CipherClaw: Using a Security Persona to Audit Code with Claude

CipherClaw is a tool that applies a security-focused persona to Claude Code, transforming it from a code writer into a security auditor. The persona, named TALON, is loaded via a CLAUDE.md file and includes security knowledge bases.
How It Works
The architecture consists of three main components:
- SOUL.md: Defines the persona identity
- MEMORY.md: Contains security knowledge including OWASP Top 10, CWE Top 25, and 20+ secret patterns
- 7 skill files: Loaded via
@importin CLAUDE.md
Commands and Usage
TALON responds to several security audit commands:
TALON: full security auditscan for secretsthreat model thiscompliance check SOC2IaC security review
Example Findings
When run on a Next.js app without any hints about bug locations, TALON identified 17 security issues including:
- [CRITICAL] Unauthenticated endpoint returning passwordHash + role:ADMIN to any caller with no token required
- [CRITICAL] DELETE endpoint with zero ownership check — allowing any user to delete anyone else's data (BOLA/IDOR vulnerability)
- [CRITICAL] Hardcoded auth token in source code
- [HIGH] File upload accepting user-controlled filename — potential path traversal vulnerability
- [MEDIUM] Phone numbers stored without encryption (GDPR Article 32 violation)
Each finding included:
- Exact line numbers
- curl exploit commands to reproduce the vulnerability
- Specific fixes
- Compliance control mapping for SOC2, HIPAA, and GDPR
The tool is designed for developers using Claude Code who want to integrate security auditing into their development workflow without switching contexts or tools.
📖 Read the full source: r/ClaudeAI
👀 See Also

Open-sourced Claude Code prompts reverse-engineered using Claude
A developer used Claude to rewrite all 26 prompts from Claude Code's source after studying the TypeScript codebase during a brief public availability window. The MIT-licensed collection includes system, tool, agent, memory, coordinator, and utility prompts.
Hoplite (YC S26) Launches Cloud Deployment for Coding Agents with QA Previews
Hoplite lets you deploy coding agents in the cloud, porting over your local setup including sessions, memories, and MCP servers. It includes a custom harness and focuses on onboarding and previews for QA.

Session Search: Local Full-Text Search for Claude Code and Codex Sessions, Now in Your Menu Bar
Session Search indexes local Claude Code and Codex transcripts using SQLite FTS, enabling deep full-text search across errors, commands, filenames, and decisions—accessible from the macOS menu bar with highlighted snippets.

agentcache: Python Library for Multi-Agent LLM Prefix Caching
agentcache is a Python library that enables multi-agent LLM frameworks to share cached prompt prefixes, achieving up to 76% cache hit rates and cutting inference time by more than half in tests with GPT-4o-mini.