Agent skill

Security Review

by affaan-m in affaan-m/ECC

Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

MITAuto-check: notesSecurity

Install Security Review

skills CLI
$ npx skills add affaan-m/ECC --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/tr/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
277k
Used in
1 other repo
Token cost
~3.2k tokens
SKILL.md length
493 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

  • Works in 10 steps: Secret Yönetimi → Input Doğrulama → SQL Injection Önleme → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Ne Zaman Aktifleştirmelisiniz, Güvenlik Kontrol Listesi, Güvenlik Testi and Deployment Öncesi Güvenlik…, plus 1 more section
  • Calls npm and git; needs OPENAI_API_KEY

What it does

Security Review is an agent skill from affaan-m/ECC. Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. Kapsamlı güvenlik kontrol listesi ve kalıplar sağlar.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Security review and REST APIs. It works with Supabase. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Security review
  • Tasks that involve REST APIs

Example prompts

  • “larla çalışırken, API endpoint”
  • “/security-review”

Requirements

  • Node.js
  • A credential in OPENAI_API_KEY

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Secret Yönetimi
  2. Input Doğrulama
  3. SQL Injection Önleme
  4. Kimlik Doğrulama ve Yetkilendirme
  5. XSS Önleme
  6. CSRF Koruması
  7. Rate Limiting
  8. Hassas Veri İfşası
  9. Blockchain Güvenliği (Solana)
  10. Bağımlılık Güvenliği

What it can do on your machine

Read from SKILL.md and the folder at commit 2d515e4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • nextjs.org
    • supabase.com
    • portswigger.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 3.2k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 493 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:45
    - [ ] `.env.local` .gitignore'da

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 2d515e4, republished under its MIT licence (© affaan-m). 493 words, ~3,175 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. Kapsamlı güvenlik kontrol listesi ve kalıplar sağlar.
origin
ECC

Güvenlik İnceleme Skill'i

Bu skill tüm kodun güvenlik en iyi uygulamalarını takip etmesini sağlar ve potansiyel güvenlik açıklarını tanımlar.

Ne Zaman Aktifleştirmelisiniz

  • Kimlik doğrulama veya yetkilendirme uygularken
  • Kullanıcı girdisi veya dosya yüklemeleri işlerken
  • Yeni API endpoint'leri oluştururken
  • Secret'lar veya kimlik bilgileriyle çalışırken
  • Ödeme özellikleri uygularken
  • Hassas veri saklarken veya iletirken
  • Üçüncü taraf API'leri entegre ederken

Güvenlik Kontrol Listesi

1. Secret Yönetimi
FAIL: ASLA Bunu Yapmayın
typescript
const apiKey = "sk-proj-xxxxx"  // Hardcoded secret
const dbPassword = "password123" // Kaynak kodda
PASS: HER ZAMAN Bunu Yapın
typescript
const apiKey = process.env.OPENAI_API_KEY
const dbUrl = process.env.DATABASE_URL

// Secret'ların var olduğunu doğrula
if (!apiKey) {
  throw new Error('OPENAI_API_KEY not configured')
}
Doğrulama Adımları
  • Hardcoded API key, token veya şifre yok
  • Tüm secret'lar environment variable'larda
  • .env.local .gitignore'da
  • Git history'de secret yok
  • Production secret'ları hosting platformunda (Vercel, Railway)
2. Input Doğrulama
Her Zaman Kullanıcı Girdisini Doğrulayın
typescript
import { z } from 'zod'

// Doğrulama şeması tanımla
const CreateUserSchema = z.object({
  email: z.string().email(),
  name: z.string().min(1).max(100),
  age: z.number().int().min(0).max(150)
})

// İşlemeden önce doğrula
export async function createUser(input: unknown) {
  try {
    const validated = CreateUserSchema.parse(input)
    return await db.users.create(validated)
  } catch (error) {
    if (error instanceof z.ZodError) {
      return { success: false, errors: error.errors }
    }
    throw error
  }
}
Dosya Yükleme Doğrulama
typescript
function validateFileUpload(file: File) {
  // Boyut kontrolü (5MB max)
  const maxSize = 5 * 1024 * 1024
  if (file.size > maxSize) {
    throw new Error('Dosya çok büyük (max 5MB)')
  }

  // Tip kontrolü
  const allowedTypes = ['image/jpeg', 'image/png', 'image/gif']
  if (!allowedTypes.includes(file.type)) {
    throw new Error('Geçersiz dosya tipi')
  }

