Agent skill

Performing Security Code Review

by aAAaqwq in aAAaqwq/AGI-Super-Team

This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

MITAuto-check passedSecurity

Install Performing Security Code Review

skills CLI
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-security-code-review .claude/skills/performing-security-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-security-code-review
GitHub stars
105
Used in
1 other repo
Token cost
~920 tokens
SKILL.md length
392 words
Files
8 (incl. scripts, references, assets)
Skills in repo
161
Repo updated
First seen
Licence
MIT

At a glance

This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

  • Works in 3 steps: Receiving Request: Claude identifies a… → Activating Security Agent: Claude… → Generating Security Report: The…
  • Assessing security
  • SKILL.md covers Overview, How It Works, When to Use This Skill and Examples, plus 7 more sections
  • Runs Python scripts from its folder

What it does

Performing Security Code Review is an agent skill from aAAaqwq/AGI-Super-Team. This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/example_code_secure.py` and `assets/example_code_vulnerable.py`).

It sits in Security, covering Web application vulnerabilities, Code review and Hooks and plugins. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.

When your agent uses it

  • Assessing security
  • With phrases like security scan

Example prompts

  • “security scan”
  • “vulnerability”
  • “/performing-security-code-review”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(cmd:*)

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Receiving Request: Claude identifies a user's request for a security review or audit of code.
  2. Activating Security Agent: Claude invokes the security-agent plugin to analyze the provided code.
  3. Generating Security Report: The security-agent produces a structured report detailing identified vulnerabilities, their severity, affected…

What it can do on your machine

Read from SKILL.md and the folder at commit 331ecd3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Security Code Review loads about 920 tokens when it runs, and up to ~1k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 392 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~920
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aAAaqwq/AGI-Super-Team at commit 331ecd3, republished under its MIT licence (© aAAaqwq). 392 words, ~920 tokens.

Download SKILL.mdSave it as .claude/skills/performing-security-code-review/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-security-code-review
description
This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(cmd:*)
version
1.0.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT

Security Agent

This skill provides automated assistance for security agent tasks.

Overview

This skill empowers Claude to act as a security expert, identifying and explaining potential vulnerabilities within code. It leverages the security-agent plugin to provide detailed security analysis, helping developers improve the security posture of their applications.

How It Works

  1. Receiving Request: Claude identifies a user's request for a security review or audit of code.
  2. Activating Security Agent: Claude invokes the security-agent plugin to analyze the provided code.
  3. Generating Security Report: The security-agent produces a structured report detailing identified vulnerabilities, their severity, affected code locations, and recommended remediation steps.

When to Use This Skill

This skill activates when you need to:

  • Review code for security vulnerabilities.
  • Perform a security audit of a codebase.
  • Identify potential security risks in a software application.

Examples

Example 1: Identifying SQL Injection Vulnerability

User request: "Please review this database query code for SQL injection vulnerabilities."

The skill will:

  1. Activate the security-agent plugin to analyze the database query code.
  2. Generate a report identifying potential SQL injection vulnerabilities, including the vulnerable code snippet, its severity, and suggested remediation, such as using parameterized queries.
Example 2: Checking for Insecure Dependencies

User request: "Can you check this project's dependencies for known security vulnerabilities?"

The skill will:

  1. Utilize the security-agent plugin to scan the project's dependencies against known vulnerability databases.
  2. Produce a report listing any vulnerable dependencies, their Common Vulnerabilities and Exposures (CVE) identifiers, and recommendations for updating to secure versions.
Show full SKILL.md (143 more words)Show less

Best Practices

  • Specificity: Provide the exact code or project you want reviewed.
  • Context: Clearly state the security concerns you have regarding the code.
  • Iteration: Use the findings to address vulnerabilities and request further reviews.

Integration

This skill integrates with Claude's code understanding capabilities and leverages the security-agent plugin to provide specialized security analysis. It can be used in conjunction with other code analysis tools to provide a comprehensive assessment of code quality and security.

