ClaudeSuperPower

Best of / Subagents

Best Security Subagents

17 Subagents in the security category, ranked by GitHub stars — updated automatically as our nightly sync refreshes stats.

  1. 1

    ECC

    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

    235.3K
  2. 2

    scan-inventory

    Restricted read-only repository cartographer dispatched by the Claude Security scan workflow to partition the tree into components and account for every top-level directory; not for direct invocation or vulnerability research.

    32.8K
  3. 3

    claude-security

    The dedicated Claude Security orchestrator. Hand it an unattended job — "fully scan this repository and patch what you find; I understand it will use a lot of tokens" — and it runs the whole thing itself: capturing the revision, driving the multi-agent scan through the claude-security:scan workflow,

    32.8K
  4. 4

    scan-verifier

    Restricted read-only verifier dispatched by the Claude Security scan workflow to vote on one candidate finding; not for direct invocation.

    32.8K
  5. 5

    scan-researcher

    Restricted read-only vulnerability researcher dispatched by the Claude Security scan workflow; not for direct invocation or general exploration.

    32.8K
  6. 6

    security-auditor

    Adversarial security reviewer — OWASP Top 10, CWE, dependency CVEs, secrets, injection. Use for security debt scanning and pre-modernization hardening.

    32.8K
  7. 7

    endor-malware-response-agent

    0
  8. 8

    identity-server-specialist

    Expert in Duende IdentityServer configuration, deployment, and troubleshooting. Specializes in client configuration, token issuance flows, store customization, signing key management, and protocol compliance. Use for diagnosing authentication failures, token validation issues, and IdentityServer arc

    0
  9. 9

    citation_compliance_agent

    Verifies citations against the target journals format requirements and flags non-compliant entries

    0
  10. 10

    vulnerability-explainer

    Use this agent when the user asks what a specific vulnerability means and how to reason about it. Examples: "Explain CVE-2021-44228", "What does CVE-2021-45046 mean for log4j-core?", "Summarize this Endor vulnerability and tell me what to do next." Returns a concise vulnerability explanation with se

    0
  11. 11

    sca-remediation

    Plan and remediate dependency vulnerabilities with Endor SCA findings, VersionUpgrade/UIA evidence, separate low-risk PR lanes, deterministic risk decisions, local validation, and approved PR/MR creation.

    0
  12. 12

    package-risk-summary

    Use this agent when the user wants a concise risk profile for a specific package version without asking for a yes/no dependency decision. Examples: "Summarize npm lodash 4.17.20 risk", "Give me the risk picture for log4j-core 2.14.1", "What should I know about this package version before I review it

    0
  13. 13

    endor-ai-sast-triage-agent

    0
  14. 14

    compliance_agent

    Runs PRISMA-trAIce + RAISE compliance checks at Stage 2.5 / 4.5 integrity gates and emits Schema 12 compliance_report

    0
  15. 15

    endor-vulnerability-explainer-agent

    0
  16. 16

    oauth-oidc-specialist

    Expert in OAuth 2.0 and OpenID Connect protocol specifications, security best practices, and compliance. Specializes in flow selection, token security, protocol-level debugging, and standards compliance. Use for protocol design decisions, security reviews, and debugging token/auth flows at the HTTP

    0
  17. 17

    senior-pentester

    20+ year offensive security reviewer. Receives one logical firewall's normalized ruleset (already through deterministic detectors) and flags semantic concerns detectors can't catch — business-logic gaps, trust-boundary violations, unusual service combos. 2-4 instances dispatched in parallel during /

    0

FAQ

How is this ranked?

By GitHub stars by default. Once a subagent has community reviews, its rating is shown alongside the star count on its detail page.

How often is this updated?

Star counts and READMEs refresh automatically every night via our GitHub sync.