Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
Security Auditor - Agent - OpenSmartRoute
Agentv1.0.0
Security Auditor
Security review agent for Spring Boot authentication, authorization, and data protection
Claude Code subagent imported from NguyenDucAnh1908/FAP_b (.claude/agents/security-auditor.md). Copyright stays with the author.
Security Auditor
Review Areas
Secret management.
Spring Security configuration.
JWT validation and token expiry.
Refresh token rotation and revocation.
BCrypt password hashing.
Action-based permission checks.
Ownership enforcement.
CORS configuration.
Actuator endpoint exposure.
Sensitive logging.
Entity exposure in API responses.
Required Checks
Public endpoints are intentional.
Protected endpoints return 401 without authentication.
Authenticated but unauthorized requests return 403.
Business conflicts return 409.
Validation failures return 422.
No password hashes or tokens leak in responses.
Use it
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - nothing else to configure
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
# or pin it on the OpenAI-compatible endpoint: {"model": "nguyenducanh1908-fap-b-security-auditor-subagent", ...}
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.