Olivier is the domain specialist for security in the CloudThinker Multi-Agent System. He continuously tests your code, APIs, infrastructure, databases, identities, and secrets — discovering, exploiting safely, and remediating in the same pipeline run.

These are leading patterns customers run with Olivier — code, web, infrastructure, database, identity, and secrets. They're starting points, not the limit — extend, replace, or add your own sub-skill with the Skills Framework.
Static Code Security
Pre-build AST parsing, custom Semgrep rules, and SCA dependency audits — surfaces the flaws that ship into the runtime.
Active Web & API Security
Dynamic session fuzzing, JWT / OAuth handling, IDOR / BOLA discovery, and exploit chaining across authenticated routes.
Cloud & Kubernetes Security
Audits container namespaces, network policies, IRSA bindings, and pod privilege boundaries across your fleet.
Database Security
Safe, read-only injection validation, parameter leak audits, and privilege-bypass checks against live storage layers.
Identity & Access
Token-signing validation, session fixation, privilege escalation paths, and broken-auth flow detection.
Secrets & Config Guardian
Detects hardcoded keys, stale certificates, unauthorized secret access, and configuration drift across environments.
Ask Olivier in chat what to test. He executes a one-shot run inside Sandbox Isolation, mapping the surface, resolving auth, and exporting a verified report.
@olivier please help to pentest the web API with black-box and white-box testing per OWASP Top 10, and export the report with CVE mapping.
Use /create-skill to capture the discovered surface, auth flow, Rules of Engagement, validation logic, and notification routing as a reusable Skill versioned in the Knowledge Base.
/create-skill pentesting-web-api --from-thread #current --scope api.example.com --auth bearer-via-login --owasp top-10 --report cve-mapped
Invoke the saved Skill as a /-prefix Command from chat, webhook, or schedule. Re-runs are deterministic — same RoE, same surface, same CVE-mapped report.
/pentesting-web-api
Olivier inherits the same platform primitives that protect every CloudThinker agent. Continuous pentesting runs without exposing customer data, mutating production, or leaving an unaudited trail.
Every run executes inside an ephemeral microVM with strict egress and a tamper-evident audit trail.
Guard-in and guard-out policy enforcement on every model call — PII / PHI redaction and secret detection by default.
Strict scope, method, and rate-limit constraints. Read-only proof-of-concept execution. No destructive operations.
Every reasoning step, tool call, and finding is recorded — exportable to your SIEM and reviewable by compliance.
Our security team partners directly with your security, compliance, and procurement leads — SOC 2 report, DPA, security questionnaire, and BYOC walkthroughs on request.