Accelerate your agent development.
Production-grade agent templates ready to deploy in your Ghost Agent Factory instance.
- Templates
- 97
- templates
- Categories
- 10
- categories
-
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
CrowdStrike Falcon Alert Triage
Provides a ranked queue of open Critical and High Falcon alerts with their age, ownership, recurring signatures, and bursts.
Featured Security Operations 1 tools -
CVE Enrichment
Builds one record per CVE from KEV, EPSS, NVD, and OSV, and, when asked, reads the upstream fix to state the exact conditions under which the vulnerability applies.
Featured Threat Intelligence / Vulnerability Management 6 tools -
GitHub Dependabot Alert Triage
Reviews open Dependabot alerts for reachability in deployed code and dismisses the unreachable ones.
Featured Vulnerability Management 1 tools -
GitHub Repository Secrets Triage
Scans a GitHub repository for hardcoded secrets and separates the real, exposed credentials from placeholders, test values, and safely loaded config.
Featured Vulnerability Management / Application Security 1 tools -
Wiz Issue Triage
Writes an evidence-based triage judgment for each open Wiz issue and rejects the ones cloud checks prove are false positives.
Featured Vulnerability Management 7 tools -
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools -
Bitbucket Repository AI-Readiness Audit
Scores each repository in a Bitbucket workspace on how well a coding agent can work in it, and reports the ones below the bar.
Reporting and Compliance 1 tools -
Bitbucket Repository Code Vulnerability Detection
Finds exploitable vulnerabilities in a Bitbucket repository's own code, and verifies each one against the source before reporting it.
Vulnerability Management / Application Security 1 tools -
Bitbucket Repository SCA Triage
Scans a Bitbucket repository's dependencies for known vulnerabilities and separates the ones an attacker can exploit from the ones they cannot.
Vulnerability Management / Application Security 1 tools -
Bitbucket Repository Secrets Triage
Scans a Bitbucket repository for hardcoded secrets and separates the real, exposed credentials from placeholders, test values, and safely loaded config.
Vulnerability Management / Application Security 1 tools -
Bugcrowd Program Report
Delivers a weekly report on a Bugcrowd program's open submission queue, response times, duplicate and out-of-scope rates, reward spend, and the targets that are drawing no submissions.
Reporting and Compliance / Application Security 1 tools -
Bugcrowd Submission Triage
Reads each newly triaged Bugcrowd submission against the affected code, locates the fix, finds duplicates, and leaves the verdict as a comment with Bugcrowd visibility.
Vulnerability Management / Application Security 4 tools -
CrowdStrike Falcon Automation Health
Provides the Falcon Fusion workflows and scheduled reports that failed, stalled, missed their schedule, or were disabled.
Security Operations 1 tools -
CrowdStrike Falcon Control Drift
Provides the Falcon policies, exclusions, rules, and automations that changed since a baseline the team approved.
Endpoint Security 1 tools -
CrowdStrike Falcon CVE Leverage
Provides the Spotlight CVEs whose remediation removes the most risk across a CrowdStrike tenant.
Vulnerability Management 1 tools -
CrowdStrike Falcon Detection Telemetry QA
Provides a quality report on Falcon alert data, covering missing triage fields, missing ATT&CK mappings, and malformed ATT&CK IDs.
Security Operations 1 tools -
CrowdStrike Falcon Posture Report
Delivers a weekly report on Falcon sensor coverage, policy and exclusion changes, and anything in the tenant that needs attention, from failing automations to license use.
Reporting and Compliance / Endpoint Security 1 tools -
CrowdStrike Falcon Sensor Remediation
Provides a ranked queue of Falcon sensors that are stale, degraded, unprovisioned, or missing a core policy.
Endpoint Security 1 tools -
CrowdStrike Falcon Vulnerable Software Context
Provides the context of each vulnerable software finding on Falcon hosts, from system-installed to active or inactive development.
