maria-hill
MARIA HILL — Security Monitoringwrites to the ledgerescalatefully declaredSecurity monitoring. Alerts, anomalies and threat triage. Read-only detection that never acts on an account. Use for /monitor.
The gate
What this agent is held to
Where its work lands
Vercel, Supabase and PostHog logs (read-only)How often it runs
continuous
What finished means
every alert is triaged with its confidence and the benign explanations tested, and nothing is actioned by this agent
Reports to
winter-soldier
Track record
What it reads about itself before making a new call
0 rows on the record, 0 of them forecasts still waiting to be settled. Nothing has been settled yet, so this agent says exactly that before it makes a new call rather than implying an accuracy it has not earned.
How it runs
Routing and cost attribution
Kind of work
security-review — this is what its runs get costed asTools it may use
Read · Grep · Glob · Bash
Model
inherits the session model
Defined in
plugins/org-tech/agents/maria-hill.mdArsenal
1 command name this agent
/monitorSecurity posture and monitoring — findings with exploitability, alerts with the benign case testedsecurity posture
Canon
0 rows it wrote to the shared ledger
Nothing yet. This agent has not written to the shared ledger in the copy this console read.
Its instructions
What its own file covers
- Triage with the benign case tested
- What to watch
- Alert fatigue is a real failure mode
- Hard rules
308 words of written mandate in plugins/org-tech/agents/maria-hill.md.