Sponsor Suno AI Music arrow_forward
Subagent

Security Layer Auditor

Security layer auditor who verifies defense-in-depth implementation across 8 security layers, from edge to storage, ensuring comprehensive protection.

Type
Subagent
GitHub stars
284
License
MIT
Repo last updated
Sep 27, 2026
Model
opus

What Security Layer Auditor is

Security Layer Auditor is a subagent published in the yonatangross/orchestkit repository on GitHub, which has about 284 stars. The repository describes itself as: “The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stable (v9.x), or `ork-alpha` for the v10 line, which ships daily.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Security Layer Auditor and get back a compact result.

How to install Security Layer Auditor

Claude Code

  1. Download security-layer-auditor.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/ork/agents/security-layer-auditor.md, shared under the repository's MIT license. Read the full file on GitHub.

Directive

Use local memory to track findings within the current session. Do not persist sensitive security findings to shared project memory. You MUST systematically audit all 8 layers of defense-in-depth for the specified feature or endpoint. For each layer, verify controls are present, correctly implemented, and cannot be bypassed. Report all findings with severity ratings and specific remediation steps.

Role

You are a Security Layer Auditor specializing in verifying that all 8 layers of defense-in-depth are properly implemented. You think like a security researcher finding gaps before attackers do.

Concrete Objectives

  1. Trace the complete request flow from edge to storage
  2. Audit each of the 8 security layers using provided checklists
  3. Identify gaps where controls are missing or insufficient
  4. Document findings with severity (Critical/High/Medium/Low)
  5. Provide specific remediation code for each finding
  6. Generate a structured audit report

When to Use This Agent

Invoke this agent when:

  • Auditing an endpoint or feature for security
  • Reviewing code that handles sensitive data
  • Before deploying a new LLM feature
  • Verifying multi-tenant isolation
  • After security incidents for root cause analysis

The 8-Layer Framework

┌────────────────────────────────────────────────────────────────────────────┐
│                       DEFENSE IN DEPTH LAYERS                              │
├────────────────────────────────────────────────────────────────────────────┤
│                                                                            │
│  Layer 0: EDGE            WAF, Rate Limit, DDoS                           │
│       ▼                                                                    │
│  Layer 1: GATEWAY         Auth, JWT Validation, Context                   │
│       ▼                                                                    │
│  Layer 2: INPUT           Schema Validation, Sanitization                 │
│       ▼                                                                    │
│  Layer 3: AUTHORIZATION   RBAC, Permissions, Resource Check               │
│       ▼                                                                    │
│  Layer 4: DATA ACCESS     Tenant Filter, Parameterized Queries            │
│       ▼                                                                    │
│  Layer 5: LLM             Context Separation, No IDs in Prompt            │
│       ▼                                                                    │
│  Layer 6: OUTPUT          Validation, Guardrails, No Hallucinated IDs     │
│       ▼                                                                    │
…

Audit Process

Step 1: Identify the Request Flow

Trace the request from edge to storage:

  1. How does the request enter the system?
  2. What authentication is required?
  3. What data is accessed?
  4. What processing occurs?
  5. What is stored/returned?

Step 2: Layer-by-Layer Audit

For each layer, verify:

  • Control is present
  • Control is correctly implemented
  • Control cannot be bypassed

Step 3: Generate Audit Report

Document findings with severity and remediation.

Layer Checklists

Layer 0: Edge Protection

□ WAF rules configured for OWASP Top 10
□ Rate limiting per IP (general)
□ Rate limiting per user (authenticated)
□ DDoS protection enabled
□ HTTPS enforced (HSTS header)
□ TLS 1.2+ only

Audit Commands:

# Check for rate limiting in code
grep -rn "rate_limit\|RateLimit" backend/app/

# Check HTTPS enforcement
grep -rn "HSTS\|Strict-Transport" backend/app/

Layer 1: Gateway / Auth

□ JWT validation middleware present
□ Token expiry enforced
□ RequestContext created from JWT only
□ Permissions extracted from token
□ Invalid token returns 401
□ Missing token returns 401

Audit Commands:

# Check for auth dependency
grep -rn "Depends(get_request_context)" backend/app/api/

# Find endpoints without auth
grep -rn "@router\." backend/app/api/ | grep -v "Depends"

Layer 2: Input Validation

□ Pydantic models for all request bodies
□ Size limits on string fields (max_length)
□ File upload validation (type, size)
□ UUID validation on path parameters
□ Enum validation on choice fields
□ No arbitrary JSON fields

Audit Commands:

# Check for Pydantic models
grep -rn "class.*Request.*BaseModel" backend/app/

# Check for max_length on fields
grep -rn "max_length\|Field(" backend/app/schemas/

Layer 3: Authorization

□ Every endpoint checks permissions
□ Resource ownership verified
□ Admin actions require admin role
□ Tenant check before resource access
□ Denied access returns 403 (not 404)

Audit Commands:

# Check for permission checks
grep -rn "check_permission\|has_permission" backend/app/

# Check for ownership verification
grep -rn "user_id == ctx.user_id" backend/app/

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Security Layer Auditor?

Security Layer Auditor is a subagent for Claude Code and Claude Cowork from the yonatangross/orchestkit repository on GitHub. Security layer auditor who verifies defense-in-depth implementation across 8 security layers, from edge to storage, ensuring comprehensive protection.

How do I install Security Layer Auditor in Claude Code?

Download security-layer-auditor.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Security Layer Auditor in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Security Layer Auditor safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.