||||
- Authentication and authorization flaws
|
||||
- Cryptographic misuse
|
||||
- Injection attacks (SQL, command, XSS, SSTI)
|
||||
- Insecure deserialization
|
||||
- Secrets management (hardcoded keys, env vars)
|
||||
- Dependency vulnerabilities
|
||||
- Race conditions and TOCTOU bugs
|
||||
- Privilege escalation paths
|
||||
|
||||
When auditing code:
|
||||
1. Map the attack surface
|
||||
2. Trace data flow from untrusted inputs
|
||||
3. Check trust boundaries
|
||||
4. Review error handling (info leaks)
|
||||
5. Assess cryptographic implementations
|
||||
6. Check dependency versions
|
||||
|
||||
Severity levels: CRITICAL / HIGH / MEDIUM / LOW / INFO
|
||||
Report format: Finding → Impact → Evidence → Remediation"""
|
||||
|
||||
[[fallback_models]]
|
||||
provider = "default"
|
||||
model = "default"
|
||||
api_key_env = "GROQ_API_KEY"
|
||||
|
||||
[schedule]
|
||||
proactive = { conditions = ["event:agent_spawned", "event:agent_terminated"] }
|
||||
|
||||
[resources]
|
||||
max_llm_tokens_per_hour = 150000
|
||||
|
||||
[capabilities]
|
||||
tools = ["file_read", "file_list", "shell_exec", "memory_store", "memory_recall"]
|
||||
memory_read = ["*"]
|
||||
memory_write = ["self.*", "shared.*"]
|
||||
shell = ["cargo audit *", "cargo tree *", "git log *"]
|
||||
Reference in new issue
Block a user