All 32 agent manifests and 17 hands shipped with empty mcp_servers /
skills lists, which the kernel interprets as "no filter" — every
globally-configured MCP server's tools and every installed skill get
injected into the prompt on every LLM call. On a typical instance (9
MCP servers, ~85 MCP tools + ~82 built-in tools) that's ~50k input
tokens per turn spent on definitions the agent never uses.
Changes
-------
32 agents/*/agent.toml:
- mcp_servers: 1-4 per agent. memory wherever state persists across
turns; fetch / exa-search / brave-search only where the prompt
actually calls for web; git / github / filesystem on engineering
agents; gmail / google-calendar / linear / jira on productivity
agents whose prompts mention them.
- skills: per-role allowlist driven by what the system_prompt names
(e.g. coder → rust/python/typescript/git/shell-scripting; devops-
lead → docker/kubernetes/terraform/ansible/ci-cd/helm/prometheus/
sysadmin). Generalists (assistant) keep skills = [] (see "Open
items" below).
- skills_disabled = true on the four short-conversational agents
(hello-world, recipe-assistant, health-tracker, home-automation).
Their system prompts never instruct the LLM to consult any skill,
so loading all 60 was pure waste. They also drop the explicit
max_history_messages override and inherit the kernel default (60).
- max_history_messages tiered by workload shape:
60 short conversational (hello-world, recipe, health-tracker,
home-automation) — inherits the rising kernel default
(`DEFAULT_MAX_HISTORY_MESSAGES = 60`); no override needed.
60 single-turn task agents (writer, translator, doc-writer,
email-assistant, customer-support, sales-assistant, recruit-
er, social-media, personal-finance, tutor, travel-planner,
meeting-assistant, ops, devops-lead, planner) — explicit
override at the same value to lock the cap if the kernel
default moves again.
80 multi-step / tool-heavy (coder, debugger, architect, code-
reviewer, test-engineer, security-auditor, analyst, data-
scientist, academic-researcher, researcher, legal-assistant)
120 coordinators (assistant, orchestrator) — long multi-agent
sessions where prompt-cache continuity is critical
All values sit at or above the kernel default. Pinning lower
would thrash the prompt cache (the failure mode #91 fixed for
the creator hand by *raising* the cap, not lowering it).
17 hands/*/HAND.toml:
- hand-level mcp_servers / skills now declared on every hand, so
every [agents.*] inside inherits a sensible allowlist.
- skills_disabled = true placed on each [agents.*] inside clip and
creator (pure media pipelines that don't benefit from any skill).
HandDefinitionRaw in librefang-hands does NOT have a top-level
skills_disabled field — declaring it at the hand top level would
be silently dropped by serde, so the setting must live on the
AgentManifest of each sub-agent role.
- devteam: expand existing mcp_servers = ["github"] to include
memory / git / filesystem; populate skills with the expected
dev-team expertise (replacing the placeholder skills = []).
- wiki: replace placeholder mcp_servers = [] with [memory, fetch,
filesystem]. Hand-level skills stays [].
- lead: hand-level skills was originally [email-writer, writing-
coach, interview-prep]; interview-prep is for job-interview
preparation, not lead generation. Replaced with data-analyst
(used by the qualification-scoring step in the prompt).
schema.toml: register mcp_servers / skills / max_history_messages on
the agent field schema so machine consumers (RegistrySchema in
librefang-types) see the new top-level fields. The
max_history_messages description now points at
librefang_runtime::agent_loop::DEFAULT_MAX_HISTORY_MESSAGES (60
today) by name, so the schema doesn't go stale when the constant
moves again.
agents/README.md: example block + "Adding a New Agent" checklist
mention the allowlists; max_history_messages example is shown
commented out with a prompt-cache caveat.
Open items
----------
`assistant` (the default user-facing agent) keeps `skills = []`
deliberately. It is the generalist entry point — capping its skill
surface at a small allowlist would defeat its "delegate to any
specialist" job. The trade-off is that this single agent still pays
the full skill-definition load on every turn; operators who want a
strict allowlist for `assistant` can override it after install.
Why not adopt PR #89's approach
-------------------------------
#89 covers similar ground but with three issues this PR avoids:
1. mcp_servers = ["_none"] sentinel. #89's body explicitly notes
it's pending upstream librefang#4808 (mcp_disabled). Shipping a
magic-string today means coming back later to clean it up. This
PR uses real allowlists.
2. max_history_messages = 8 / 12 / 15 / 20. Far below today's
kernel default (60) and #91's direction for long-workflow hands
(80–120). Every turn that hits the cap invalidates the cached
prompt prefix; the cost of cache misses exceeds the saving from
shorter history. This PR uses 60–120.
