Agent skill

security-reviewer

Security review wrapper for vibe review flow. Detects OWASP-style risks, secret leaks, auth flaws, and unsafe input handling.

Stars 163
Forks 31

Install this agent skill to your Project

npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/security-reviewer-foryourhealth111-pix-vibe-skills

SKILL.md

security-reviewer (Codex Compatibility)

Use this skill after code changes that touch input handling, auth, APIs, data access, uploads, payments, or external integrations.

Security Review Workflow

  1. Initial Scan
  • Locate auth, API endpoints, DB queries, file handling, and external calls.
  • Check for hardcoded secrets and unsafe config defaults.
  1. OWASP-Oriented Checks
  • Injection: parameterized queries, sanitized inputs.
  • AuthZ/AuthN: enforce authorization per route, secure session/token handling.
  • Data exposure: secrets/PII protection and safe logging.
  • XSS/SSRF: output encoding, URL allowlist, no blind fetch of user URLs.
  • Dependency risk: audit vulnerable dependencies.
  1. High-Risk Pattern Audit
  • Hardcoded secrets/tokens
  • Command execution with user input
  • SQL string concatenation
  • Missing auth check
  • Missing rate limiting on sensitive endpoints
  • Unsafe crypto/password handling
  1. Remediation Output
  • Severity (CRITICAL/HIGH/MEDIUM/LOW)
  • Evidence (file + line + risk)
  • Concrete fix proposal
  • Verification steps after fix

Vibe Integration

  • Security gate skill usable at any grade.
  • Pair with security-best-practices for language/framework-specific guidance.
  • Pair with code-review for combined correctness + security review.

Expand your agent's capabilities with these related and highly-rated skills.

Didn't find tool you were looking for?

Be as detailed as possible for better results