Agent skill

Security Review

by affaan-m in affaan-m/ECC

Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles.

MITAuto-check: notesSecurity

Install Security Review

skills CLI
$ npx skills add affaan-m/ECC --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/es/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
276k
Token cost
~3.4k tokens
SKILL.md length
671 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles.

  • Works in 10 steps: Gestión de Secretos → Validación de Entrada → Prevención de Inyección SQL → …
  • Tasks that involve Security review
  • SKILL.md covers Cuándo Activar, Lista de Verificación de…, Pruebas de Seguridad and Lista de Verificación Previa…, plus 1 more section
  • Calls npm and git; needs OPENAI_API_KEY

What it does

Security Review is an agent skill from affaan-m/ECC. Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. Proporciona lista de verificación y patrones de seguridad completos.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review and Web application vulnerabilities. It works with SQL and Supabase. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/security-review”

Requirements

  • Node.js
  • A credential in OPENAI_API_KEY

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Gestión de Secretos
  2. Validación de Entrada
  3. Prevención de Inyección SQL
  4. Autenticación y Autorización
  5. Prevención de XSS
  6. Protección CSRF
  7. Limitación de Velocidad
  8. Exposición de Datos Sensibles
  9. Seguridad en Blockchain (Solana)
  10. Seguridad de Dependencias

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 3.4k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 671 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:45
    - [ ] `.env.local` en .gitignore

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 671 words, ~3,365 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. Proporciona lista de verificación y patrones de seguridad completos.
origin
ECC

Skill de Revisión de Seguridad

Este skill garantiza que todo el código siga las buenas prácticas de seguridad e identifica vulnerabilidades potenciales.

Cuándo Activar

  • Implementar autenticación o autorización
  • Manejar entrada de usuario o subida de archivos
  • Crear nuevos endpoints de API
  • Trabajar con secretos o credenciales
  • Implementar funcionalidades de pago
  • Almacenar o transmitir datos sensibles
  • Integrar APIs de terceros

Lista de Verificación de Seguridad

1. Gestión de Secretos
FALLA: NUNCA Hacer Esto
typescript
const apiKey = "sk-proj-xxxxx"  // Secreto hardcodeado
const dbPassword = "password123" // En el código fuente
PASA: SIEMPRE Hacer Esto
typescript
const apiKey = process.env.OPENAI_API_KEY
const dbUrl = process.env.DATABASE_URL

// Verificar que los secretos existen
if (!apiKey) {
  throw new Error('OPENAI_API_KEY not configured')
}
Pasos de Verificación
  • Sin claves de API, tokens ni contraseñas hardcodeadas
  • Todos los secretos en variables de entorno
  • .env.local en .gitignore
  • Sin secretos en el historial de git
  • Secretos de producción en la plataforma de hosting (Vercel, Railway)
2. Validación de Entrada
Siempre Validar la Entrada del Usuario
typescript
import { z } from 'zod'

// Definir esquema de validación
const CreateUserSchema = z.object({
  email: z.string().email(),
  name: z.string().min(1).max(100),
  age: z.number().int().min(0).max(150)
})

// Validar antes de procesar
export async function createUser(input: unknown) {
  try {
    const validated = CreateUserSchema.parse(input)
    return await db.users.create(validated)
  } catch (error) {
    if (error instanceof z.ZodError) {
      return { success: false, errors: error.errors }
    }
    throw error
  }
}
Validación de Subida de Archivos
typescript
function validateFileUpload(file: File) {
  // Verificar tamaño (máximo 5MB)
  const maxSize = 5 * 1024 * 1024
  if (file.size > maxSize) {
    throw new Error('File too large (max 5MB)')
  }

  // Verificar tipo
  const allowedTypes = ['image/jpeg', 'image/png', 'image/gif']
  if (!allowedTypes.includes(file.type)) {
    throw new Error('Invalid file type')
  }