  // Uzantı kontrolü
  const allowedExtensions = ['.jpg', '.jpeg', '.png', '.gif']
  const extension = file.name.toLowerCase().match(/\.[^.]+$/)?.[0]
  if (!extension || !allowedExtensions.includes(extension)) {
    throw new Error('Geçersiz dosya uzantısı')
  }

  return true
}
Doğrulama Adımları
  • Tüm kullanıcı girdileri şema ile doğrulanmış
  • Dosya yüklemeleri kısıtlanmış (boyut, tip, uzantı)
  • Kullanıcı girdisi doğrudan sorgularda kullanılmıyor
  • Whitelist doğrulama (blacklist değil)
  • Hata mesajları hassas bilgi sızdırmıyor
3. SQL Injection Önleme
FAIL: ASLA SQL Concatenation Yapmayın
typescript
// TEHLİKELİ - SQL Injection açığı
const query = `SELECT * FROM users WHERE email = '${userEmail}'`
await db.query(query)
PASS: HER ZAMAN Parametreli Sorgular Kullanın
typescript
// Güvenli - parametreli sorgu
const { data } = await supabase
  .from('users')
  .select('*')
  .eq('email', userEmail)

// Veya raw SQL ile
await db.query(
  'SELECT * FROM users WHERE email = $1',
  [userEmail]
)
Doğrulama Adımları
  • Tüm veritabanı sorguları parametreli
  • SQL'de string concatenation yok
  • ORM/query builder doğru kullanılıyor
  • Supabase sorguları düzgün sanitize edilmiş
4. Kimlik Doğrulama ve Yetkilendirme
JWT Token İşleme
typescript
// FAIL: YANLIŞ: localStorage (XSS'e karşı savunmasız)
localStorage.setItem('token', token)

// PASS: DOĞRU: httpOnly cookies
res.setHeader('Set-Cookie',
  `token=${token}; HttpOnly; Secure; SameSite=Strict; Max-Age=3600`)
Yetkilendirme Kontrolleri
typescript
export async function deleteUser(userId: string, requesterId: string) {
  // HER ZAMAN önce yetkilendirmeyi doğrula
  const requester = await db.users.findUnique({
    where: { id: requesterId }
  })

  if (requester.role !== 'admin') {
    return NextResponse.json(
      { error: 'Unauthorized' },
      { status: 403 }
    )
  }

  // Silme işlemine devam et
  await db.users.delete({ where: { id: userId } })
}
Row Level Security (Supabase)
sql
-- Tüm tablolarda RLS'yi aktifleştir
ALTER TABLE users ENABLE ROW LEVEL SECURITY;

-- Kullanıcılar sadece kendi verilerini görebilir
CREATE POLICY "Users view own data"
  ON users FOR SELECT
  USING (auth.uid() = id);

-- Kullanıcılar sadece kendi verilerini güncelleyebilir
CREATE POLICY "Users update own data"
  ON users FOR UPDATE
  USING (auth.uid() = id);
Doğrulama Adımları
  • Token'lar httpOnly cookie'lerde (localStorage'da değil)
  • Hassas operasyonlardan önce yetkilendirme kontrolleri
  • Supabase'de Row Level Security aktif
  • Rol tabanlı erişim kontrolü uygulanmış
  • Session yönetimi güvenli
5. XSS Önleme
HTML'i Sanitize Et
typescript
import DOMPurify from 'isomorphic-dompurify'

// HER ZAMAN kullanıcı tarafından sağlanan HTML'i sanitize et
function renderUserContent(html: string) {
  const clean = DOMPurify.sanitize(html, {
    ALLOWED_TAGS: ['b', 'i', 'em', 'strong', 'p'],
    ALLOWED_ATTR: []
  })
  return <div dangerouslySetInnerHTML={{ __html: clean }} />
}
Content Security Policy
typescript
// next.config.js
const securityHeaders = [
  {
    key: 'Content-Security-Policy',
    value: `
      default-src 'self';
      script-src 'self' 'unsafe-eval' 'unsafe-inline';
      style-src 'self' 'unsafe-inline';
      img-src 'self' data: https:;
      font-src 'self';
      connect-src 'self' https://api.example.com;
    `.replace(/\s{2,}/g, ' ').trim()
  }
]
Doğrulama Adımları
  • Kullanıcı tarafından sağlanan HTML sanitize edilmiş
  • CSP başlıkları yapılandırılmış
  • Doğrulanmamış dinamik içerik render'ı yok
  • React'in yerleşik XSS koruması kullanılıyor
6. CSRF Koruması
CSRF Token'ları
typescript
import { csrf } from '@/lib/csrf'

export async function POST(request: Request) {
  const token = request.headers.get('X-CSRF-Token')

  if (!csrf.verify(token)) {
    return NextResponse.json(
      { error: 'Invalid CSRF token' },
      { status: 403 }
    )
  }

  // İsteği işle
}
typescript
res.setHeader('Set-Cookie',
  `session=${sessionId}; HttpOnly; Secure; SameSite=Strict`)
Doğrulama Adımları
  • State değiştiren operasyonlarda CSRF token'ları
  • Tüm cookie'lerde SameSite=Strict
  • Double-submit cookie pattern uygulanmış
7. Rate Limiting
API Rate Limiting
typescript
import rateLimit from 'express-rate-limit'

const limiter = rateLimit({
  windowMs: 15 * 60 * 1000, // 15 dakika
  max: 100, // Pencere başına 100 istek
  message: 'Çok fazla istek'
})

