Skip to main content

Overview

The Security Team pack provides expert agents for comprehensive security assessments across applications, infrastructure, and blockchain systems. From security audits to penetration testing, from smart contract analysis to compliance frameworks — this pack covers offensive and defensive security. Perfect for security engineers, penetration testers, compliance teams, and organizations prioritizing security.

Installation

npx github:dmicheneau/opencode-template-agent install --pack security

Included Agents

security-auditor

Security Audit SpecialistCode security reviews, vulnerability assessments, risk evaluation, and OWASP Top 10 analysis

penetration-tester

Penetration Testing ExpertOffensive security testing, vulnerability exploitation, attack simulation, and risk demonstrations

smart-contract-auditor

Smart Contract SecurityBlockchain security audits, Solidity vulnerability detection, attack pattern analysis, and Web3 security

compliance-auditor

Compliance Framework SpecialistSOC2, GDPR, HIPAA, PCI-DSS, ISO 27001 compliance audits and framework implementation

Who Should Use This Pack?

Conduct comprehensive security audits and implement security controls
Perform offensive security testing and identify exploitable vulnerabilities
Ensure regulatory compliance and implement security frameworks
Audit smart contracts and secure Web3 applications

Example Workflow

Here’s how to perform a comprehensive security assessment:
1

Initial security audit

Use security-auditor for comprehensive code and architecture review
@security/security-auditor
Audit this authentication system for security vulnerabilities
2

Penetration testing

Use penetration-tester to identify exploitable vulnerabilities
@security/penetration-tester
Test this API for injection attacks, broken authentication, and authorization bypass
3

Smart contract audit (if applicable)

Use smart-contract-auditor for blockchain security
@security/smart-contract-auditor
Audit this DeFi smart contract for reentrancy and overflow vulnerabilities
4

Compliance assessment

Use compliance-auditor to verify regulatory requirements
@security/compliance-auditor
Assess our SOC2 compliance for access controls and data encryption
5

Remediation guidance

Use security-auditor to prioritize fixes and provide remediation steps
@security/security-auditor
Prioritize these 15 vulnerabilities by severity and provide remediation guidance
6

Verify fixes

Use penetration-tester to confirm vulnerabilities are resolved
@security/penetration-tester
Re-test the authentication system to verify the SQL injection fix

Key Capabilities

Security Auditing

  • OWASP Top 10 vulnerability detection
  • Code security reviews
  • Architecture security assessment
  • Threat modeling
  • Security best practices guidance

Penetration Testing

  • Application security testing (web, mobile, API)
  • Network security assessment
  • Social engineering simulations
  • Vulnerability exploitation
  • Attack path analysis

Smart Contract Security

  • Solidity vulnerability detection
  • Reentrancy and overflow analysis
  • Access control verification
  • Gas optimization review
  • Upgrade pattern security

Compliance Frameworks

  • SOC2 Type I and Type II
  • GDPR data protection
  • HIPAA healthcare compliance
  • PCI-DSS payment security
  • ISO 27001 information security

Common Use Cases

Agents: security-auditor → penetration-tester → compliance-auditorComprehensive security assessment of web applications with compliance verification.

Vulnerability Categories

security-auditor and penetration-tester cover:
  • Injection attacks (SQL, NoSQL, command)
  • Broken authentication and session management
  • Cross-Site Scripting (XSS)
  • Security misconfiguration
  • Sensitive data exposure
  • And more…
smart-contract-auditor detects:
  • Reentrancy attacks
  • Integer overflow/underflow
  • Access control issues
  • Front-running vulnerabilities
  • Gas optimization issues
security-auditor and penetration-tester assess:
  • Network segmentation
  • Firewall configurations
  • Encryption in transit and at rest
  • Container and orchestration security
  • Cloud security posture
compliance-auditor verifies:
  • Access controls and authentication
  • Data encryption and protection
  • Audit logging and monitoring
  • Incident response procedures
  • Business continuity planning

Security Assessment Process

PhaseAgentsActivities
Reconnaissancepenetration-testerInformation gathering, attack surface mapping
Scanningsecurity-auditor, penetration-testerAutomated and manual vulnerability detection
Exploitationpenetration-testerAttempt to exploit identified vulnerabilities
Reportingsecurity-auditorDocument findings, severity ratings, remediation
Compliancecompliance-auditorMap findings to compliance requirements
Verificationpenetration-testerRe-test after fixes are implemented

Compliance Frameworks

FrameworkFocusAgent
SOC2Service organization controls for SaaScompliance-auditor
GDPREU data protection and privacycompliance-auditor
HIPAAHealthcare data protectioncompliance-auditor
PCI-DSSPayment card data securitycompliance-auditor, security-auditor
ISO 27001Information security managementcompliance-auditor, security-auditor
OWASP ASVSApplication security verificationsecurity-auditor, penetration-tester

Complementary Agents

Consider adding these agents for expanded security coverage:
  • security-engineer — Design secure architectures and implement DevSecOps
  • code-reviewer — Automated code quality and security reviews
  • docker-specialist — Container security and image scanning
  • kubernetes-specialist — Kubernetes security hardening
  • aws-specialist — Cloud security posture and IAM policies

Security Tools Integration

The security pack agents work alongside these tools:
Static Application Security Testing:
  • Semgrep, SonarQube, Checkmarx
  • Agents provide manual review and false positive filtering

Next Steps

Install Security Pack

npx github:dmicheneau/opencode-template-agent install --pack security

Explore Individual Agents

Browse detailed documentation for each agent

DevOps Pack

Add infrastructure security and deployment automation

Backend Pack

Build secure backend systems and APIs

Build docs developers (and LLMs) love