Vulnerability Management 1 tools -
Datadog Detection Posture Report
Delivers a weekly report on Datadog Cloud SIEM log ingestion gaps, detection rules that are disabled, erroring, or blind, and anything in the organization that needs an admin, from Security Filter exclusions to silent Agents.
Reporting and Compliance / Security Operations 1 tools -
Datadog Detection Tuning
Finds the Datadog Cloud SIEM detection rules that produce the most noise, reads each one against the signals it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Datadog Service SRE
Reviews a service's Datadog metrics, traces, error tracking, and deployments each day, traces each error to its source code, and proposes the fix, on any runtime that reports to Datadog.
Infrastructure Operations 4 tools -
Elastic Security Detection Posture Report
Delivers a weekly report on Elastic Security data stream gaps, detection rules that are failing, warning, or blind, and anything in the deployment that needs an admin, from offline Elastic Agents to lifecycle errors.
Reporting and Compliance / Security Operations 1 tools -
Elastic Security Detection Tuning
Finds the Elastic Security detection rules that produce the most noise, reads each one against the alerts it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Ghost Agent Factory Operation Assessment
Assesses the health, success, and efficiency of the agents in a Ghost Agent Factory workspace from their recent runs, and proposes the changes worth making.
Ghost Agent Factory / Reporting and Compliance 1 tools -
Ghost Agent Factory SRE
Checks the health of the Ghost Agent Factory that every agent runs on, and finds the failed runs the platform caused.
Ghost Agent Factory / Infrastructure Operations 1 tools -
GitHub Dependabot Alert Triage Recheck
Rechecks and reopens Dependabot alerts that were dismissed as not used if a later code change makes them reachable.
Vulnerability Management 1 tools -
GitHub Dependabot Posture Report
Delivers a weekly report on Dependabot coverage across a GitHub organization, what changed, and anything that needs attention.
Reporting and Compliance / Vulnerability Management 1 tools -
GitHub Dependabot Triage Agent Report
Provides a weekly compliance report on the agent runs inside the Ghost Agent Factory for Dependabot triage and recheck agents, with alerts dismissed, alerts reopened, and analyst time saved.
Vulnerability Management / Reporting and Compliance / Ghost Agent Factory 2 tools -
GitHub Public Repository Posture Audit
Reports the public repositories in a GitHub organization that fail its security policy, with each failing check.
Reporting and Compliance 1 tools -
GitHub Repository AI-Readiness Audit
Scores each repository in a GitHub organization on how well a coding agent can work in it, and reports the ones below the bar.
Reporting and Compliance 1 tools -
GitHub Repository Code Vulnerability Detection
Finds exploitable vulnerabilities in a GitHub repository's own code, and verifies each one against the source before reporting it.
Vulnerability Management / Application Security 1 tools -
GitHub Repository SCA Triage
Scans a GitHub repository's dependencies for known vulnerabilities and separates the ones an attacker can exploit from the ones they cannot.
Vulnerability Management / Application Security 1 tools -
GitLab Dependency Scanning Posture Report
Delivers a weekly report on dependency scanning coverage across a GitLab group, what changed, and anything that needs attention.
Reporting and Compliance / Vulnerability Management 1 tools -
GitLab Dependency Scanning Triage
Reviews open GitLab dependency scanning vulnerabilities for reachability in deployed code and dismisses the ones that are not used.
Vulnerability Management 1 tools -
GitLab Dependency Scanning Triage Agent Report
Provides a weekly compliance report on the agent runs inside the Ghost Agent Factory for GitLab dependency scanning triage and recheck agents, with vulnerabilities dismissed, vulnerabilities reverted, and analyst time saved.
Vulnerability Management / Reporting and Compliance / Ghost Agent Factory 2 tools -
GitLab Dependency Scanning Triage Recheck
Rechecks and reverts GitLab dependency vulnerabilities that were dismissed as not applicable or used in tests when a code change makes them reachable.
