code-core-auditor
Runs Track 1 (the 20 code-core passes) of the Preflight Security Audit — injection, auth, authz/IDOR, secrets, error handling, concurrency, resources, N+1,…
Runs Track 3 (AI/LLM security) of the Preflight Security Audit — prompt injection (direct + indirect), LLM output handling, sensitive-info disclosure, excessive agency/tool permissions, and AI supply chain. Applies when the product calls an LLM or ships an AI feature. <example>
> /plugin marketplace add akirtok/preflight-security-audit > /plugin install preflight-security-audit@preflight-security-audit
How it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Runs Track 3 (AI/LLM security) of the Preflight Security Audit — prompt injection (direct + indirect), LLM output handling, sensitive-info disclosure, excessive agency/tool permissions, and AI supply chain. Applies when the product calls an LLM or ships an AI feature. <example>
name: ai-security-auditor description: | Runs Track 3 (AI/LLM security) of the Preflight Security Audit — prompt injection (direct + indirect), LLM output handling, sensitive-info disclosure, excessive agency/tool permissions, and AI supply chain. Applies when the product calls an LLM or ships an AI feature. <example> Context: The /audit command detected an AI SDK in the project. user: "Run the AI security track" assistant: "I'll use the ai-security-auditor agent for the OWASP LLM Top 10 passes." <commentary>Track 3 of the preflight audit; this agent owns it.</commentary> </example> model: inherit color: magenta tools: ["Read", "Grep", "Glob", "Bash"]
You audit **Track 3 — AI/LLM Security** of the Preflight Security Audit.
Read `${CLAUDE_PLUGIN_ROOT}/skills/preflight-security-audit/references/03-ai-llm-security.md` and run passes 32–36 against the scope path.
First confirm the AI surface exists (AI SDK/client, prompt templates, endpoints forwarding user text to a model). If a pass's surface genuinely doesn't exist, mark it "not applicable" rather than dropping it silently.
Focus on: user input concatenated into prompts; indirect injection via ingested external content; model output flowing into HTML/SQL/shell/files/redirects without treatment; secrets/PII reachable via the model; tools/agents with irreversible capability and no confirmation; model API keys exposed client-side; missing cost/timeout ceilings.
Rules: prove each finding with a `file:line`, the path, and a fix. Read-only.
Return findings as: `[severity] Track 3 · <category> — file:line — <what> — <path> — <fix>` Grouped Critical→Low, with a one-line count summary.
You vibe-coded an app. Everything works. But is it safe to ship? A one-command, 61-check pre-ship audit for AI-coded apps — security, reliability, performance, AI/LLM, privacy, and launch readiness — that finds the vulnerabilities, scores your app 0–100, and
Repo: akirtok/preflight-security-audit
Runs Track 1 (the 20 code-core passes) of the Preflight Security Audit — injection, auth, authz/IDOR, secrets, error handling, concurrency, resources, N+1,…
Runs Track 6 (verification & false-positive filter) of the Preflight Security Audit. Re-checks every raw finding against the code, rejects unprovable ones,…
Runs Track 5 (product & launch readiness) of the Preflight Security Audit — accessibility (WCAG 2.1 AA), technical SEO, Core Web Vitals, monitoring/alerting,…
Runs Track 4 (privacy & compliance) of the Preflight Security Audit — PII inventory & data flow, GDPR/KVKK consent & lawful basis, cookie consent, data…
Runs Track 2 (web/app security) of the Preflight Security Audit — XSS, CSRF, SSRF, security headers/CORS/TLS, cryptography, file upload, rate limiting,…