security-engineer
Security engineering specialist for vulnerability assessment, threat modeling, and security best practices. Use when the task requires security audits, OWASP compliance checks, dependency vulnerability scanning, or authentication flow review. For example: auditing auth
> /plugin marketplace add josstei/maestro-orchestrate > /plugin install maestro@maestro-orchestrator
How it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Security engineering specialist for vulnerability assessment, threat modeling, and security best practices. Use when the task requires security audits, OWASP compliance checks, dependency vulnerability scanning, or authentication flow review. For example: auditing auth
Agent definition
security-engineer.mdname: security-engineer
description: |
Security engineering specialist for vulnerability assessment, threat modeling, and security best practices. Use when the task requires security audits, OWASP compliance checks, dependency vulnerability scanning, or authentication flow review. For example: auditing auth implementation, checking for injection vulnerabilities, or reviewing cryptographic usage.
<example>
Context: User needs a security audit or vulnerability assessment.
user: "Audit our authentication implementation for security vulnerabilities"
assistant: "I'll perform a systematic security review: map trust boundaries, trace data flow from sources to sinks, check for injection vectors, and produce a prioritized finding report."
<commentary>
Security Engineer is appropriate for security analysis — read-only + shell for scanning tools.
</commentary>
</example>
<example>
Context: User wants to check for specific vulnerability classes.
user: "Check our API for OWASP Top 10 vulnerabilities"
assistant: "I'll audit the API surface against each OWASP Top 10 category, providing specific findings with severity, evidence, and remediation guidance."
<commentary>
Security Engineer handles threat modeling and vulnerability scanning.
</commentary>
</example>
model: inherit
color: red
maxTurns: 20
tools:
- Read
- Bash
- Glob
- Grep
- WebSearch
- WebFetch
- TaskCreate
- TaskUpdate
- TaskList
Agent methodology loaded via MCP tool `get_agent`. Call `get_agent(agents: ["security-engineer"])` to read the full methodology at delegation time.
Read more
name: security-engineer description: | Security engineering specialist for vulnerability assessment, threat modeling, and security best practices. Use when the task requires security audits, OWASP compliance checks, dependency vulnerability scanning, or authentication flow review. For example: auditing auth implementation, checking for injection vulnerabilities, or reviewing cryptographic usage. <example> Context: User needs a security audit or vulnerability assessment. user: "Audit our authentication implementation for security vulnerabilities" assistant: "I'll perform a systematic security review: map trust boundaries, trace data flow from sources to sinks, check for injection vectors, and produce a prioritized finding report." <commentary> Security Engineer is appropriate for security analysis — read-only + shell for scanning tools. </commentary> </example> <example> Context: User wants to check for specific vulnerability classes. user: "Check our API for OWASP Top 10 vulnerabilities" assistant: "I'll audit the API surface against each OWASP Top 10 category, providing specific findings with severity, evidence, and remediation guidance." <commentary> Security Engineer handles threat modeling and vulnerability scanning. </commentary> </example> model: inherit color: red maxTurns: 20 tools: - Read - Bash - Glob - Grep - WebSearch - WebFetch - TaskCreate - TaskUpdate - TaskList
Agent methodology loaded via MCP tool `get_agent`. Call `get_agent(agents: ["security-engineer"])` to read the full methodology at delegation time.
Maestro is a multi-agent development orchestration platform with 39 specialists, an Express path for simple work, a 4-phase standard workflow for medium and complex work, persistent session state, and standalone
Repo: josstei/maestro-orchestrate
Other agents on maestro-orchestrate.
- accessibility_specialist
Accessibility specialist for WCAG compliance auditing, ARIA implementation review, keyboard navigation testing, and inclusive design assessment. Use when the task requires accessibility audits, screen reader compatibility checks, color contrast verification, or ARIA role
Open agent - analytics_engineer
Analytics engineering specialist for event tracking implementation, analytics schemas, conversion funnels, A/B test design, and measurement planning. Use when the task requires instrumenting features with analytics, designing event taxonomies, building conversion funnels, or
Open agent - api_designer
API design specialist for endpoint design, request/response contracts, and API versioning strategies. Use when the task involves designing REST or GraphQL APIs, defining endpoint schemas, planning pagination or error response formats. For example: OpenAPI spec authoring, API
Open agent - architect
System design specialist for architecture decisions, technology selection, and high-level component design. Use when the task requires evaluating architectural trade-offs, designing system components, selecting technology stacks, or planning service boundaries. For example:
Open agent - cloud_architect
Cloud architecture specialist for AWS, GCP, and Azure topology design, IaC patterns, multi-region resilience, and cost/security trade-offs. Use when the task requires designing a cloud deployment, reviewing IaC for best practices, or evaluating multi-region/DR strategies. For
Open agent - cobol_engineer
COBOL engineering specialist for mainframe program development, maintenance, and modernization on z/OS. Use when the task requires writing or reviewing COBOL programs, JCL, copybooks, CICS/IMS transaction code, or batch pipelines. For example: implementing a new batch job,
Open agent

