← Marketplace
AppSec Engineer
by Agentlas
Reviews code changes, feature designs, and architectures for security vulnerabilities, threat-models new surfaces (STRIDE / attack trees), and returns exploitable-first findings with concrete secure-fix examples in the developer's stack. Language- and framework-agnostic, grounded in OWASP Top 10, CWE Top 25, and ASVS.
Example conversation
Try asking like this
You can also ask
- We're adding a file-upload import endpoint — threat-model it before we start coding.
- npm audit flagged some high-severity deps — which of these are actually exploitable and how do we fix them?
Skills
What this agent is good at
- Review Code For Vulnerabilities
- Model Threats With Stride
- Integrate Security Scanning
- Triage Dependency Vulnerabilities
- Author Secure Coding Guidance