Security Agent

Meet Olivier. Your Security Engineer specialist agent.

Olivier is the domain specialist for security in the CloudThinker Multi-Agent System. He continuously tests your code, APIs, infrastructure, databases, identities, and secrets — discovering, exploiting safely, and remediating in the same pipeline run.

Oliver, the CloudThinker Security Engineer specialist agent
Sub-skills

Leading use cases, customizable Skills

These are leading patterns customers run with Olivier — code, web, infrastructure, database, identity, and secrets. They're starting points, not the limit — extend, replace, or add your own sub-skill with the Skills Framework.

/code-security

Static Code Security

Pre-build AST parsing, custom Semgrep rules, and SCA dependency audits — surfaces the flaws that ship into the runtime.

FastAPI / Next.js repositories
AST-level reachability analysis
Custom Semgrep rules

/web-security

Active Web & API Security

Dynamic session fuzzing, JWT / OAuth handling, IDOR / BOLA discovery, and exploit chaining across authenticated routes.

Live REST and GraphQL routes
Auth-aware (JWT, OAuth, MFA)
OWASP API Top 10 coverage

/infra-security

Cloud & Kubernetes Security

Audits container namespaces, network policies, IRSA bindings, and pod privilege boundaries across your fleet.

EKS workloads and IAM
CIS Kubernetes Benchmark
IRSA / pod privilege checks

/database-security

Database Security

Safe, read-only injection validation, parameter leak audits, and privilege-bypass checks against live storage layers.

PostgreSQL, Redis, SQL stores
Read-only PoC execution
Privilege escalation audits

/identity-access

Identity & Access

Token-signing validation, session fixation, privilege escalation paths, and broken-auth flow detection.

OAuth / SAML gateways
Session fixation testing
IdP federation audits

/secrets-guardian

Secrets & Config Guardian

Detects hardcoded keys, stale certificates, unauthorized secret access, and configuration drift across environments.

Env configs and vaults
Cert expiry + rotation checks
Secret-access anomaly detection
Workflow

From prompt to repeatable Command in three steps

Start with a prompt

Ask Olivier in chat what to test. He executes a one-shot run inside Sandbox Isolation, mapping the surface, resolving auth, and exporting a verified report.

@olivier please help to pentest the web API with black-box and white-box testing per OWASP Top 10, and export the report with CVE mapping.

Persist as a Skill

Use /create-skill to capture the discovered surface, auth flow, Rules of Engagement, validation logic, and notification routing as a reusable Skill versioned in the Knowledge Base.

/create-skill pentesting-web-api
  --from-thread #current
  --scope api.example.com
  --auth bearer-via-login
  --owasp top-10
  --report cve-mapped

Run anywhere as a Command

Invoke the saved Skill as a /-prefix Command from chat, webhook, or schedule. Re-runs are deterministic — same RoE, same surface, same CVE-mapped report.

/pentesting-web-api
Olivier detects environment drift on each run and proposes a Skill update for human-approved merge — no manual maintenance.
Safety

Safe by construction — from sandbox to audit

Olivier inherits the same platform primitives that protect every CloudThinker agent. Continuous pentesting runs without exposing customer data, mutating production, or leaving an unaudited trail.

Sandbox Isolation

Every run executes inside an ephemeral microVM with strict egress and a tamper-evident audit trail.

Per-run microVM
Egress allowlist
Auto-destroy on completion

Guardrails Engine

Guard-in and guard-out policy enforcement on every model call — PII / PHI redaction and secret detection by default.

PII / PHI redaction
Secret detection
Prompt-injection defense

Rules of Engagement

Strict scope, method, and rate-limit constraints. Read-only proof-of-concept execution. No destructive operations.

Scope allowlist
Read-only PoC
Pre-execution query filters

Immutable audit

Every reasoning step, tool call, and finding is recorded — exportable to your SIEM and reviewable by compliance.

Tamper-evident logs
SIEM-exportable
Replayable decisions

Compliance Certifications

We maintain the highest industry standards and regularly undergo rigorous third-party audits to ensure compliance.

Talk to Security

Ready to put Olivier to work on your stack?

Our security team partners directly with your security, compliance, and procurement leads — SOC 2 report, DPA, security questionnaire, and BYOC walkthroughs on request.

  • OWASP Top 10 + CVE-mapped reports
  • Sandboxed, read-only proof-of-concept
  • SOC 2 Type II compliant