Security Auditor by NeoLabHQ
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be…
- Type
- Subagent
- Repository
- NeoLabHQ/context-engineering-kit
- GitHub stars
- 1.7k
- License
- GPL-3.0
- Repo last updated
- Aug 26, 2026
- Source file
- README.md
What Security Auditor by NeoLabHQ is
Security Auditor by NeoLabHQ is a subagent published in the NeoLabHQ/context-engineering-kit repository on GitHub, which has about 1.7k stars. The repository describes itself as: “Hand-crafted Claude Code Skills focused on improving agent results quality. Compatible with OpenCode, Cursor, Antigravity, Gemini CLI, and others. Includes CodeRabbit open-source alternative.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Security Auditor and get back a compact result.
How to install Security Auditor by NeoLabHQ
Claude Code
- Download README.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from README.md, shared under the repository's GPL-3.0 license. Read the full file on GitHub.
Advanced context engineering techniques and patterns for Claude Code, OpenCode, Cursor, Antigravity and more.
Quick Start · Plugins · Github Action · Reference · Docs
Context Engineering Kit
A hand-crafted collection of advanced context engineering techniques and patterns with minimal token footprint, focused on improving agent result quality and predictability.
The marketplace is based on prompts our company's developers have used daily for a long time, supplemented by plugins from benchmarked papers and high-quality projects.
Key Features
- Simple to Use - Easy to install and use without any dependencies. Contains automatically used skills and self-explanatory commands.
- Token-Efficient - Carefully crafted prompts and architecture, preferring command-oriented skills with sub-agents over general information skills when possible, to minimize populating context with unnecessary information.
- Quality-Focused - Each plugin is focused on meaningfully improving agent results in a specific area.
- Granular - Install only the plugins you need. Each plugin loads only its specific agents, commands, and skills, without overlap or redundant skills.
- Scientifically proven - Plugins are based on proven techniques and patterns validated by reputable benchmarks and studies.
- Open-Standards - Skills are based on agentskills.io specification. The SDD plugin is based on the Arc42 specification standard for software development documentation.
News
Updates from key releases:
- v3.1.0: Improved Spec-Driven Development plugin generated code quality by embedding DDD/SOLID rules in the developer agent and adding a dedicated code-reviewer agent that applies functional and OOP best-practices rules together with Muda waste analysis to reduce code complexity and duplication.
- v3.0.0: Added support for AMP and Hermes agents. Tech Stack plugin now automatically injects typescript best practices when agent reads or writes TypeScript files.
- v2.2.0: Subagent-Driven Development plugin now works as a distilled version of SDD plugin using meta-judge and judge sub-agents for specification generation on the fly and in parallel to implementation. DDD plugin now includes Clean Architecture, DDD, SOLID, Functional Programming, and other pattern examples as rules that are automatically added to the context during code writing.
- v2.1.0: Spec-Driven Development plugin agents include high-level code quality guidelines from DDD plugin.
- v2.0.0: Spec-Driven Development plugin was rewritten from scratch. It is now able to produce working code in 99% of cases on real-life production projects!
Quick Start
Step 1: Install Marketplace and Plugins
Claude Code
Open Claude Code and add the Context Engineering Kit marketplace:
/plugin marketplace add NeoLabHQ/context-engineering-kitThis makes all plugins available for installation, but does not load any agents or skills into your context.
Install any plugin — for example, reflexion:
/plugin install reflexion@NeoLabHQ/context-engineering-kitEach installed plugin loads only its specific agents, commands, and skills into Claude's context.
Gemini CLI
Install the extension directly from the repository:
gemini extensions install https://github.com/NeoLabHQ/context-engineering-kitNote: This installs every plugin's skills and agents as a single bundle — there's no per-plugin selection like Claude Code's. Unfortunately, Gemini CLI does not support per-plugin selection. But you can delete skills and agents that you don't need, after installation.
Antigravity CLI
Install the plugin directly from the repository's antigravity/ folder — Gemini CLI is not required:
agy plugin install https://github.com/NeoLabHQ/context-engineering-kit/antigravityNote: This installs every plugin's skills and agents as a single bundle — there's no per-plugin selection like Claude Code's. Unfortunately, Antigravity CLI does not support per-plugin selection. But you can delete skills and agents that you don't need, after installation.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Security Auditor by NeoLabHQ?
Security Auditor by NeoLabHQ is a subagent for Claude Code and Claude Cowork from the NeoLabHQ/context-engineering-kit repository on GitHub. Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be…
How do I install Security Auditor by NeoLabHQ in Claude Code?
Download README.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Security Auditor by NeoLabHQ in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Security Auditor by NeoLabHQ safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Team Lead Use this agent when reorganizing implementation steps for maximum parallel execution with explicit dependency tracking and agent… Subagent · NeoLabHQ/context-engineering-kit
- Sdd Specification Driven Development workflow commands and agents, based on Github Spec Kit and OpenSpec. Uses specialized agents for effective context management and quality review. Plugin · NeoLabHQ/context-engineering-kit
- Tdd Introduces commands for test-driven development, common anti-patterns and skills for testing using subagents. Plugin · NeoLabHQ/context-engineering-kit
- Tech Writer Creates and maintains comprehensive, accessible technical documentation by transforming complex concepts into clear, structured content that helps users accomplish their tasks Subagent · NeoLabHQ/context-engineering-kit
- Software Architect Use this agent when synthesizing research findings, codebase analysis, and business requirements into architectural solutions for task specifications. Subagent · NeoLabHQ/context-engineering-kit
- Researcher Use this agent when researching unknown technologies, libraries, frameworks, and dependencies to gather relevant resources and documentation for implementation tasks. Creates reusable skills that all agents can leverage. Subagent · NeoLabHQ/context-engineering-kit
- Qa Engineer Use this agent when adding LLM-as-Judge verification sections to implementation steps in task files. Analyzes artifact types, determines… Subagent · NeoLabHQ/context-engineering-kit
- Tech Lead Use this agent when breaking down architecture into implementation steps with success criteria, dependencies, and risk assessment, and reorganizing those steps for maximum parallel execution. Transforms architectural blueprints into executable, parallelized task sequences written as per-step sub-task files grouped into independently verifiable phases. Subagent · NeoLabHQ/context-engineering-kit