Subagents, all 2,179 of them.
Specialist agents your main agent can delegate to. Browse subagent definitions from the public directories. Add one to your gateway and every agent you use gets it through one link.
132 results · page 2 of 5
- Add to your gateway
Octopus Security AuditSecurity
Comprehensive security auditing skill leveraging the security-auditor persona. Use for vulnerability scanning, OWASP compliance checks, and security reviews.
- Add to your gateway
Security AuditorSecurity
Security auditor for DevSecOps, OWASP compliance, vulnerability assessment, and threat modeling
- Add to your gateway
Security PrinciplesSecurity
Critique principles for secure code development
- Add to your gateway
Exploitability Validator AgentSecurity
Multi-stage pipeline to validate vulnerability findings are real, reachable, and exploitable
- Add to your gateway
Oss Investigator Ioc Extractor AgentSecurity
Extract IOCs from vendor security reports as forensic evidence
- Add to your gateway
Api BuilderSecurity
REST and GraphQL API design expert covering resource modeling, authentication flows, rate limiting, versioning, and OpenAPI spec generation. Use when designing API endpoints, implementing JWT/API-key auth, or writing OpenAPI docs. Trigger with "design an API", "API endpoint help".
- Add to your gateway
BlueSecurity
Design MITRE ATT&CK-mapped detection rules, CIS-benchmarked hardening playbooks, and SOC triage procedures to reduce attacker dwell time. Use when building defensive security controls or auditing detection coverage. Trigger with "design detection rules", "write a hardening playbook".
- Add to your gateway
Firestore Security AgentSecurity
Generates and validates production-grade Firestore security rules for user auth, role-based access, A2A service accounts, and data validation patterns, with emulator-ready unit tests. Use when securing Firestore collections or enabling agent-to-agent communication. Trigger with "generate Firestore s
- Add to your gateway
Geepers ApiSecurity
Reviews APIs for REST compliance, naming consistency, OpenAPI coverage, and security posture. Use when adding endpoints, auditing an existing API, or standardizing a messy surface. Trigger with "audit the API", "review endpoint design".
- Add to your gateway
Geepers Code CheckerSecurity
Validates code across syntax, logic, security, performance, and accessibility dimensions using multi-model synthesis, then produces a prioritized report with corrected snippets. Use after code generation or before production hand-off. Trigger with "check this code for errors", "validate the generate
- Add to your gateway
Geepers DepsSecurity
Audits project dependencies for CVEs, outdated packages, and license compatibility using pip-audit, npm audit, and pip-licenses/license-checker. Use when hardening security posture or planning a major dependency upgrade. Trigger with "audit dependencies for vulnerabilities", "check what breaks if I
- Add to your gateway
Geepers Intern PoolSecurity
Cost-optimized code generator using tiered model routing — cheap models for boilerplate, mid-tier for logic, high-tier only for security-critical paths. Use when generating bulk code on a budget. Trigger with "generate code cheaply", "draft the implementation".
- Add to your gateway
HuntSecurity
Runs hypothesis-driven threat hunts to surface attackers that evaded automated detection — IOC enrichment, compromise assessment, and hunting playbooks. Use when proactively searching for threats or assessing potential compromise. Trigger with "run a threat hunt", "assess for compromise".
- Add to your gateway
PatchSecurity
Triages CVEs using CVSS + EPSS + CISA KEV, designs patch SLA programs with asset-criticality tiers, and audits existing vuln management programs. Use when prioritizing a backlog of CVEs, designing a patching cadence, or finding SLA gaps. Trigger with "triage our CVEs", "design a vulnerability manage
- Add to your gateway
PhishSecurity
Designs phishing simulation programs, security awareness curricula, and social engineering assessments that drive behavior change through immediate feedback and difficulty progression. Use when building or auditing a security awareness program or measuring click/report rates. Trigger with "design a
- Add to your gateway
SastSecurity
Integrates SAST/DAST tooling into the SDLC — Semgrep rules, CodeQL, OWASP ZAP, and secure code review covering the full OWASP Top 10. Use when adding security scanning to a pipeline or fixing a security finding. Trigger with "set up SAST scanning", "fix this security finding".
- Add to your gateway
Security Auditor ExpertSecurity
OWASP Top 10 vulnerability scanner and security code reviewer that identifies injection flaws, auth failures, misconfigurations, and crypto weaknesses with CWE-mapped findings and remediation code. Use when you need a security audit, vulnerability scan, or code review for security issues. Trigger wi
- Add to your gateway
Severity TriageSecurity
Classifies incoming issues, bug reports, and vulnerability findings using the S1-S4 severity framework with blast-radius analysis and escalation routing. Use when triaging bugs or security findings that need consistent prioritization. Trigger with "triage this issue", "classify severity".
- Add to your gateway
Threat ModelerSecurity
Security threat modeling specialist that applies STRIDE to system architectures, identifies trust boundary risks, and produces prioritized mitigation plans with risk scores. Use when designing a new system, reviewing architecture for security threats, or reducing attack surface. Trigger with "threat
- Add to your gateway
VoltSecurity
Designs firmware architectures, HAL boundaries, RTOS selection, and OTA rollback strategies for ESP32, STM32, nRF52, and RP2040 targets. Use when you need a firmware architecture, OTA update strategy, or embedded security design. Trigger with "design my firmware architecture", "help me add OTA updat
- Add to your gateway
WardenSecurity
Writes threat models, IAM policies, hardening specs, and auth implementation reviews sized to actual risk — not compliance theater. Use when you need a security audit, secrets management design, or auth pattern review. Trigger with "threat model my app", "audit my security posture".
- Add to your gateway
Security AuditorSecurity
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.
- Add to your gateway
Code ReviewerSecurity
Expert code review specialist. Proactively reviews code for quality, security, and maintainability. Use immediately after writing or modifying code.
- Add to your gateway
Flow Nexus AuthSecurity
Flow Nexus authentication and user management specialist. Handles login, registration, session management, and user account operations using Flow Nexus MCP tools.
- Add to your gateway
Security ManagerSecurity
Implements comprehensive security mechanisms for distributed consensus protocols
- Add to your gateway
Ash Policy ReviewerSecurity
Ash policy security reviewer — audits policies, checks, and authorization rules for gaps, bypass patterns, and ordering hazards. Use proactively on Ash resources with policies do blocks or checks/ modules.
- Add to your gateway
Hex Deps TriagerSecurity
Triage Hex supply-chain audit findings in Elixir/Phoenix — review diff windows and metadata to produce structured security verdicts. Use after /phx:deps-audit.
- Add to your gateway
Parallel ReviewerSecurity
Parallel code review using 4 specialist agents (elixir-reviewer, security-analyzer, testing-reviewer, verification-runner). Use for thorough review of significant changes.
- Add to your gateway
Security AnalyzerSecurity
Security audit specialist for Elixir/Phoenix - authentication, authorization, input validation, OWASP vulnerabilities. Use proactively when implementing auth or handling user input.
- Add to your gateway
Api ExpertSecurity
Use this agent for Output.ai API server design, Express middleware configuration, workflow execution endpoints, and API security patterns. Specializes in workflow integration via REST APIs.