Prerequisites

  • Appropriate file access permissions
  • Required dependencies installed

Instructions

  1. Invoke this skill when the trigger conditions are met
  2. Provide necessary context and parameters
  3. Review the generated output
  4. Apply modifications as needed

Output

The skill produces structured output relevant to the task.

Error Handling

  • Invalid input: Prompts for correction
  • Missing dependencies: Lists required components
  • Permission errors: Suggests remediation steps

Resources

  • Project documentation
  • Related skills and commands

© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-security-code-review of aAAaqwq/AGI-Super-Team.

  • SKILL.md
  • assets/README.md
  • assets/example_code_secure.py
  • assets/example_code_vulnerable.py
  • assets/report_template.md
  • references/README.md
  • scripts/README.md
  • scripts/code_analyzer.py

Open the folder on GitHubat commit 331ecd3

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aAAaqwq/AGI-Super-Team, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Performing Security Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Security Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Security Code Review this skillaAAaqwq/AGI-Super-Team1051 repos~920Automated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Security Reviewdeadlock-mod-manager/deadlock-mod-manager473—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Security Auditorpavel-molyanov/molyanov-ai-dev296—~566Automated safety check: PassMIT
Security Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~523Automated safety check: PassApache-2.0

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    473 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Auditor

    pavel-molyanov/molyanov-ai-dev

    Analyzes changed security boundaries against applicable OWASP risks and project contracts.

    296 GitHub stars~566 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

    3.6k GitHub stars~523 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

    239 GitHub stars~5.8k tokensUpdated yesterday
    SecurityAuto-check passed

More from aAAaqwq/AGI-Super-Team

All 161 skills in this repo
  • Content Creator

    aAAaqwq/AGI-Super-Team

    Create SEO-optimized marketing content with consistent brand voice.

    105 GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • Financial Calculator

    aAAaqwq/AGI-Super-Team

    Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.

    105 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Frontend Design Ultimate

    aAAaqwq/AGI-Super-Team

    Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.

    105 GitHub starsUsed in 2 repos~2.7k tokens
    Auto-check passed
  • Sysadmin Toolbox

    aAAaqwq/AGI-Super-Team

    Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks.

    105 GitHub starsUsed in 2 repos~775 tokens
    Auto-check passed
  • Zsxq Smart Publish

    aAAaqwq/AGI-Super-Team

    Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check passed
  • Content Extract

    aAAaqwq/AGI-Super-Team

    Robust URL-to-Markdown extraction for OpenClaw workflows. An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub starsUsed in 1 repo~650 tokens
    Auto-check passed

Categories

Questions about Performing Security Code Review

What does Performing Security Code Review do?

This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. Performing Security Code Review is an agent skill from aAAaqwq/AGI-Super-Team. This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

When should I use Performing Security Code Review?

Performing Security Code Review fits situations like: assessing security; with phrases like security scan.

How do I install Performing Security Code Review in Claude Code?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a claude-code`. Or copy the skill folder (skills/performing-security-code-review in aAAaqwq/AGI-Super-Team) into .claude/skills/performing-security-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Performing Security Code Review in Codex?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a codex`. Or copy the skill folder (skills/performing-security-code-review in aAAaqwq/AGI-Super-Team) into .agents/skills/performing-security-code-review in your project. Codex loads it when a task matches its description.

Can I use Performing Security Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-security-code-review, .gemini/skills/performing-security-code-review, .github/skills/performing-security-code-review and .opencode/skills/performing-security-code-review in your project.

What does Performing Security Code Review need to run?

Going by SKILL.md and its folder, Performing Security Code Review needs Python for the scripts in its folder. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*).

Does Performing Security Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Security Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Security Code Review use?

Performing Security Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Security Code Review use?

About 920 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 103 tokens, read only when the agent opens those files.

What are the alternatives to Performing Security Code Review?

Skills that share tags, products or a category with Performing Security Code Review: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Security Review (getsentry/skills, 1k stars), Security Review (deadlock-mod-manager/deadlock-mod-manager, 473 stars) and Security Auditor (pavel-molyanov/molyanov-ai-dev, 296 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Security Code Review?

aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 161 skills in this directory. The repository was last updated on September 27, 2026.

Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.