performing-security-code-review
Scans codebases for OWASP Top 10 vulnerabilities and hardcoded secrets.
Install
mkdir -p .claude/skills/performing-security-code-review && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/5401" && unzip -o skill.zip -d .claude/skills/performing-security-code-review && rm skill.zipInstalls to .claude/skills/performing-security-code-review
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Execute this skill enables AI assistant to conduct a security-focusedKey capabilities
- →Scan for hardcoded secrets
- →Analyze code for injection vulnerabilities
- →Review authentication and authorization logic
- →Audit dependencies for known vulnerabilities
- →Check for insecure communication patterns
- →Compile findings into a structured report
How it works
The skill scans source files for common vulnerability patterns, audits dependencies, and compiles findings into a severity-rated report with remediation steps.
Inputs & outputs
When to use performing-security-code-review
- →Scanning for hardcoded secrets
- →Reviewing code for XSS vulnerabilities
- →Auditing project dependencies
- →Conducting pre-deployment security checks
About this skill
Performing Security Code Review
Overview
Conducts security-focused code reviews by scanning source files for common vulnerability patterns including SQL injection, XSS, authentication flaws, insecure dependencies, and secret exposure. Produces structured severity-rated reports with specific remediation guidance.
Prerequisites
- Read access to all source files in the target project
grepavailable on PATH for pattern matching- Access to
package.jsonor equivalent dependency manifest for dependency auditing - Familiarity with OWASP Top 10 vulnerability categories
Instructions
- Identify the scope of the review: specific files, directories, or the entire codebase. Confirm the primary language(s) and framework(s) in use.
- Scan for hardcoded secrets and credentials:
- Search for patterns matching API keys, tokens, passwords, AWS access keys (
AKIA...), and private key headers (BEGIN PRIVATE KEY). - Flag any
.envfiles or configuration files containing plaintext secrets.
- Search for patterns matching API keys, tokens, passwords, AWS access keys (
- Analyze code for injection vulnerabilities:
- Identify raw SQL string concatenation (SQL injection risk).
- Locate unsanitized user input rendered in HTML (XSS risk).
- Check for
eval(),exec(), orFunction()calls with dynamic input (code injection risk).
- Review authentication and authorization logic:
- Verify password hashing uses strong algorithms (bcrypt, argon2) rather than MD5/SHA1.
- Check for missing authentication on sensitive endpoints.
- Identify overly permissive CORS configurations.
- Audit dependencies for known vulnerabilities:
- Run
npm auditor equivalent package manager audit command. - Cross-reference dependency versions against known CVE databases.
- Run
- Check for insecure communication patterns:
- Flag HTTP URLs where HTTPS is expected.
- Identify disabled TLS certificate verification.
- Compile findings into a structured report sorted by severity (Critical, High, Medium, Low), including the vulnerable code location, explanation, and remediation steps.
Output
A structured security review report containing:
- Summary with total findings count by severity level
- Per-finding entries with: file path, line number, vulnerability type, severity, code snippet, explanation, and recommended fix
- Dependency audit results with CVE identifiers where applicable
- Overall risk assessment (Critical / High / Medium / Low / Clean)
Error Handling
| Error | Cause | Solution |
|---|---|---|
| No source files found | Incorrect scope path or empty directory | Verify the target directory path and confirm it contains source files |
| Binary files in scan | Non-text files matched by search patterns | Exclude binary extensions and node_modules/ from scans |
| Dependency manifest missing | No package.json, requirements.txt, or equivalent | Skip dependency audit; note in report that dependency analysis was not possible |
| Permission denied on files | Restricted file access | Request read permissions or narrow the review scope to accessible files |
| False positive on secret pattern | Benign string matching secret regex | Verify context before reporting; mark as potential false positive if the match appears in test fixtures or documentation |
Examples
SQL injection review:
Trigger: "Review this database query code for SQL injection vulnerabilities."
Process: Scan all files containing SQL query construction. Identify string concatenation with user input ("SELECT * FROM users WHERE id = " + userId). Report as High severity with remediation: use parameterized queries or prepared statements.
Dependency vulnerability scan:
Trigger: "Check this project's dependencies for known security vulnerabilities."
Process: Run npm audit on the project. Parse output for vulnerabilities. Report each finding with CVE identifier, affected package, installed version, and patched version. Recommend npm audit fix or manual version pinning.
Full codebase security audit: Trigger: "Run a security scan on this codebase." Process: Execute all seven scan categories (secrets, injection, auth, dependencies, communication, dangerous commands, obfuscation). Produce a comprehensive report with findings grouped by category and sorted by severity.
Resources
- OWASP Top 10 -- industry-standard vulnerability classification
- Node.js Security Checklist -- Node-specific security guidance
- CWE/SANS Top 25 -- most dangerous software weaknesses
${CLAUDE_SKILL_DIR}/references/README.md-- bundled reference materials
Prerequisites
Limitations
- →No source files found if path is incorrect
- →Binary files in scan can cause false positives
- →Dependency manifest missing skips audit
How it compares
This skill conducts a security-focused code review by scanning for specific vulnerability patterns and auditing dependencies, providing a structured report with remediation guidance, unlike a general code review.
Compared to similar skills
performing-security-code-review side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| performing-security-code-review (this skill) | 1 | 25d | Review | Intermediate |
| 1password | 27 | 2mo | Review | Intermediate |
| software-security | 21 | 6mo | No flags | Intermediate |
| security-compliance | 19 | 7mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
software-security
project-codeguard
A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.
security-compliance
davila7
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.
fix-dependabot-alerts
microsoft
Fix Dependabot security alerts by updating vulnerable npm dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", or wants to update packages with security issues.
information-security-manager-iso27001
davila7
Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS implementation, cybersecurity risk assessment, security controls management, and compliance oversight. Use for ISMS design, security risk assessments, control implementation, and ISO 27001 certification activities.
backend-security-coder
sickn33
Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.