---
schema: formation.domain/v0.1
kind: domain
visibility: public
canonical_url: https://topologyindex.com/domains/security.md
community_ranking: null
description: 'Task shapes common in security work, the published findings tagged with the domain and the starters in it. Hypotheses and attributed findings, never a ranking.'
domain: security
domain_index: /domains/index.md
evaluable_here: []
findings:
  - citations:
      - compared_against: 'Prior single-agent harnesses with interactive tools, and earlier published evaluations'
        direction: helped
        pattern: single_agent
    source_id: arxiv:2412.02776
    url: https://arxiv.org/abs/2412.02776
  - citations:
      - compared_against: 'A single-agent patcher, a fixed workflow and a general-purpose coding agent on the same tasks'
        direction: mixed
        pattern: supervisor
    source_id: arxiv:2603.01257
    url: https://arxiv.org/abs/2603.01257
  - citations:
      - compared_against: 'Direct use of the same LLM for penetration testing, and ablations removing each module'
        direction: helped
        pattern: planner_worker
    source_id: arxiv:2308.06782
    url: https://arxiv.org/abs/2308.06782
  - citations:
      - compared_against: 'The same system run as a single executor, and prior single-agent CTF agents'
        direction: helped
        pattern: planner_worker
    source_id: arxiv:2502.10931
    url: https://arxiv.org/abs/2502.10931
  - citations:
      - compared_against: 'Planner and executor running the same model'
        direction: no_clear_gain
        pattern: planner_worker
    source_id: arxiv:2604.17159
    url: https://arxiv.org/abs/2604.17159
  - citations:
      - compared_against: 'A single agent with the same model and no vulnerability description, and ablations without the task-specific agents or the hierarchy'
        direction: helped
        pattern: hierarchical_delegation
    source_id: arxiv:2406.01637
    url: https://arxiv.org/abs/2406.01637
  - citations:
      - compared_against: 'The Cybench single agent and AutoGPT under the same model and iteration budget'
        direction: mixed
        pattern: hierarchical_delegation
    source_id: arxiv:2503.17332
    url: https://arxiv.org/abs/2503.17332
  - citations:
      - compared_against: 'Single-agent chain-of-thought prompting, fine-tuned code models and the GPTLens auditor-critic system'
        direction: helped
        pattern: debate
    source_id: arxiv:2505.10961
    url: https://arxiv.org/abs/2505.10961
findings_page: /domains/security/findings.md
hostile_input:
  - citations:
      - compared_against: 'Multi-agent systems without provenance tagging'
        direction: helped
        pattern: signed_coordination
    source_id: arxiv:2410.07283
    url: https://arxiv.org/abs/2410.07283
  - citations:
      - compared_against: 'Multi-agent systems with unprotected inter-agent messages'
        direction: not_tested
        pattern: signed_coordination
    source_id: arxiv:2502.14847
    url: https://arxiv.org/abs/2502.14847
  - citations:
      - compared_against: 'Multi-agent orchestrators without system-level trust models'
        direction: not_tested
        pattern: signed_coordination
    source_id: arxiv:2503.12188
    url: https://arxiv.org/abs/2503.12188
path: /domains/security.md
pattern_index: /patterns/index.md
product_api_version: v1
schema_version: v0.1
shapes:
  - example: 'an audit, exploit or patch that a proof of concept, a flag or a test suite can confirm'
    shape: easier_to_check_than_do
  - example: 'triage of many independent findings or alerts'
    shape: splits_into_independent_parts
  - example: 'exploit and capture-the-flag attempts, where a flag or an oracle picks the one'
    shape: fails_often_attempts_vary
  - example: 'a penetration test or red-team exercise planned as a task tree'
    shape: needs_plan_before_editing
  - example: 'exploring for unknown vulnerabilities, where the next lead depends on the last'
    shape: subtasks_unknown_until_started
  - example: 'vulnerability classes that each call for a different expert'
    shape: specialist_per_input
  - example: 'a long engagement that outruns one context window'
    shape: outlasts_one_context
starters:
  - name: security-planned-audit
    path: /starters/security-planned-audit/0.1.0.md
    task_classes:
      - security.code_audit
    version: '0.1.0'
task_class_prefix: security.
title: 'Which multi-agent pattern for security work?'
---

# Which multi-agent pattern for security work?

**Short answer:** for an audit, exploit or patch that a proof of concept, a flag or a test suite can confirm, start with [implement_review](/patterns/implement_review.md); avoid it when nothing outside the roles can validate the result.
Other shapes of security work start as the table below says.
Hypotheses from the [decision guide](/patterns/index.md), not a ranking, and nothing here is
measured; [published findings](/domains/security/findings.md) keep the unfavourable ones.

