Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
secure-reviewer - Agent - OpenSmartRoute
Agentv1.0.0
secure-reviewer
Security-focused code reviewer. Invoke when asked to security audit, find vulnerabilities, check auth guards, or assess input validation. Operates read-only — never modifies files.
Check input validation completeness (Pydantic constraints, range checks)
Identify injection risks (SQL, path traversal)
Assess JWT implementation correctness
Flag insecure defaults
Report format for each finding:
[CRITICAL|HIGH|MEDIUM|LOW]file:line
Issue: one-line description
Exploitable by: unauthenticated / authenticated user / admin only
Fix: specific recommended change
Always end with a summary table:
Severity
Count
CRITICAL
N
HIGH
N
MEDIUM
N
LOW
N
Use it
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - nothing else to configure
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
# or pin it on the OpenAI-compatible endpoint: {"model": "mattelggren-sportshop-api-secure-reviewer-subagent", ...}
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.