Vulnerability Management 1 tools -
GitLab Public Repository Posture Audit
Reports the public projects in a GitLab group that fail its security policy, with each failing check.
Reporting and Compliance 1 tools -
GitLab Repository AI-Readiness Audit
Scores each repository in a GitLab group on how well a coding agent can work in it, and reports the ones below the bar.
Reporting and Compliance 1 tools -
GitLab Repository Code Vulnerability Detection
Finds exploitable vulnerabilities in a GitLab repository's own code, and verifies each one against the source before reporting it.
Vulnerability Management / Application Security 1 tools -
GitLab Repository SCA Triage
Scans a GitLab repository's dependencies for known vulnerabilities and separates the ones an attacker can exploit from the ones they cannot.
Vulnerability Management / Application Security 1 tools -
GitLab Repository Secrets Triage
Scans a GitLab repository for hardcoded secrets and separates the real, exposed credentials from placeholders, test values, and safely loaded config.
Vulnerability Management / Application Security 1 tools -
Google Cloud Run SCA Vulnerability Triage
Triages the container vulnerabilities in a Cloud Run service's deployed image and separates the ones worth fixing from the ones that are not reachable.
Vulnerability Management 4 tools -
Google Cloud Run SRE
Reviews a Cloud Run service's metrics, logs, and errors each day, traces each error to its source code, and proposes the fix.
Infrastructure Operations 4 tools -
Google SecOps Detection Posture Report
Delivers a weekly report on Google SecOps ingestion gaps by log type and feed, rules that are erroring, disabled, or blind, and anything in the instance that needs an admin, from parser failures to silent forwarders.
Reporting and Compliance / Security Operations 1 tools -
Google SecOps Detection Tuning
Finds the Google SecOps rules that produce the most noise, reads each one against the detections it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Google Security Command Center Finding Triage
Writes an evidence-based judgment for each active Critical and High Security Command Center finding, verifies it against the live resource, and mutes the ones the checks prove are false positives.
Vulnerability Management 2 tools -
Google Security Command Center Posture Report
Delivers a weekly report on Security Command Center coverage across your organization, what changed in the findings, and anything in the configuration that needs an admin, from disabled detectors to mute rules nobody reviewed.
Reporting and Compliance / Vulnerability Management 2 tools -
Google Workspace App Access Review
Reviews third-party OAuth apps, their per-user tokens, and domain-wide delegations in a Google Workspace domain, and proposes which to block, restrict, remove, or keep.
Identity and Access 1 tools -
Google Workspace Offboarding Verification
Checks each departed user for Drive files shared outside the domain, live OAuth tokens, and access outside Workspace, and reports each open path.
Identity and Access 9 tools -
Google Workspace Posture Report
Delivers a weekly Google Workspace report on admin second factors, domain-wide delegation, and mail and recovery settings, with what changed since last week.
Identity and Access / Reporting and Compliance 1 tools -
HackerOne Program Report
Delivers a weekly report on a HackerOne program's response times, open report queue, duplicate rate, bounty spend, and the scope that is drawing no reports.
Reporting and Compliance / Application Security 1 tools -
HackerOne Report Triage
Reads each new HackerOne report against the affected code and leaves its verdict and likely duplicates as an internal comment.
Vulnerability Management / Application Security 4 tools -
Indicator Enrichment
Looks up IPs, domains, URLs, and file hashes across public threat intelligence sources and writes one verdict per indicator, with each source's claim kept separate.
Threat Intelligence / Security Operations 8 tools -
Jira Agent Ticket Report
Reports on the open Jira tickets that Ghost Agent Factory agents filed, by type, age, and status, and on what changed in them during the last sprint.
Reporting and Compliance / Task Management 1 tools -
Jira Ticket Creation
Turns the structured findings another agent produces into Jira tickets, one per finding, and keeps them in sync on every run without duplicates.
Task Management 1 tools -
Linear Agent Issue Report
Reports on the open Linear issues that Ghost Agent Factory agents filed, by type, age, and status, and on what changed in them during the last cycle.
