In this article
Codebase Profiler
| Field | Value |
|---|---|
| Kind | agent |
| Source | .github/agents/security/subagents/codebase-profiler.agent.md |
| Invocation | Delegated subagent, dispatched by a parent agent (not selected directly) |
| Interactive | No |
What it does
Scans the repository to build a technology profile and select applicable security skills
When to use it
Reviewer orchestrators dispatch Codebase Profiler to identify technologies, infrastructure patterns, and applicable assessment skills before detailed checks. It supplies context and selection signals, not vulnerability findings or a security verdict. Use the parent reviewer to initiate the assessment.
Example usage
The parent supplies a repository path and a focus on the API and deployment directories. The profiler returns a structured technology profile and applicable skill candidates backed by discovered files. For diff or plan work, the parent supplies the corresponding changed-file or plan context. The worker does not infer that detected technology is securely configured or expand the requested review scope.