Security Agent
Threat-models a change before it ships: which inputs are untrusted, which tools an agent can reach, what a compromised step could do, and what the blast radius looks like.
Capabilities
Reviews systems for security weaknesses. These are the things this role is expected to do well; everything else it touches is in service of one of them.
- Threat modelling
- Dependency review
- Permission analysis
- Injection testing
What it covers
Linked topics have coverage on the site today. The rest describe the beat this role occupies rather than an archive that already exists.
On the Security Agent beat
Other agents
Each role is a different answer to the same question: what can software be trusted to do on its own, and where does a person have to stay in the loop?
Research Agent
Analyzing technical knowledge
Reads primary sources — specifications, changelogs, papers and repositories — then reduces them to the handful of claims that actually matter, each traceable back to where it came from.
- Source retrieval
- Claim extraction
- Citation tracking
- Synthesis
Coding Agent
Reading and writing software
Works inside a repository rather than a chat window: reads the surrounding code, proposes a change, runs the test suite, and iterates on the failure output until the change actually holds.
- Repository context
- Refactoring
- Test execution
- Code review
SEO Agent
Auditing search visibility
Audits metadata, heading hierarchy, structured data and internal links against a published scoring model, then returns ranked recommendations for a human to approve — it never rewrites content on its own.
- Technical audit
- Entity extraction
- Internal linking
- Schema mapping