* refactor: migrate icon fields from emoji to lucide:<name> tokens
Every TOML manifest's `icon = "<emoji>"` line is replaced with
`icon = "lucide:<kebab-name>"` — a reference to a lucide-react icon,
which the librefang.ai site and dashboard render as crisp SVG. Reasons
for the switch:
- Emoji render very differently across OS/browser/font stacks; the
registry catalog looked inconsistent from one row to the next.
- Five manifests (clip / creator / linkedin / reddit / twitter) had
their icons stored as literal Python-style escape strings
("\\U0001F3AC") because the TOML parser upstream never decoded
them. Switching away from emoji drops that class of bug entirely.
- As a drive-by, also decode the \\uXXXX accent escapes in the
[i18n.fr] block of hands/creator/HAND.toml so "Créateur" shows
up correctly.
87 files touched. example manifests left untouched (still "TODO").
* fix: backfill i18n name + drop the single-member email category
- Every existing [i18n.<lang>] block now has a `name` field. 60 files
previously translated description but kept the English name
implicitly — which rendered as "some English some Chinese" in the
registry UI. Fill in the missing name from the English brand (or a
known localized equivalent: DingTalk→钉钉, Feishu→飞书, Email→
电子邮件 / メール / E-Mail / Correo / Courriel, and a handful of
hands that have Chinese product names like 视频剪辑 Hand).
- channels/email.toml was the only item under category="email";
reclassify it as "messaging" so the sub-category filter chip list
on the category page isn't littered with singletons.
* feat(i18n): localize 76 agents/integrations/plugins into 7 languages
Adds full [i18n.zh], [i18n.zh-TW], [i18n.ja], [i18n.ko], [i18n.de],
[i18n.es], [i18n.fr] blocks with name + description to every manifest
that previously shipped English-only.
Coverage:
- 32 agents (academic-researcher, analyst, architect, assistant,
code-reviewer, coder, customer-support, data-scientist, debugger,
devops-lead, doc-writer, email-assistant, health-tracker,
hello-world, home-automation, legal-assistant, meeting-assistant,
ops, orchestrator, personal-finance, planner, recipe-assistant,
recruiter, researcher, sales-assistant, security-auditor,
social-media, test-engineer, translator, travel-planner, tutor,
writer)
- 33 integrations (AWS, Azure, Bitbucket, Brave Search, Discord,
Dropbox, Elasticsearch, Exa Search, Fetch, Filesystem, GCP, Git,
GitHub, GitLab, Gmail, Google Calendar, Google Drive, Google Maps,
Jira, Linear, Memory, MongoDB, Notion, PostgreSQL, Puppeteer, Redis,
Sentry, Sequential Thinking, Slack, SQLite, Teams, Time, Todoist) —
brand names kept as-is across all locales, only descriptions
translated.
- 11 plugins (auto-summarizer, context-decay, conversation-logger,
episodic-memory, guardrails, keyword-memory, mempalace-indexer,
sentiment-tracker, todo-tracker, topic-memory, user-profile)
The descriptions are one-line summaries — hand-translated rather than
machine-generated, so technical terms (MCP, PR, CI/CD, etc.) stay
consistent across locales.
* feat(i18n): close remaining per-lang gaps for channels, workflows, devteam
Third pass on i18n coverage. Every non-example manifest now carries a
full set of [i18n.zh], [i18n.zh-TW], [i18n.ja], [i18n.ko], [i18n.de],
[i18n.es], [i18n.fr] blocks.
- 44 channel adapters: added French descriptions (zh/zh-TW/ja/ko/de/es
were already present). Brand names kept as-is in all locales so users
recognize Discord / Slack / LINE / etc. consistently.
- 22 workflows: filled zh-TW / ja / ko / de / es / fr blocks. Each
translation mirrors the existing zh one in structure and tone so the
catalog reads consistently across locales.
- hands/devteam/HAND.toml: added the four langs that were missing
(zh-TW, de, es, fr).
Only the 6 templates under examples/ are left without i18n blocks on
purpose — they still contain "TODO:" placeholders.
