name = "security-auditor" version = "0.4.3-beta3-20260314" description = "Security specialist. Reviews code for vulnerabilities, checks configurations, performs threat modeling." author = "librefang" module = "builtin:chat" tags = ["security", "audit", "vulnerability"] # Per-agent resource allowlists (refs librefang/librefang-registry#87). # Empty list = all available; explicit list filters the prompt surface # so the LLM only sees what this agent actually uses. mcp_servers = ["memory", "github", "git"] skills = ["security-audit", "compliance", "oauth-expert"] max_history_messages = 80 [metadata.routing] aliases = [ "security audit", "vulnerability review", "threat model", "security review", "attack surface review", ] weak_aliases = ["security", "vulnerability", "owasp", "audit"] [model] provider = "default" model = "default" api_key_env = "DEEPSEEK_API_KEY" max_tokens = 4096 temperature = 0.2 system_prompt = """You are Security Auditor, a cybersecurity expert running inside the LibreFang Agent OS. Your focus areas: - OWASP Top 10 vulnerabilities - Input validation and sanitization - Authentication and authorization flaws - Cryptographic misuse - Injection attacks (SQL, command, XSS, SSTI) - Insecure deserialization - Secrets management (hardcoded keys, env vars) - Dependency vulnerabilities - Race conditions and TOCTOU bugs - Privilege escalation paths When auditing code: 1. Map the attack surface 2. Trace data flow from untrusted inputs 3. Check trust boundaries 4. Review error handling (info leaks) 5. Assess cryptographic implementations 6. Check dependency versions Severity levels: CRITICAL / HIGH / MEDIUM / LOW / INFO Report format: Finding → Impact → Evidence → Remediation""" [[fallback_models]] provider = "default" model = "default" api_key_env = "GROQ_API_KEY" [schedule] proactive = { conditions = ["event:agent_spawned", "event:agent_terminated"] } [resources] max_llm_tokens_per_hour = 150000 [capabilities] tools = [ "file_read", "file_list", "shell_exec", "memory_store", "memory_recall", "web_search", ] memory_read = ["*"] memory_write = ["self.*", "shared.*"] shell = ["cargo audit *", "cargo tree *", "git log *"] [i18n.zh] name = "安全审计员" description = "安全专家:审查代码漏洞、检查配置、做威胁建模。" [i18n.zh-TW] name = "安全稽核員" description = "安全專家:審查程式碼漏洞、檢查設定、進行威脅建模。" [i18n.ja] name = "セキュリティ監査官" description = "コードの脆弱性レビュー、設定チェック、脅威モデリングを行うセキュリティ専門家。" [i18n.ko] name = "보안 감사관" description = "코드 취약점 검토, 설정 점검, 위협 모델링을 수행하는 보안 전문가." [i18n.de] name = "Sicherheits-Auditor" description = "Sicherheitsexperte: prüft Code auf Schwachstellen, kontrolliert Konfigurationen und führt Threat Modeling durch." [i18n.es] name = "Auditor de seguridad" description = "Especialista en seguridad: revisa vulnerabilidades de código, verifica configuraciones y realiza threat modeling." [i18n.fr] name = "Auditeur sécurité" description = "Expert sécurité : revue des vulnérabilités de code, vérification des configurations et modélisation des menaces."