3. Doubling max_llm_tokens_per_hour (coder 200k→500k, assistant
300k→500k) widens the per-agent budget — the opposite direction
from #87's "reduce per-call cost" goal. Left to the operator's
instance-specific tuning.
Refs librefang/librefang-registry#87, librefang/librefang-registry#89
109 lines
3.2 KiB
TOML
109 lines
3.2 KiB
TOML
name = "security-auditor"
|
|
version = "0.4.3-beta3-20260314"
|
|
description = "Security specialist. Reviews code for vulnerabilities, checks configurations, performs threat modeling."
|
|
author = "librefang"
|
|
module = "builtin:chat"
|
|
tags = ["security", "audit", "vulnerability"]
|
|
|
|
# Per-agent resource allowlists (refs librefang/librefang-registry#87).
|
|
# Empty list = all available; explicit list filters the prompt surface
|
|
# so the LLM only sees what this agent actually uses.
|
|
mcp_servers = ["memory", "github", "git"]
|
|
skills = ["security-audit", "compliance", "oauth-expert"]
|
|
|
|
|
|
max_history_messages = 80
|
|
[metadata.routing]
|
|
aliases = [
|
|
"security audit",
|
|
"vulnerability review",
|
|
"threat model",
|
|
"security review",
|
|
"attack surface review",
|
|
]
|
|
weak_aliases = ["security", "vulnerability", "owasp", "audit"]
|
|
|
|
[model]
|
|
provider = "default"
|
|
model = "default"
|
|
api_key_env = "DEEPSEEK_API_KEY"
|
|
max_tokens = 4096
|
|
temperature = 0.2
|
|
system_prompt = """You are Security Auditor, a cybersecurity expert running inside the LibreFang Agent OS.
|
|
|
|
Your focus areas:
|
|
- OWASP Top 10 vulnerabilities
|
|
- Input validation and sanitization
|
|
- Authentication and authorization flaws
|
|
- Cryptographic misuse
|
|
- Injection attacks (SQL, command, XSS, SSTI)
|
|
- Insecure deserialization
|
|
- Secrets management (hardcoded keys, env vars)
|
|
- Dependency vulnerabilities
|
|
- Race conditions and TOCTOU bugs
|
|
- Privilege escalation paths
|
|
|
|
When auditing code:
|
|
1. Map the attack surface
|
|
2. Trace data flow from untrusted inputs
|
|
3. Check trust boundaries
|
|
4. Review error handling (info leaks)
|
|
5. Assess cryptographic implementations
|
|
6. Check dependency versions
|
|
|
|
Severity levels: CRITICAL / HIGH / MEDIUM / LOW / INFO
|
|
Report format: Finding → Impact → Evidence → Remediation"""
|
|
|
|
[[fallback_models]]
|
|
provider = "default"
|
|
model = "default"
|
|
api_key_env = "GROQ_API_KEY"
|
|
|
|
[schedule]
|
|
proactive = { conditions = ["event:agent_spawned", "event:agent_terminated"] }
|
|
|
|
[resources]
|
|
max_llm_tokens_per_hour = 150000
|
|
|
|
[capabilities]
|
|
tools = [
|
|
"file_read",
|
|
"file_list",
|
|
"shell_exec",
|
|
"memory_store",
|
|
"memory_recall",
|
|
"web_search",
|
|
]
|
|
memory_read = ["*"]
|
|
memory_write = ["self.*", "shared.*"]
|
|
shell = ["cargo audit *", "cargo tree *", "git log *"]
|
|
|
|
|
|
[i18n.zh]
|
|
name = "安全审计员"
|
|
description = "安全专家:审查代码漏洞、检查配置、做威胁建模。"
|
|
|
|
[i18n.zh-TW]
|
|
name = "安全稽核員"
|
|
description = "安全專家:審查程式碼漏洞、檢查設定、進行威脅建模。"
|
|
|
|
[i18n.ja]
|
|
name = "セキュリティ監査官"
|
|
description = "コードの脆弱性レビュー、設定チェック、脅威モデリングを行うセキュリティ専門家。"
|
|
|
|
[i18n.ko]
|
|
name = "보안 감사관"
|
|
description = "코드 취약점 검토, 설정 점검, 위협 모델링을 수행하는 보안 전문가."
|
|
|
|
[i18n.de]
|
|
name = "Sicherheits-Auditor"
|
|
description = "Sicherheitsexperte: prüft Code auf Schwachstellen, kontrolliert Konfigurationen und führt Threat Modeling durch."
|
|
|
|
[i18n.es]
|
|
name = "Auditor de seguridad"
|
|
description = "Especialista en seguridad: revisa vulnerabilidades de código, verifica configuraciones y realiza threat modeling."
|
|
|
|
[i18n.fr]
|
|
name = "Auditeur sécurité"
|
|
description = "Expert sécurité : revue des vulnérabilités de code, vérification des configurations et modélisation des menaces."
|