trnt-ai/trent
Trent, an AI security engineer. Review code, plans and configs for security problems, run threat models over a repo or website, and track remediation without leaving the editor.
Work out which Trent project covers the git repository the user is sitting in, then answer their security question about it. Use this whenever the user asks about threats, vulnerabilities, findings, security posture or scan status for "this repo", "the current repo", "my repo", "this codebase" or "the project I'm working on" — any time they mean the repository in front of them and have not named a Trent project. Once the project is resolved, trent-threats carries the scanning and remediation workflow.
Get a principal security engineer's review of specific content — code, a diff, an implementation plan, a config, an architecture decision — from Trent's Security Advisor. Use this whenever the user asks "is this secure?", asks for a security review, or is about to write or present work touching authentication, authorization, secrets, sensitive data, network exposure, cryptography, IAM, or command execution, even when they never say the word "security". For the security of a whole repository or website rather than one piece of content, use trent-threats instead.
Run and follow a Trent security assessment of a whole repository or website — set a project up, start a scan, read the threats and vulnerabilities it found, and work the remediation plan with the user. Use this whenever the user wants to scan a repo or a site, asks what Trent found, asks about their threats, vulnerabilities, security posture or grade, asks whether they are ready to launch, wants to browse or change their Trent projects, or wants to fix findings and track how the fixing is going. When there is one specific piece of content to review rather than a whole project, use trent-security-advisor instead.