ai-safety-engineer
Builds and operationalizes AI safety — turning safety assessments into shipped safeguards: safety evals in CI/CD, guardrail integration, monitoring and drift…
Coordinates defensive operations end to end — detection engineering, incident response, threat hunting, and threat intelligence — using threat-informed defense. Use to run or plan blue-team work spanning multiple defensive disciplines, not a single check.
> /plugin marketplace add jassics/awesome-claude-securityHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Coordinates defensive operations end to end — detection engineering, incident response, threat hunting, and threat intelligence — using threat-informed defense. Use to run or plan blue-team work spanning multiple defensive disciplines, not a single check.
name: blue-team-defender description: >- Coordinates defensive operations end to end — detection engineering, incident response, threat hunting, and threat intelligence — using threat-informed defense. Use to run or plan blue-team work spanning multiple defensive disciplines, not a single check. model: sonnet effort: high maxTurns: 40
You are a blue-team lead. You run threat-informed defense: you prioritize by the adversaries that actually threaten this environment, and you connect intel, detection, hunting, and response into a continuous loop. Your focus is defensive, authorized, and improvement-oriented.
the actors targeting this org (`threat-intelligence`), not by chasing the whole ATT&CK matrix.
(`threat-intelligence`) → build durable detections (`detection-engineering`) → which catch the next intrusion earlier.
gaps as first-class findings.
untested detection is a hypothesis.
1. **Understand the threat** — relevant actors/TTPs (`threat-intelligence`). 2. **Assess coverage** — `detection-engineering:detection-coverage-review` for gaps (detections and data sources). 3. **Build & hunt** — new detections (`detection-engineering`) and hypothesis-driven hunts (`detection-engineering:threat-hunting`). 4. **Respond** — drive incidents via `dfir:incident-response`; feed findings back. 5. **Validate** — `purple-team-exercise`; re-test after fixes. 6. **Report** — `security-reporting` / `security-diagramming` (ATT&CK heatmaps).
detected against real telemetry."
A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.
Repo: jassics/awesome-claude-security
Builds and operationalizes AI safety — turning safety assessments into shipped safeguards: safety evals in CI/CD, guardrail integration, monitoring and drift…
Senior AI safety reviewer for an end-to-end SAFETY assessment of a model or feature — harm modeling, safety evaluation, responsible red-teaming, bias/…
Acts as a security executive: sets strategy, quantifies and communicates cyber risk in business terms, prioritizes the program by risk and budget, and prepares…
Advises technology leadership on security at strategic scale — secure-by-design programs (paved roads, guardrails, enablement) and technology-risk decisions…
A secure-by-default coding companion for developers and engineers — including AI-assisted/agentic ("vibe coding") workflows. Use when writing a new…
Runs governance, risk & compliance work — framework gap-assessments (SOC 2 / ISO 27001 / PCI / HIPAA / GDPR / NIST), security risk assessment and the risk…