  // Verificar extensión
  const allowedExtensions = ['.jpg', '.jpeg', '.png', '.gif']
  const extension = file.name.toLowerCase().match(/\.[^.]+$/)?.[0]
  if (!extension || !allowedExtensions.includes(extension)) {
    throw new Error('Invalid file extension')
  }

  return true
}
Pasos de Verificación
  • Todas las entradas del usuario validadas con esquemas
  • Subidas de archivos restringidas (tamaño, tipo, extensión)
  • Sin uso directo de entrada del usuario en consultas
  • Validación por lista blanca (no por lista negra)
  • Los mensajes de error no revelan información sensible
3. Prevención de Inyección SQL
FALLA: NUNCA Concatenar SQL
typescript
// PELIGROSO - Vulnerabilidad de inyección SQL
const query = `SELECT * FROM users WHERE email = '${userEmail}'`
await db.query(query)
PASA: SIEMPRE Usar Consultas Parametrizadas
typescript
// Seguro - consulta parametrizada
const { data } = await supabase
  .from('users')
  .select('*')
  .eq('email', userEmail)

// O con SQL puro
await db.query(
  'SELECT * FROM users WHERE email = $1',
  [userEmail]
)
Pasos de Verificación
  • Todas las consultas de base de datos usan consultas parametrizadas
  • Sin concatenación de cadenas en SQL
  • ORM/query builder usado correctamente
  • Consultas de Supabase correctamente sanitizadas
4. Autenticación y Autorización
Manejo de Tokens JWT
typescript
// FALLA: INCORRECTO: localStorage (vulnerable a XSS)
localStorage.setItem('token', token)

// PASA: CORRECTO: cookies httpOnly
res.setHeader('Set-Cookie',
  `token=${token}; HttpOnly; Secure; SameSite=Strict; Max-Age=3600`)
Verificaciones de Autorización
typescript
export async function deleteUser(userId: string, requesterId: string) {
  // SIEMPRE verificar la autorización primero
  const requester = await db.users.findUnique({
    where: { id: requesterId }
  })

  if (requester.role !== 'admin') {
    return NextResponse.json(
      { error: 'Unauthorized' },
      { status: 403 }
    )
  }

  // Proceder con la eliminación
  await db.users.delete({ where: { id: userId } })
}
Row Level Security (Supabase)
sql
-- Habilitar RLS en todas las tablas
ALTER TABLE users ENABLE ROW LEVEL SECURITY;

-- Los usuarios solo pueden ver sus propios datos
CREATE POLICY "Users view own data"
  ON users FOR SELECT
  USING (auth.uid() = id);

-- Los usuarios solo pueden actualizar sus propios datos
CREATE POLICY "Users update own data"
  ON users FOR UPDATE
  USING (auth.uid() = id);
Pasos de Verificación
  • Tokens almacenados en cookies httpOnly (no localStorage)
  • Verificaciones de autorización antes de operaciones sensibles
  • Row Level Security habilitado en Supabase
  • Control de acceso basado en roles implementado
  • Gestión de sesiones segura
5. Prevención de XSS
Sanitizar HTML
typescript
import DOMPurify from 'isomorphic-dompurify'

// SIEMPRE sanitizar HTML proporcionado por el usuario
function renderUserContent(html: string) {
  const clean = DOMPurify.sanitize(html, {
    ALLOWED_TAGS: ['b', 'i', 'em', 'strong', 'p'],
    ALLOWED_ATTR: []
  })
  return <div dangerouslySetInnerHTML={{ __html: clean }} />
}
Content Security Policy

Comenzar con una política estricta y relajarla solo con un plan de eliminación documentado. No usar 'unsafe-inline' ni 'unsafe-eval' por defecto; neutralizan gran parte de la protección de CSP y deben tratarse como deuda de compatibilidad temporal.

typescript
// next.config.js
const securityHeaders = [
  {
    key: 'Content-Security-Policy',
    value: `
      default-src 'self';
      base-uri 'self';
      object-src 'none';
      frame-ancestors 'none';
      script-src 'self';
      style-src 'self';
      img-src 'self' data: https:;
      font-src 'self';
      connect-src 'self' https://api.example.com;
    `.replace(/\s{2,}/g, ' ').trim()
  }
]
Pasos de Verificación
  • HTML proporcionado por el usuario sanitizado
  • Cabeceras CSP configuradas
  • Sin renderizado de contenido dinámico no validado
  • Protección XSS incorporada de React utilizada
6. Protección CSRF
Tokens CSRF
typescript
import { csrf } from '@/lib/csrf'

export async function POST(request: Request) {
  const token = request.headers.get('X-CSRF-Token')

  if (!csrf.verify(token)) {
    return NextResponse.json(
      { error: 'Invalid CSRF token' },
      { status: 403 }
    )
  }