Reporting and Compliance / Task Management 1 tools -
Linear Ticket Creation
Turns the structured findings another agent produces into Linear issues, one per finding, and keeps them in sync on every run without duplicates.
Task Management 1 tools -
Mallory CVE Enrichment
Builds one record per CVE from Mallory's exploits, exploitation evidence, threat actors, malware, detection signatures, affected configurations, and mention trend, so a triage agent knows whether anyone is using it.
Threat Intelligence / Vulnerability Management 1 tools -
Mallory Exposure Match
Reads the CVE matches Mallory holds for synced inventory, runs the product and package lookups for inventory it cannot sync, and reports each match with its match status, coverage caveats, and exploitation evidence.
Threat Intelligence / Vulnerability Management 2 tools -
Mallory Indicator Enrichment
Looks up IPs, domains, URLs, hashes, and emails in Mallory, writes one verdict per indicator from the source opinions and linked malware and actors, and records a sighting for each one your environment saw.
Threat Intelligence / Security Operations 1 tools -
Mallory IOC Sync
Pulls the Mallory observables that meet a malicious-opinion policy I set and writes them, with expiry, into the lookup, watchlist, or reference list your detection rules already read.
Threat Intelligence / Security Operations 6 tools -
Mallory Threat Briefing
Delivers a briefing from Mallory on the stories, vulnerabilities, actors, and malware that matter to your stack and sector, with what changed since the last briefing and the action for each item.
Threat Intelligence / Reporting and Compliance 1 tools -
Microsoft Defender for Cloud Posture Report
Delivers a weekly report on Defender for Cloud coverage across your subscriptions, how the secure score moved, and anything in the configuration that needs an admin, from missing plans to exemptions nobody reviewed.
Reporting and Compliance / Vulnerability Management 2 tools -
Microsoft Defender for Cloud Recommendation Triage
Writes an evidence-based judgment for each unhealthy High severity Defender for Cloud recommendation, verifies it against the live resource, and exempts the ones the checks prove are already mitigated.
Vulnerability Management 2 tools -
Microsoft Entra ID App Consent Review
Reviews delegated grants, application permissions, and directory roles held by apps in an Entra ID tenant, and proposes which to revoke, restrict, or keep.
Identity and Access 1 tools -
Microsoft Entra ID Offboarding Verification
Checks each departed user for an account re-enabled by sync, owned apps with valid secrets, and access outside Entra ID, and reports each open path.
Identity and Access 9 tools -
Microsoft Entra ID Posture Report
Delivers a weekly Entra ID report on permanent privileged roles, Conditional Access changes, and expiring app credentials, with what changed since last week.
Identity and Access / Reporting and Compliance 1 tools -
Microsoft Sentinel Detection Posture Report
Delivers a weekly report on Microsoft Sentinel table ingestion gaps, analytics rules that are failing, disabled, or blind, and anything in the workspace that needs an admin, from broken data connectors to the daily cap.
Reporting and Compliance / Security Operations 1 tools -
Microsoft Sentinel Detection Tuning
Finds the Microsoft Sentinel analytics rules that produce the most noise, reads each one against the alerts it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Okta API Access Review
Reviews the API service integrations, OAuth service apps, and API tokens that reach Okta's admin API, and proposes which to revoke, restrict, or keep.
Identity and Access 1 tools -
Okta Offboarding Verification
Checks each departed user for a suspended Okta account, app accounts that SCIM never removed, and access outside Okta, and reports each open path.
Identity and Access 9 tools -
Okta Posture Report
Delivers a weekly Okta report on admin factors, API tokens and the roles they carry, and policy changes, with what changed since last week.
Identity and Access / Reporting and Compliance 1 tools -
Orca Alert Triage
Writes an evidence-based judgment for each open Critical and High Orca alert and dismisses the ones cloud checks prove are false positives.
