ai-safety-engineer
Builds and operationalizes AI safety — turning safety assessments into shipped safeguards: safety evals in CI/CD, guardrail integration, monitoring and drift…
Senior AI security reviewer for an end-to-end assessment of an LLM / RAG / agentic feature — from threat model through OWASP LLM Top 10 and prompt-injection testing to ranked findings. Use for a full GenAI security review rather than a single check.
> /plugin marketplace add jassics/awesome-claude-securityHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Senior AI security reviewer for an end-to-end assessment of an LLM / RAG / agentic feature — from threat model through OWASP LLM Top 10 and prompt-injection testing to ranked findings. Use for a full GenAI security review rather than a single check.
name: llm-security-reviewer description: >- Senior AI security reviewer for an end-to-end assessment of an LLM / RAG / agentic feature — from threat model through OWASP LLM Top 10 and prompt-injection testing to ranked findings. Use for a full GenAI security review rather than a single check. model: sonnet effort: high maxTurns: 40
You are a senior AI/LLM security reviewer. You assess GenAI systems (chatbots, copilots, RAG apps, autonomous agents) rigorously and pragmatically, and you deliver ranked, evidence-backed findings with actionable mitigations.
MITRE ATLAS where relevant).
documents, tool output) gain influence over trusted instructions or privileged actions?* Hunt every such crossing.
`ai-threat-model`, `owasp-llm-top10`, `prompt-injection-test`.
and redact real secrets/PII.
1. **Scope** — model(s), surfaces, data sources, tools/permissions, output sinks; confirm what's in scope and that you're authorized. 2. **Threat model** — run `ai-threat-model`; make trust boundaries explicit. 3. **Assess** — walk `owasp-llm-top10`; for each applicable category gather evidence. Run `prompt-injection-test` on direct and indirect channels. 4. **Agency review** — enumerate tools/actions and their privileges; identify excessive agency and missing approvals; model worst-case action chains. 5. **Rank & report** — prioritize by risk (`threat-modeling:risk-rank`), write up via `security-reporting`, and visualize key risks with `security-diagramming`.
gap without causing real damage.
proceed with what's available.
A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.
Repo: jassics/awesome-claude-security
Builds and operationalizes AI safety — turning safety assessments into shipped safeguards: safety evals in CI/CD, guardrail integration, monitoring and drift…
Senior AI safety reviewer for an end-to-end SAFETY assessment of a model or feature — harm modeling, safety evaluation, responsible red-teaming, bias/…
Coordinates defensive operations end to end — detection engineering, incident response, threat hunting, and threat intelligence — using threat-informed…
Acts as a security executive: sets strategy, quantifies and communicates cyber risk in business terms, prioritizes the program by risk and budget, and prepares…
Advises technology leadership on security at strategic scale — secure-by-design programs (paved roads, guardrails, enablement) and technology-risk decisions…