  // Procesar solicitud
}
Cookies SameSite
typescript
res.setHeader('Set-Cookie',
  `session=${sessionId}; HttpOnly; Secure; SameSite=Strict`)
Pasos de Verificación
  • Tokens CSRF en operaciones que cambian estado
  • SameSite=Strict en todas las cookies
  • Patrón de doble envío de cookie implementado
7. Limitación de Velocidad
Limitación de Velocidad en API
typescript
import rateLimit from 'express-rate-limit'

const limiter = rateLimit({
  windowMs: 15 * 60 * 1000, // 15 minutos
  max: 100, // 100 solicitudes por ventana
  message: 'Too many requests'
})

// Aplicar a rutas
app.use('/api/', limiter)
Operaciones Costosas
typescript
// Limitación agresiva para búsquedas
const searchLimiter = rateLimit({
  windowMs: 60 * 1000, // 1 minuto
  max: 10, // 10 solicitudes por minuto
  message: 'Too many search requests'
})

app.use('/api/search', searchLimiter)
Pasos de Verificación
  • Limitación de velocidad en todos los endpoints de API
  • Límites más estrictos en operaciones costosas
  • Limitación de velocidad basada en IP
  • Limitación de velocidad basada en usuario (autenticado)
Show full SKILL.md (266 more words)Show less
8. Exposición de Datos Sensibles
Logging
typescript
// FALLA: INCORRECTO: Registrar datos sensibles
console.log('User login:', { email, password })
console.log('Payment:', { cardNumber, cvv })

// PASA: CORRECTO: Redactar datos sensibles
console.log('User login:', { email, userId })
console.log('Payment:', { last4: card.last4, userId })
Mensajes de Error
typescript
// FALLA: INCORRECTO: Exponer detalles internos
catch (error) {
  return NextResponse.json(
    { error: error.message, stack: error.stack },
    { status: 500 }
  )
}

// PASA: CORRECTO: Mensajes de error genéricos
catch (error) {
  console.error('Internal error:', error)
  return NextResponse.json(
    { error: 'An error occurred. Please try again.' },
    { status: 500 }
  )
}
Pasos de Verificación
  • Sin contraseñas, tokens ni secretos en los logs
  • Mensajes de error genéricos para usuarios
  • Errores detallados solo en logs del servidor
  • Sin stack traces expuestos a los usuarios
9. Seguridad en Blockchain (Solana)
Verificación de Wallet
typescript
import { verify } from '@solana/web3.js'

async function verifyWalletOwnership(
  publicKey: string,
  signature: string,
  message: string
) {
  try {
    const isValid = verify(
      Buffer.from(message),
      Buffer.from(signature, 'base64'),
      Buffer.from(publicKey, 'base64')
    )
    return isValid
  } catch (error) {
    return false
  }
}
Verificación de Transacciones
typescript
async function verifyTransaction(transaction: Transaction) {
  // Verificar destinatario
  if (transaction.to !== expectedRecipient) {
    throw new Error('Invalid recipient')
  }

  // Verificar monto
  if (transaction.amount > maxAmount) {
    throw new Error('Amount exceeds limit')
  }

  // Verificar que el usuario tiene saldo suficiente
  const balance = await getBalance(transaction.from)
  if (balance < transaction.amount) {
    throw new Error('Insufficient balance')
  }

  return true
}
Pasos de Verificación
  • Firmas de wallet verificadas
  • Detalles de transacción validados
  • Verificaciones de saldo antes de transacciones
  • Sin firma ciega de transacciones
10. Seguridad de Dependencias
Actualizaciones Regulares
bash
# Verificar vulnerabilidades
npm audit

# Corregir problemas reparables automáticamente
npm audit fix

# Actualizar dependencias
npm update

# Verificar paquetes desactualizados
npm outdated
Archivos Lock
bash
# SIEMPRE hacer commit de los archivos lock
git add package-lock.json

