Files
librefang-registry/agents/security-auditor/agent.toml
T
Evan d4f15fd662 feat: add web_search capability to all agents and hands (#74)
Adds the web_search tool to every agent.toml and hand HAND.toml that did
not already declare it. Without this capability the runtime gates the
tool with 'Capability denied: tool not in allowed list', leaving agents
unable to perform web searches even when a search provider is
configured.

For tools arrays that already contained web_fetch, web_search is
inserted directly after it (its natural companion). For arrays without
web_fetch, web_search is appended to the end.

24 files updated total: 21 agents and 3 hands.
2026-04-25 23:07:24 +09:00

101 lines
2.9 KiB
TOML

name = "security-auditor"
version = "0.4.3-beta3-20260314"
description = "Security specialist. Reviews code for vulnerabilities, checks configurations, performs threat modeling."
author = "librefang"
module = "builtin:chat"
tags = ["security", "audit", "vulnerability"]
[metadata.routing]
aliases = [
"security audit",
"vulnerability review",
"threat model",
"security review",
"attack surface review",
]
weak_aliases = ["security", "vulnerability", "owasp", "audit"]
[model]
provider = "default"
model = "default"
api_key_env = "DEEPSEEK_API_KEY"
max_tokens = 4096
temperature = 0.2
system_prompt = """You are Security Auditor, a cybersecurity expert running inside the LibreFang Agent OS.
Your focus areas:
- OWASP Top 10 vulnerabilities
- Input validation and sanitization
- Authentication and authorization flaws
- Cryptographic misuse
- Injection attacks (SQL, command, XSS, SSTI)
- Insecure deserialization
- Secrets management (hardcoded keys, env vars)
- Dependency vulnerabilities
- Race conditions and TOCTOU bugs
- Privilege escalation paths
When auditing code:
1. Map the attack surface
2. Trace data flow from untrusted inputs
3. Check trust boundaries
4. Review error handling (info leaks)
5. Assess cryptographic implementations
6. Check dependency versions
Severity levels: CRITICAL / HIGH / MEDIUM / LOW / INFO
Report format: Finding → Impact → Evidence → Remediation"""
[[fallback_models]]
provider = "default"
model = "default"
api_key_env = "GROQ_API_KEY"
[schedule]
proactive = { conditions = ["event:agent_spawned", "event:agent_terminated"] }
[resources]
max_llm_tokens_per_hour = 150000
[capabilities]
tools = [
"file_read",
"file_list",
"shell_exec",
"memory_store",
"memory_recall",
"web_search",
]
memory_read = ["*"]
memory_write = ["self.*", "shared.*"]
shell = ["cargo audit *", "cargo tree *", "git log *"]
[i18n.zh]
name = "安全审计员"
description = "安全专家:审查代码漏洞、检查配置、做威胁建模。"
[i18n.zh-TW]
name = "安全稽核員"
description = "安全專家:審查程式碼漏洞、檢查設定、進行威脅建模。"
[i18n.ja]
name = "セキュリティ監査官"
description = "コードの脆弱性レビュー、設定チェック、脅威モデリングを行うセキュリティ専門家。"
[i18n.ko]
name = "보안 감사관"
description = "코드 취약점 검토, 설정 점검, 위협 모델링을 수행하는 보안 전문가."
[i18n.de]
name = "Sicherheits-Auditor"
description = "Sicherheitsexperte: prüft Code auf Schwachstellen, kontrolliert Konfigurationen und führt Threat Modeling durch."
[i18n.es]
name = "Auditor de seguridad"
description = "Especialista en seguridad: revisa vulnerabilidades de código, verifica configuraciones y realiza threat modeling."
[i18n.fr]
name = "Auditeur sécurité"
description = "Expert sécurité : revue des vulnérabilités de code, vérification des configurations et modélisation des menaces."