Vulnerability Management 7 tools -
Orca Posture Report
Delivers a weekly report on Orca coverage across your cloud accounts, what changed in the alerts, and anything in the tenant that needs an admin, from failing account connections to stale scans.
Reporting and Compliance / Vulnerability Management 4 tools -
Prisma Cloud Alert Triage
Writes an evidence-based judgment for each open Critical and High Prisma Cloud alert and dismisses the ones cloud checks prove are false positives.
Vulnerability Management 7 tools -
Prisma Cloud Posture Report
Delivers a weekly report on Prisma Cloud coverage across your cloud accounts, what changed in the alerts and policies, and anything in the tenant that needs an admin, from ingestion errors to disconnected Defenders.
Reporting and Compliance / Vulnerability Management 4 tools -
Qualys Posture Report
Delivers a weekly report on Qualys coverage across your hosts, what changed in the detection backlog, and anything in the subscription that needs an admin, from stale agents to license use.
Reporting and Compliance / Vulnerability Management 4 tools -
Qualys Vulnerability Triage
Writes an evidence-based judgment for each open Severity 4 and 5 Qualys detection and ignores the ones the evidence shows are false positives.
Vulnerability Management 4 tools -
Rapid7 InsightVM Posture Report
Delivers a weekly report on InsightVM coverage across your assets, what changed in the vulnerability backlog, and anything in the console that needs an admin, from offline engines to license use.
Reporting and Compliance / Vulnerability Management 4 tools -
Rapid7 InsightVM Vulnerability Triage
Writes an evidence-based judgment for each open Critical and Severe InsightVM vulnerability and submits a false positive exception for the ones the evidence disproves.
Vulnerability Management 4 tools -
Semgrep Finding Triage
Checks open Semgrep findings against the affected repository and ignores the ones the code shows are false positives.
Vulnerability Management / Application Security 4 tools -
Semgrep Posture Report
Delivers a weekly report on Semgrep coverage, what changed, and anything in the deployment that needs attention, from failing scans to contributor licenses.
Reporting and Compliance / Vulnerability Management 4 tools -
SentinelOne Alert Triage
Triages new SentinelOne threats, contains the confirmed ones, closes the known-good ones, and escalates the rest to an analyst.
Security Operations 1 tools -
SentinelOne Posture Report
Delivers a weekly report on SentinelOne agent coverage, what changed, and anything in the console that needs attention, from detect-only policies to license seats.
Reporting and Compliance / Endpoint Security 1 tools -
Snyk Issue Triage
Checks open Snyk issues against the affected repository and ignores the ones the code shows are not a real risk.
Vulnerability Management / Application Security 4 tools -
Snyk Posture Report
Delivers a weekly report on Snyk coverage, what changed, and anything in the account that needs attention, from broken integrations to license limits.
Reporting and Compliance / Vulnerability Management 4 tools -
Splunk Detection Posture Report
Delivers a weekly report on Splunk ingestion gaps, correlation searches that are failing, skipped, or blind, and anything in the deployment that needs an admin, from silent forwarders to license use.
Reporting and Compliance / Security Operations 1 tools -
Splunk Detection Tuning
Finds the Splunk correlation searches that produce the most noise, reads each one against the notable events it raised, and proposes a specific tuning change with the evidence and what it would have missed.
Security Operations 1 tools -
Tenable Posture Report
Delivers a weekly report on Tenable coverage across your assets, what changed in the vulnerability backlog, and anything in the container that needs an admin, from failing scans to license use.
Reporting and Compliance / Vulnerability Management 4 tools -
Tenable Vulnerability Triage
Writes an evidence-based judgment for each open Critical and High Tenable vulnerability and tags the assets that need a fix now.
Vulnerability Management 4 tools -
Wiz Posture Report
Delivers a weekly report on Wiz coverage across your cloud accounts, what changed, and anything in the tenant that needs attention, from failing connectors to license use.
Reporting and Compliance / Vulnerability Management 4 tools
No templates match your filters.