# Usar en CI/CD para builds reproducibles
npm ci  # En lugar de npm install
Pasos de Verificación
  • Dependencias actualizadas
  • Sin vulnerabilidades conocidas (npm audit limpio)
  • Archivos lock con commit
  • Dependabot habilitado en GitHub
  • Actualizaciones de seguridad regulares

Pruebas de Seguridad

Pruebas de Seguridad Automatizadas
typescript
// Probar autenticación
test('requires authentication', async () => {
  const response = await fetch('/api/protected')
  expect(response.status).toBe(401)
})

// Probar autorización
test('requires admin role', async () => {
  const response = await fetch('/api/admin', {
    headers: { Authorization: `Bearer ${userToken}` }
  })
  expect(response.status).toBe(403)
})

// Probar validación de entrada
test('rejects invalid input', async () => {
  const response = await fetch('/api/users', {
    method: 'POST',
    body: JSON.stringify({ email: 'not-an-email' })
  })
  expect(response.status).toBe(400)
})

// Probar limitación de velocidad
test('enforces rate limits', async () => {
  const requests = Array(101).fill(null).map(() =>
    fetch('/api/endpoint')
  )

  const responses = await Promise.all(requests)
  const tooManyRequests = responses.filter(r => r.status === 429)

  expect(tooManyRequests.length).toBeGreaterThan(0)
})

Lista de Verificación Previa al Despliegue

Antes de CUALQUIER despliegue a producción:

  • Secretos: Sin secretos hardcodeados, todos en variables de entorno
  • Validación de Entrada: Todas las entradas del usuario validadas
  • Inyección SQL: Todas las consultas parametrizadas
  • XSS: Contenido del usuario sanitizado
  • CSRF: Protección habilitada
  • Autenticación: Manejo correcto de tokens
  • Autorización: Verificaciones de rol en su lugar
  • Limitación de Velocidad: Habilitada en todos los endpoints
  • HTTPS: Forzado en producción
  • Cabeceras de Seguridad: CSP, X-Frame-Options configurados
  • Manejo de Errores: Sin datos sensibles en errores
  • Logging: Sin datos sensibles registrados
  • Dependencias: Actualizadas, sin vulnerabilidades
  • Row Level Security: Habilitado en Supabase
  • CORS: Correctamente configurado
  • Subida de Archivos: Validada (tamaño, tipo)
  • Firmas de Wallet: Verificadas (si hay blockchain)

Recursos

  • OWASP Top 10
  • Documentación de seguridad de Next.js
  • Documentación de seguridad de Supabase
  • Web Security Academy (PortSwigger)

Recuerda: La seguridad no es opcional. Una sola vulnerabilidad puede comprometer toda la plataforma. Ante la duda, optar por el lado de la precaución.

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/es/skills/security-review of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skillaffaan-m/ECC276k—~3.4kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.5kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Vibe Checkbenavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    xu-xiang/everything-claude-code-zh

    当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

    2k GitHub stars~2.5k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

    2k GitHub stars~2.4k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    在添加身份验证、处理用户输入、操作机密信息、创建 API 接口或实现支付/敏感功能时使用此技能。提供全面的安全自查清单和模式。

    2k GitHub stars~2.4k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Vibe Check

    benavlabs/vibe-check

    Security audit for web apps, especially AI-built ("vibe coded") ones.

    118 GitHub stars~1.1k tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Works with

Categories

Questions about Security Review

What does Security Review do?

Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. Security Review is an agent skill from affaan-m/ECC. Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles.

When should I use Security Review?

Security Review fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities.

How do I install Security Review in Claude Code?

Run `npx skills add affaan-m/ECC --skill security-review -a claude-code`. Or copy the skill folder (docs/es/skills/security-review in affaan-m/ECC) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add affaan-m/ECC --skill security-review -a codex`. Or copy the skill folder (docs/es/skills/security-review in affaan-m/ECC) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (npm and git) and credentials named OPENAI_API_KEY. Our summary lists: Node.js; A credential in OPENAI_API_KEY.

Does Security Review access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Security Review (xu-xiang/everything-claude-code-zh, 2k stars), Security Review (xu-xiang/everything-claude-code-zh, 2k stars), Security Review (xu-xiang/everything-claude-code-zh, 2k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.