RE

Performs a full-project security assessment to identify vulnerabilities and ensure compliance.

Install

mkdir -p .claude/skills/review-security && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13851" && unzip -o skill.zip -d .claude/skills/review-security && rm skill.zip

Installs to .claude/skills/review-security

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Full-project security sweep — OWASP dependency check, secrets scan, CVE audit, auth pattern review, governance compliance. Use for periodic security audits or standalone security assessments.
191 chars✓ has a “when” trigger
Advanced

Key capabilities

  • →Scan source code for secrets patterns
  • →Audit project dependencies for CVEs
  • →Review authentication and access control patterns
  • →Scan for OWASP Top 10 code-level vulnerabilities
  • →Generate a security audit report with findings and recommendations

How it works

The skill performs a complete security assessment by scanning for secrets, auditing dependencies, and reviewing authentication and OWASP Top 10 patterns using grep-based and tool-based checks.

Inputs & outputs

You give it
Project source code and configuration files
You get back
Security audit report with findings, severity, and recommendations

When to use review-security

  • →Run a periodic security sweep
  • →Audit authentication patterns
  • →Scan for hardcoded secrets

About review-security

Executes project-wide security audits. Scans for exposed secrets, outdated dependencies, and reviews authentication patterns against security best practices.

Full-project security sweep — OWASP dependency check, secrets scan, CVE audit, auth pattern review, governance compliance. Use for periodic security audits or standalone security assessments.

When not to use it

  • →When performing a PR-scoped security review
  • →When the project does not have source code to scan

Limitations

  • →The skill relies on available toolchain discovery for dependency audits.
  • →Some checks are grep-based and may have false positives.
  • →The skill does not perform dynamic analysis or penetration testing.

How it compares

This skill conducts a full project-wide security sweep, integrating multiple scanning techniques and governance checks, unlike a single-purpose vulnerability scanner.

Compared to similar skills

review-security side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
review-security (this skill)05moReviewAdvanced
security-scanning-security-dependencies15moNo flagsIntermediate
dependency-management-deps-audit15moNo flagsIntermediate
ship-safe03moReviewBeginner

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

security-scanning-security-dependencies

sickn33

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.

14

dependency-management-deps-audit

sickn33

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

11

ship-safe

kinncj

Run ship-safe security and quality audit on the current project. Executes npx ship-safe audit . and reports findings by severity. Use before shipping any feature or PR.

00

security-review

DrinkBoooz

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

00

sensitive-data-review

jonathan-geva

Use when reviewing code, tests, fixtures, docs, or commits for sensitive data exposure: names, phone numbers, emails, usernames, passwords, tokens, API keys, private IDs, birth dates, postal codes (PLZ/ZIP), hometown/Heimatort, or school-specific class/course identifiers.

00

contrib-pr-review

homeassistant-ai

Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.

14

Search skills

Search the agent skills registry