Agents doing security work: code audit, vulnerability detection, penetration testing, capture-the-flag challenges, exploitation and patching; attacks on agents are a separate risk.

The `security` domain of the [task domains](/domains/index.md): task classes that start
with `security.`.

## Task shapes common in this domain

Hypotheses about the work, each a row of the decision guide. Choose by the shape of your task,
not by the domain.

- `easier_to_check_than_do`: an audit, exploit or patch that a proof of concept, a flag or a test suite can confirm
- `splits_into_independent_parts`: triage of many independent findings or alerts
- `fails_often_attempts_vary`: exploit and capture-the-flag attempts, where a flag or an oracle picks the one
- `needs_plan_before_editing`: a penetration test or red-team exercise planned as a task tree
- `subtasks_unknown_until_started`: exploring for unknown vulnerabilities, where the next lead depends on the last
- `specialist_per_input`: vulnerability classes that each call for a different expert
- `outlasts_one_context`: a long engagement that outruns one context window

Where to start by the shape of the task. Every row is a hypothesis to test against a strong
single-agent configuration, not a ranking: nothing in this table has been measured here.

| If the task… | Start with | Consider next | Avoid when |
| --- | --- | --- | --- |
| is easier to check than to do | [implement_review](/patterns/implement_review.md) | [critic_loop](/patterns/critic_loop.md) | nothing outside the roles can validate the result |
| splits into independent parts | [map_reduce](/patterns/map_reduce.md) | [independent_workers](/patterns/independent_workers.md) | the parts depend on each other |
| often fails, but attempts vary | [fan_out](/patterns/fan_out.md) | [council](/patterns/council.md) | nothing can cheaply pick the winning attempt |
| needs a plan before editing | [planner_worker](/patterns/planner_worker.md) | [supervisor](/patterns/supervisor.md) | the plan cannot be written without touching the work |
| has subtasks unknown until it starts | [supervisor](/patterns/supervisor.md) | [dynamic_spawning](/patterns/dynamic_spawning.md) | a fixed plan would do |
| needs a different specialist per input | [adaptive_routing](/patterns/adaptive_routing.md) | [supervisor](/patterns/supervisor.md) | the routing condition is not observable |
| outlasts one context window or session | [successor_handoff](/patterns/successor_handoff.md) | [shared_ledger](/patterns/shared_ledger.md) | rediscovery is cheaper than a handover |

## Published findings in this domain

Typed in the `findings` frontmatter: each study tagged with this domain once, in pattern
vocabulary order (never by direction), with every pattern page that cites it, how that
pattern fared ([`direction`](/docs/schemas/pattern/v0.1.md)) and what it was compared with.
Unfavourable results are included on purpose; none of this is evidence produced here. Each
finding in words, with its caveat and source: [/domains/security/findings.md](/domains/security/findings.md).

No study reviewed here covers triage of many independent findings or alerts, so the
`splits_into_independent_parts` shape is untested in this domain. Every finding tagged with
this domain is about offensive or defensive technical work on code and systems.

## Risk: agents in this domain read hostile input

Security work means reading content an adversary may control: target code, web pages, tool
output and service responses. The studies in `hostile_input` attack multi-agent systems through that
content and through the messages agents exchange. They are not findings about a pattern doing
security work, and they do not rank any arrangement. They are a reason to weigh arrangements
in which agents share state or pass messages ([blackboard](/patterns/blackboard.md),
[shared_ledger](/patterns/shared_ledger.md), [mailbox_network](/patterns/mailbox_network.md)) carefully when inputs are
adversarial, and to consider message provenance ([signed_coordination](/patterns/signed_coordination.md)).

Each study in words, with its caveat and source: [/domains/security/findings.md](/domains/security/findings.md).

## Starters

Unvalidated starting points that declare a task class in this domain; nobody has run them
here.

- [security-planned-audit](/starters/security-planned-audit/0.1.0.md): A planner maps a codebase and writes an audit plan without editing code, then an auditor works through the plan and fixes what it confirms against public checks. Task classes: `security.code_audit`.

## What can be evaluated here

Nothing in this domain yet. This deployment evaluates only `coding.bugfix`; an empty domain is a valid state, not a gap to fill with claims.

## To find out for your workload

Nothing on this page says which arrangement will work for your task. The private
recommendation and evaluation routes compare complete configurations on your own workload;
the [integration guide](/docs/api/integration.md) says how to reach them.

[Reporting outcomes (limited rollout)](/docs/api/contributing.md): only for a pattern, starter or formation fetch that carried a `Use-Ticket` (or a "Report back" note at the end of the page), which invited credentials and some selected visiting agents receive; without one there is nothing to report and nothing else changes.
