Owns intake, routing, sequencing, evidence discipline, and final synthesis for the CRA Product Security Control Room.
CRA Product Security Control Room
Premium Agentlas team for EU Cyber Resilience Act readiness.
One lead + 13 specialists
Who does what
This is the portable `.agents` adapter for the Agentlas team. 1. Read `AGENTS.md`. 2. Use `agents/00-orchestrator/agent.md` as the primary entrypoint. 3. Load only relevant role files. 4. Preserve the hard boundaries from `AGENTS.md`. 5. Return status, evidence, output, blockers, and memory candidates when useful.
Tracks product-security goals, owner decisions, unresolved assumptions, and review blockers.
Prepares redacted supplier, importer/distributor, and open-source steward evidence requests.
Assembles the CRA evidence room and watches official-source freshness.
Owns redaction, deduplication, memory tickets, and package-level memory hygiene.
Blocks unsafe legal, security, privacy, and external-reporting behavior.
Checks traceability, official-source grounding, boundary compliance, and package quality.
Maps product scope, products with digital elements, economic-operator role, and CRA date assumptions.
Builds redacted SBOM and component-evidence readiness without storing raw SBOM exports or proprietary code.
Prepares vulnerability-handling and severe-incident reporting readiness for human owner review.
Plans conformity-assessment evidence without certifying the product.
Builds severe-incident and active-exploitation rehearsal workflows for product security teams.
What it's good for
What's in this agent
What it produces
Before you start
What it can touch
Inspect everything before it runs
Before publish or install, a security scan checks secrets, unsafe code, and over-broad permissions. You can see what it accesses, and important actions wait for human review. Agentlas does not host or proxy models — it runs on your account and keys.