Adds the web_search tool to every agent.toml and hand HAND.toml that did not already declare it. Without this capability the runtime gates the tool with 'Capability denied: tool not in allowed list', leaving agents unable to perform web searches even when a search provider is configured. For tools arrays that already contained web_fetch, web_search is inserted directly after it (its natural companion). For arrays without web_fetch, web_search is appended to the end. 24 files updated total: 21 agents and 3 hands.
101 lines
2.9 KiB
TOML
101 lines
2.9 KiB
TOML
name = "security-auditor"
|
|
version = "0.4.3-beta3-20260314"
|
|
description = "Security specialist. Reviews code for vulnerabilities, checks configurations, performs threat modeling."
|
|
author = "librefang"
|
|
module = "builtin:chat"
|
|
tags = ["security", "audit", "vulnerability"]
|
|
|
|
[metadata.routing]
|
|
aliases = [
|
|
"security audit",
|
|
"vulnerability review",
|
|
"threat model",
|
|
"security review",
|
|
"attack surface review",
|
|
]
|
|
weak_aliases = ["security", "vulnerability", "owasp", "audit"]
|
|
|
|
[model]
|
|
provider = "default"
|
|
model = "default"
|
|
api_key_env = "DEEPSEEK_API_KEY"
|
|
max_tokens = 4096
|
|
temperature = 0.2
|
|
system_prompt = """You are Security Auditor, a cybersecurity expert running inside the LibreFang Agent OS.
|
|
|
|
Your focus areas:
|
|
- OWASP Top 10 vulnerabilities
|
|
- Input validation and sanitization
|
|
- Authentication and authorization flaws
|
|
- Cryptographic misuse
|
|
- Injection attacks (SQL, command, XSS, SSTI)
|
|
- Insecure deserialization
|
|
- Secrets management (hardcoded keys, env vars)
|
|
- Dependency vulnerabilities
|
|
- Race conditions and TOCTOU bugs
|
|
- Privilege escalation paths
|
|
|
|
When auditing code:
|
|
1. Map the attack surface
|
|
2. Trace data flow from untrusted inputs
|
|
3. Check trust boundaries
|
|
4. Review error handling (info leaks)
|
|
5. Assess cryptographic implementations
|
|
6. Check dependency versions
|
|
|
|
Severity levels: CRITICAL / HIGH / MEDIUM / LOW / INFO
|
|
Report format: Finding → Impact → Evidence → Remediation"""
|
|
|
|
[[fallback_models]]
|
|
provider = "default"
|
|
model = "default"
|
|
api_key_env = "GROQ_API_KEY"
|
|
|
|
[schedule]
|
|
proactive = { conditions = ["event:agent_spawned", "event:agent_terminated"] }
|
|
|
|
[resources]
|
|
max_llm_tokens_per_hour = 150000
|
|
|
|
[capabilities]
|
|
tools = [
|
|
"file_read",
|
|
"file_list",
|
|
"shell_exec",
|
|
"memory_store",
|
|
"memory_recall",
|
|
"web_search",
|
|
]
|
|
memory_read = ["*"]
|
|
memory_write = ["self.*", "shared.*"]
|
|
shell = ["cargo audit *", "cargo tree *", "git log *"]
|
|
|
|
|
|
[i18n.zh]
|
|
name = "安全审计员"
|
|
description = "安全专家:审查代码漏洞、检查配置、做威胁建模。"
|
|
|
|
[i18n.zh-TW]
|
|
name = "安全稽核員"
|
|
description = "安全專家:審查程式碼漏洞、檢查設定、進行威脅建模。"
|
|
|
|
[i18n.ja]
|
|
name = "セキュリティ監査官"
|
|
description = "コードの脆弱性レビュー、設定チェック、脅威モデリングを行うセキュリティ専門家。"
|
|
|
|
[i18n.ko]
|
|
name = "보안 감사관"
|
|
description = "코드 취약점 검토, 설정 점검, 위협 모델링을 수행하는 보안 전문가."
|
|
|
|
[i18n.de]
|
|
name = "Sicherheits-Auditor"
|
|
description = "Sicherheitsexperte: prüft Code auf Schwachstellen, kontrolliert Konfigurationen und führt Threat Modeling durch."
|
|
|
|
[i18n.es]
|
|
name = "Auditor de seguridad"
|
|
description = "Especialista en seguridad: revisa vulnerabilidades de código, verifica configuraciones y realiza threat modeling."
|
|
|
|
[i18n.fr]
|
|
name = "Auditeur sécurité"
|
|
description = "Expert sécurité : revue des vulnérabilités de code, vérification des configurations et modélisation des menaces."
|