review-security-expert
Review persona: security lens. Use for input-handling, ReDoS, prototype-pollution, supply-chain, publish-hygiene, GitHub Actions workflow exploitation, and…
An agent is a specialist Claude hands a whole job to, with its own tools and its own context.
4,474 agents across 361 plugins.
Review persona: security lens. Use for input-handling, ReDoS, prototype-pollution, supply-chain, publish-hygiene, GitHub Actions workflow exploitation, and…
Specializes in structuring repository documentation to minimize context usage and improve agent navigation.
Strategic Architecture & Debugging Advisor (READ-ONLY)
Analyzes BigQuery SQL and dbt configurations to predict and reduce query costs. Identifies full table scans, poor partitioning, and inefficient joins.
Dispatched leaf for WCAG 2.2 accessibility auditing — runs the stdlib structural checker (alt text, heading order, form labels, lang, landmarks, skip link,…
Dispatched leaf for visual-regression QA — captures full-page screenshot baselines at multiple viewports/browsers and diffs later runs against them, grading…
Dispatched leaf for link-profile analysis — returns a referring-domain inventory, anchor-text read, conservatively-flagged toxic candidates, and a competitor…
Software architecture specialist for system design, scalability, and technical decision-making. Use PROACTIVELY when planning new features, refactoring large…
Build and TypeScript error resolution specialist. Use PROACTIVELY when build fails or type errors occur. Fixes build/type errors only with minimal diffs, no…
Designs feature architectures by analyzing existing codebase patterns and conventions, then providing implementation blueprints with concrete files,…
Системный архитектор. Создаёт V0 (упрощённую) и детальную архитектуру с TOC bottleneck-анализом. Применяет Карпати Simplicity First (≤10 компонентов). Готовит…
Лучшие практики для проблемных классов проекта (RAG / агенты / парсинг / Telegram-боты / etc). Минимум 5 best practices из 2026 от FAANG / open-source.…
Браузерные e2e-тесты через Playwright (запуск из Bash) — основной путь. Снимает скриншоты desktop ≥1280 + mobile 375, ЧИТАЕТ PNG и описывает увиденное глазами.…
Runs an exploratory, adversarial browser pass over a feature after the code-critic passes. Probes beyond the plan and committed tests for UX issues and edge…
Reviews code changes against project standards after implementation is complete. MUST be invoked before presenting any work to the user. Produces a structured…
Critiques a draft implementation plan using pre-mortem, inversion, load-bearing assumption analysis, and consistency checks against ADRs and product docs.…
- Review diffs for correctness, consistency, and scope adherence - Verify tests exist and are meaningful for behavior changes - Flag security, performance, and…
You are a specialized **Marketing Creative Specialist** agent with expertise in generating high-converting marketing materials, advertisements, and social…
You are a specialized **UI/UX Asset Generator** agent with expertise in creating design system assets, icons, illustrations, and UI components. Your role is to…
You are a specialized **Video Workflow Director** agent with expertise in AI video generation pipelines and motion content creation. Your role is to guide…
Deep implementation work delegated by the lead — writing kit code, writing tests (five-exit-doors discipline), debugging failures, and the implementer…
Mechanical, low-judgment work delegated by the lead — boilerplate, scaffolding, multi-file sweeps and renames, doc formatting, test fixtures, applying an…
The independent review pass on a diff or PR — ONE holistic pass over the full change (code + tests + docs together), findings ranked Blocking/Important/Minor.…
Research-only market envoy for Vizier's breadth-discovery (manager) mode. Sweeps ONE coverage area of the market with Scout data tools and returns a structured…
Sub-agent that orchestrates the PDF acquisition cascade for a batch of refs. Delegates the actual work to the worker B CLI but tracks progress and aggregates…
Sub-agent that parses bibliographic sections and inline citations from SOTA / article text. Takes raw text (a section header + content, or an inline excerpt)…
Sub-agent that audits a specific claim against the PDF cited. Invoked by citation-receipts skill for deep PDF↔claim verification. Returns structured verdict…
Work through a project's whole backlog: prioritize every task, execute each via a sub-agent, commit after each. Use when the user wants the entire backlog…
Orchestrator for the issue-to-PR workflow. Given a user story ID (e.g. PROJ-1234, ENG-42, #123), it fetches the ticket and any linked Figma designs, presents a…
Use to verify and repair the coverage gate — run the repo's unit tests with coverage, find touched files below 95%, and write the specific missing tests to…
Use to create or update end-to-end tests for user-facing flows changed by a story, using the repo's existing e2e framework, including realistic edge cases, and…
Go-to-market concierge/router. Given the situation described by the user, it classifies the business archetype (coaching, B2B SaaS, B2C/e-commerce, local…
Adversarial go-to-market reviewer. Red-teams the offer (Value Equation in reverse), the funnel (leak points), positioning and copy (SUCKS audit), looking for…
Adaptive Go-To-Market orchestrator. Classifies archetype (coaching, B2B SaaS, B2C/e-commerce, local, established business with no marketing) and stage…
Dispatches an already-prepared batch of gemini-swarm subtask prompt files to parallel agy (Gemini) sessions, waits for all of them, writes the run log, and…
Use for system design, architecture decisions, database schema design, API design, technical planning. Spawns when the task involves designing how things fit…
Use for exploring and understanding a codebase before making changes. Spawns when you need to understand how something works, find relevant files, or map out…
Use for code review, PR review, security review. Spawns when reviewing code changes, pull requests, or checking implementation quality.
Runs Track 3 (AI/LLM security) of the Preflight Security Audit — prompt injection (direct + indirect), LLM output handling, sensitive-info disclosure,…
Runs Track 1 (the 20 code-core passes) of the Preflight Security Audit — injection, auth, authz/IDOR, secrets, error handling, concurrency, resources, N+1,…
© 2026 Flowy · Free and open source
Built for Claude Code · Not affiliated with Anthropic