review-security
Performs a full-project security assessment to identify vulnerabilities and ensure compliance.
Install
mkdir -p .claude/skills/review-security && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13851" && unzip -o skill.zip -d .claude/skills/review-security && rm skill.zipInstalls to .claude/skills/review-security
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Full-project security sweep — OWASP dependency check, secrets scan, CVE audit, auth pattern review, governance compliance. Use for periodic security audits or standalone security assessments.Key capabilities
- →Scan source code for secrets patterns
- →Audit project dependencies for CVEs
- →Review authentication and access control patterns
- →Scan for OWASP Top 10 code-level vulnerabilities
- →Generate a security audit report with findings and recommendations
How it works
The skill performs a complete security assessment by scanning for secrets, auditing dependencies, and reviewing authentication and OWASP Top 10 patterns using grep-based and tool-based checks.
Inputs & outputs
When to use review-security
- →Run a periodic security sweep
- →Audit authentication patterns
- →Scan for hardcoded secrets
About review-security
Executes project-wide security audits. Scans for exposed secrets, outdated dependencies, and reviews authentication patterns against security best practices.
Full-project security sweep — OWASP dependency check, secrets scan, CVE audit, auth pattern review, governance compliance. Use for periodic security audits or standalone security assessments.
When not to use it
- →When performing a PR-scoped security review
- →When the project does not have source code to scan
Limitations
- →The skill relies on available toolchain discovery for dependency audits.
- →Some checks are grep-based and may have false positives.
- →The skill does not perform dynamic analysis or penetration testing.
How it compares
This skill conducts a full project-wide security sweep, integrating multiple scanning techniques and governance checks, unlike a single-purpose vulnerability scanner.
Compared to similar skills
review-security side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| review-security (this skill) | 0 | 5mo | Review | Advanced |
| security-scanning-security-dependencies | 1 | 5mo | No flags | Intermediate |
| dependency-management-deps-audit | 1 | 5mo | No flags | Intermediate |
| ship-safe | 0 | 3mo | Review | Beginner |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by ResearchMonkey
View all by ResearchMonkey →You might also like
security-scanning-security-dependencies
sickn33
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.
dependency-management-deps-audit
sickn33
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
ship-safe
kinncj
Run ship-safe security and quality audit on the current project. Executes npx ship-safe audit . and reports findings by severity. Use before shipping any feature or PR.
security-review
DrinkBoooz
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
sensitive-data-review
jonathan-geva
Use when reviewing code, tests, fixtures, docs, or commits for sensitive data exposure: names, phone numbers, emails, usernames, passwords, tokens, API keys, private IDs, birth dates, postal codes (PLZ/ZIP), hometown/Heimatort, or school-specific class/course identifiers.
contrib-pr-review
homeassistant-ai
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.