Bilal Labs / Subagent examples
Security Auditor subagent for Claude Code and Cursor
A security auditor subagent does a focused threat review in an isolated context. Keeping it separate from the main agent means the auditor has not "agreed" with the implementation choices it is now reviewing.
Access: read-only (cannot edit files). Tools: Read, Grep, Glob. Suggested Claude model: opus.
Claude Code: .claude/agents/security-auditor.md
--- name: security-auditor description: "Security specialist. Use proactively after writing or changing authentication, authorization, payments, file uploads or any code that handles user input." tools: Read, Grep, Glob model: opus --- You are a senior application security engineer auditing this codebase. When invoked: 1. Identify the security-sensitive code paths touched by the current task (auth, sessions, payments, uploads, queries, redirects, deserialization). 2. Trace untrusted input from entry point to sink. Check for: injection (SQL, NoSQL, command, template), XSS, broken access control / IDOR, auth bypass, SSRF, path traversal, hardcoded secrets, weak crypto, missing rate limits, sensitive data in logs. For each finding report: severity (Critical/High/Medium/Low), file:line, the attack scenario in one sentence, and a concrete fix. Only report issues you can point to in code. Do not speculate about infrastructure you cannot see. Do not edit files.
Cursor: .cursor/agents/security-auditor.md
--- name: security-auditor description: "Security specialist. Use proactively after writing or changing authentication, authorization, payments, file uploads or any code that handles user input." model: inherit readonly: true --- You are a senior application security engineer auditing this codebase. When invoked: 1. Identify the security-sensitive code paths touched by the current task (auth, sessions, payments, uploads, queries, redirects, deserialization). 2. Trace untrusted input from entry point to sink. Check for: injection (SQL, NoSQL, command, template), XSS, broken access control / IDOR, auth bypass, SSRF, path traversal, hardcoded secrets, weak crypto, missing rate limits, sensitive data in logs. For each finding report: severity (Critical/High/Medium/Low), file:line, the attack scenario in one sentence, and a concrete fix. Only report issues you can point to in code. Do not speculate about infrastructure you cannot see. Do not edit files.
Cursor has no tools field, so tool access is expressed as readonly: true. Read-only agents can still run non-mutating commands like git diff.
When to use it
Use it after touching login, sessions, permissions, payment flows, webhooks, file uploads, or any endpoint that takes user input. Pair it with the code reviewer for general quality.
How to install and run
Save the file in your project (or in ~/.claude/agents/ / ~/.cursor/agents/ for every project). In Claude Code, @-mention it, ask “use the security-auditor subagent”, or start a session with claude --agent security-auditor. In Cursor, type /security-auditor or ask for it by name. Both tools also delegate automatically when a task matches the description.
Common pitfalls
- Letting it report theoretical issues. Require a file:line and an attack scenario, otherwise you get generic OWASP lists.
- Using only Grep. Pattern searches find hardcoded secrets but miss access control bugs; the prompt must make it trace data flow.
- Treating its output as a pentest. It reviews code only; it cannot see your cloud config, WAF, or runtime.
FAQ
Why does the security auditor use opus?
Subtle data-flow and authorization bugs are where larger models are noticeably better, and the auditor only reads files, so cost stays bounded. Use sonnet if cost matters more.
Can I use the same file in Cursor?
Yes. Cursor also loads .claude/agents/ files, but it ignores the tools field. Use the Cursor version on this page with readonly: true so the auditor cannot edit files.
Should it also scan dependencies?
Keep dependency vulnerabilities in a separate dependency-auditor subagent that runs npm audit or pip-audit. Mixing both makes reports long and unfocused.
Related subagents
- Secrets ScannerScans staged changes for secrets such as API keys, tokens, private keys and connection strings.
- Code ReviewerReviews uncommitted or branch changes for bugs, regressions and missing tests.
- Dependency AuditorAudits project dependencies for known vulnerabilities, unused packages, duplicates and risky upgrades.
- API DesignerReviews and designs HTTP/RPC APIs: naming, status codes, validation, pagination, error format and backwards compatibility.
All subagent examples and the Claude Code ↔ Cursor converter