# Secure Change Use this profile for authorized security-sensitive changes, defensive review, and vulnerability remediation—not routine coding or offensive activity outside the operator's scope. ```text Claude Opus 5 security lead (active root and only writer) ├── GLM-5.3 vulnerability hunter (MCP, read-only) └── DeepSeek V4 Pro finding verifier (MCP, read-only, launched for concrete findings) ``` Threat modeling and audit can run in parallel while the root maps the change. Findings remain hypotheses until evidence confirms them. The root exclusively remediates and requests targeted revalidation. Worker read-only permissions, exact roles, contracts, graph, and goal/turn lifecycle are mechanical; coverage judgment and launch policy remain root responsibilities. Cost and latency are high. Provider failure creates a named coverage gap, and no result may claim complete security assurance. Hunter and verifier are persistent supervised Unix app-server workers. The root controls both, and reciprocal action grants let them steer, pause, continue, detach, or return one another to an unresolved exploitability claim without granting remediation authority. Slow analysis receives generous token budgets or clock-free turns; warning-only stalls never erase work, and suspension preserves history, traces, and partial findings.