100 lines
2.9 KiB
TOML
100 lines
2.9 KiB
TOML
name = "security-auditor"
|
|
version = "0.4.3-beta3-20260314"
|
|
description = "Security specialist. Reviews code for vulnerabilities, checks configurations, performs threat modeling."
|
|
author = "librefang"
|
|
module = "builtin:chat"
|
|
tags = ["security", "audit", "vulnerability"]
|
|
|
|
[metadata.routing]
|
|
aliases = [
|
|
"security audit",
|
|
"vulnerability review",
|
|
"threat model",
|
|
"security review",
|
|
"attack surface review",
|
|
]
|
|
weak_aliases = ["security", "vulnerability", "owasp", "audit"]
|
|
|
|
[model]
|
|
provider = "default"
|
|
model = "default"
|
|
api_key_env = "DEEPSEEK_API_KEY"
|
|
max_tokens = 4096
|
|
temperature = 0.2
|
|
system_prompt = """You are Security Auditor, a cybersecurity expert running inside the LibreFang Agent OS.
|
|
|
|
Your focus areas:
|
|
- OWASP Top 10 vulnerabilities
|
|
- Input validation and sanitization
|
|
- Authentication and authorization flaws
|
|
- Cryptographic misuse
|
|
- Injection attacks (SQL, command, XSS, SSTI)
|
|
- Insecure deserialization
|
|
- Secrets management (hardcoded keys, env vars)
|
|
- Dependency vulnerabilities
|
|
- Race conditions and TOCTOU bugs
|
|
- Privilege escalation paths
|
|
|
|
When auditing code:
|
|
1. Map the attack surface
|
|
2. Trace data flow from untrusted inputs
|
|
3. Check trust boundaries
|
|
4. Review error handling (info leaks)
|
|
5. Assess cryptographic implementations
|
|
6. Check dependency versions
|
|
|
|
Severity levels: CRITICAL / HIGH / MEDIUM / LOW / INFO
|
|
Report format: Finding → Impact → Evidence → Remediation"""
|
|
|
|
[[fallback_models]]
|
|
provider = "default"
|
|
model = "default"
|
|
api_key_env = "GROQ_API_KEY"
|
|
|
|
[schedule]
|
|
proactive = { conditions = ["event:agent_spawned", "event:agent_terminated"] }
|
|
|
|
[resources]
|
|
max_llm_tokens_per_hour = 150000
|
|
|
|
[capabilities]
|
|
tools = [
|
|
"file_read",
|
|
"file_list",
|
|
"shell_exec",
|
|
"memory_store",
|
|
"memory_recall",
|
|
]
|
|
memory_read = ["*"]
|
|
memory_write = ["self.*", "shared.*"]
|
|
shell = ["cargo audit *", "cargo tree *", "git log *"]
|
|
|
|
|
|
[i18n.zh]
|
|
name = "安全审计员"
|
|
description = "安全专家:审查代码漏洞、检查配置、做威胁建模。"
|
|
|
|
[i18n.zh-TW]
|
|
name = "安全稽核員"
|
|
description = "安全專家:審查程式碼漏洞、檢查設定、進行威脅建模。"
|
|
|
|
[i18n.ja]
|
|
name = "セキュリティ監査官"
|
|
description = "コードの脆弱性レビュー、設定チェック、脅威モデリングを行うセキュリティ専門家。"
|
|
|
|
[i18n.ko]
|
|
name = "보안 감사관"
|
|
description = "코드 취약점 검토, 설정 점검, 위협 모델링을 수행하는 보안 전문가."
|
|
|
|
[i18n.de]
|
|
name = "Sicherheits-Auditor"
|
|
description = "Sicherheitsexperte: prüft Code auf Schwachstellen, kontrolliert Konfigurationen und führt Threat Modeling durch."
|
|
|
|
[i18n.es]
|
|
name = "Auditor de seguridad"
|
|
description = "Especialista en seguridad: revisa vulnerabilidades de código, verifica configuraciones y realiza threat modeling."
|
|
|
|
[i18n.fr]
|
|
name = "Auditeur sécurité"
|
|
description = "Expert sécurité : revue des vulnérabilités de code, vérification des configurations et modélisation des menaces."
|