security
Critique principles for secure code development
$ npx -y skills add nyldn/claude-octopus --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Critique principles for secure code development
Agent definition
security.mdname: security-principles
domain: security
description: Critique principles for secure code development
Security Principles
Code MUST adhere to these security requirements:
Input & Output
1. **No SQL Injection** - All database queries MUST be parameterized. Never concatenate user input into SQL strings.
2. **No XSS (Cross-Site Scripting)** - All output MUST be properly escaped/encoded for the context (HTML, JavaScript, URL, CSS).
3. **No Command Injection** - Never pass user input directly to shell commands. Use safe APIs or strict validation.
Authentication & Authorization
4. **No CSRF** - State-changing requests MUST require valid CSRF tokens.
5. **Secure Authentication** - Use strong password hashing (bcrypt/argon2), implement rate limiting, support MFA.
6. **Least Privilege** - Grant minimal permissions required. Never run as root/admin unless necessary.
Data Protection
7. **Secure Defaults** - Fail closed, not open. Default to denying access.
8. **Sensitive Data Handling** - Never log passwords, tokens, or PII. Use encryption at rest and in transit.
9. **Secure Session Management** - Use secure, httpOnly cookies. Regenerate session IDs on privilege changes.
Defense in Depth
10. **Input Validation** - Validate ALL user input server-side. Client-side validation is for UX only.
11. **Error Handling** - Never expose stack traces or internal details to users.
12. **Dependency Security** - Audit dependencies for known vulnerabilities. Keep packages updated.
Checklist
When reviewing code, verify:
- [ ] No hardcoded secrets or credentials
- [ ] All inputs validated and sanitized
- [ ] All outputs properly encoded
- [ ] Authentication properly implemented
- [ ] Authorization checks on all protected resources
- [ ] Secure communication (HTTPS, TLS)
- [ ] Proper error handling without info leakage
- [ ] Logging without sensitive data exposure
Read more
name: security-principles domain: security description: Critique principles for secure code development
Security Principles
Code MUST adhere to these security requirements:
Input & Output
1. **No SQL Injection** - All database queries MUST be parameterized. Never concatenate user input into SQL strings.
2. **No XSS (Cross-Site Scripting)** - All output MUST be properly escaped/encoded for the context (HTML, JavaScript, URL, CSS).
3. **No Command Injection** - Never pass user input directly to shell commands. Use safe APIs or strict validation.
Authentication & Authorization
4. **No CSRF** - State-changing requests MUST require valid CSRF tokens.
5. **Secure Authentication** - Use strong password hashing (bcrypt/argon2), implement rate limiting, support MFA.
6. **Least Privilege** - Grant minimal permissions required. Never run as root/admin unless necessary.
Data Protection
7. **Secure Defaults** - Fail closed, not open. Default to denying access.
8. **Sensitive Data Handling** - Never log passwords, tokens, or PII. Use encryption at rest and in transit.
9. **Secure Session Management** - Use secure, httpOnly cookies. Regenerate session IDs on privilege changes.
Defense in Depth
10. **Input Validation** - Validate ALL user input server-side. Client-side validation is for UX only.
11. **Error Handling** - Never expose stack traces or internal details to users.
12. **Dependency Security** - Audit dependencies for known vulnerabilities. Keep packages updated.
Checklist
When reviewing code, verify:
- [ ] No hardcoded secrets or credentials
- [ ] All inputs validated and sanitized
- [ ] All outputs properly encoded
- [ ] Authentication properly implemented
- [ ] Authorization checks on all protected resources
- [ ] Secure communication (HTTPS, TLS)
- [ ] Proper error handling without info leakage
- [ ] Logging without sensitive data exposure
Every AI model has blind spots. Claude Octopus supports ten external provider integrations — Codex, Gemini, Antigravity CLI, Copilot, Qwen, Ollama, Perplexity, OpenRouter, OpenCode, and Grok — alongside the built-in Claude Code host, with consensus gates that
Repo: nyldn/claude-octopus
Other agents on octo.
- backend-architect
Expert backend architect for scalable API design, microservices, and distributed systems. Masters REST/GraphQL/gRPC, event-driven patterns, service mesh, and resilience. Use PROACTIVELY for new backend services or APIs.
Open agent - cloud-architect
Expert cloud architect for AWS/Azure/GCP multi-cloud design, IaC (Terraform/CDK), FinOps, serverless, security, and compliance. Use PROACTIVELY for cloud architecture, cost optimization, or migration planning.
Open agent - code-reviewer
Elite code reviewer for AI-powered analysis, security vulnerabilities, performance, and production reliability. Masters static analysis, security scanning, and 2025/2026 best practices. Use PROACTIVELY for code quality.
Open agent - database-architect
Expert database architect for data layer design, technology selection, schema modeling, and scalable architectures. Masters SQL/NoSQL/TimeSeries, normalization, migration planning. Use PROACTIVELY for database architecture or data modeling.
Open agent - debugger
Debugging specialist for errors, test failures, and unexpected behavior. Use proactively when encountering any issues.
Open agent - docs-architect
Creates comprehensive technical documentation from existing codebases. Analyzes architecture, design patterns, and implementation details to produce long-form technical manuals and ebooks. Use PROACTIVELY for system documentation, architecture guides, or technical deep-dives.
Open agent