// Route'lara uygula
app.use('/api/', limiter)
Pahalı Operasyonlar
typescript
// Aramalar için agresif rate limiting
const searchLimiter = rateLimit({
  windowMs: 60 * 1000, // 1 dakika
  max: 10, // Dakikada 10 istek
  message: 'Çok fazla arama isteği'
})

app.use('/api/search', searchLimiter)
Doğrulama Adımları
  • Tüm API endpoint'lerinde rate limiting
  • Pahalı operasyonlarda daha sıkı limitler
  • IP tabanlı rate limiting
  • Kullanıcı tabanlı rate limiting (authenticated)
8. Hassas Veri İfşası
Loglama
typescript
// FAIL: YANLIŞ: Hassas veri loglama
console.log('User login:', { email, password })
console.log('Payment:', { cardNumber, cvv })

// PASS: DOĞRU: Hassas veriyi gizle
console.log('User login:', { email, userId })
console.log('Payment:', { last4: card.last4, userId })
Hata Mesajları
typescript
// FAIL: YANLIŞ: İç detayları açığa çıkarma
catch (error) {
  return NextResponse.json(
    { error: error.message, stack: error.stack },
    { status: 500 }
  )
}

// PASS: DOĞRU: Genel hata mesajları
catch (error) {
  console.error('Internal error:', error)
  return NextResponse.json(
    { error: 'Bir hata oluştu. Lütfen tekrar deneyin.' },
    { status: 500 }
  )
}
Show full SKILL.md (199 more words)Show less
Doğrulama Adımları
  • Loglarda şifre, token veya secret yok
  • Kullanıcılar için genel hata mesajları
  • Detaylı hatalar sadece sunucu loglarında
  • Kullanıcılara stack trace gösterilmiyor
9. Blockchain Güvenliği (Solana)
Wallet Doğrulama
typescript
import { verify } from '@solana/web3.js'

async function verifyWalletOwnership(
  publicKey: string,
  signature: string,
  message: string
) {
  try {
    const isValid = verify(
      Buffer.from(message),
      Buffer.from(signature, 'base64'),
      Buffer.from(publicKey, 'base64')
    )
    return isValid
  } catch (error) {
    return false
  }
}
Transaction Doğrulama
typescript
async function verifyTransaction(transaction: Transaction) {
  // Alıcıyı doğrula
  if (transaction.to !== expectedRecipient) {
    throw new Error('Geçersiz alıcı')
  }

  // Miktarı doğrula
  if (transaction.amount > maxAmount) {
    throw new Error('Miktar limiti aşıyor')
  }

  // Kullanıcının yeterli bakiyesi olduğunu doğrula
  const balance = await getBalance(transaction.from)
  if (balance < transaction.amount) {
    throw new Error('Yetersiz bakiye')
  }

  return true
}
Doğrulama Adımları
  • Wallet imzaları doğrulanmış
  • Transaction detayları validate edilmiş
  • Transaction'lardan önce bakiye kontrolleri
  • Kör transaction imzalama yok
10. Bağımlılık Güvenliği
Düzenli Güncellemeler
bash
# Güvenlik açıklarını kontrol et
npm audit

# Otomatik düzeltilebilir sorunları düzelt
npm audit fix

# Bağımlılıkları güncelle
npm update

# Eski paketleri kontrol et
npm outdated
Lock Dosyaları
bash
# HER ZAMAN lock dosyalarını commit et
git add package-lock.json

# CI/CD'de tekrarlanabilir build'ler için kullan
npm ci  # npm install yerine
Doğrulama Adımları
  • Bağımlılıklar güncel
  • Bilinen güvenlik açığı yok (npm audit clean)
  • Lock dosyaları commit edilmiş
  • GitHub'da Dependabot aktif
  • Düzenli güvenlik güncellemeleri

Güvenlik Testi

Otomatik Güvenlik Testleri
typescript
// Kimlik doğrulama testi
test('kimlik doğrulama gerektirir', async () => {
  const response = await fetch('/api/protected')
  expect(response.status).toBe(401)
})

// Yetkilendirme testi
test('admin rolü gerektirir', async () => {
  const response = await fetch('/api/admin', {
    headers: { Authorization: `Bearer ${userToken}` }
  })
  expect(response.status).toBe(403)
})

// Input doğrulama testi
test('geçersiz input'u reddeder', async () => {
  const response = await fetch('/api/users', {
    method: 'POST',
    body: JSON.stringify({ email: 'not-an-email' })
  })
  expect(response.status).toBe(400)
})

// Rate limiting testi
test('rate limit'leri zorlar', async () => {
  const requests = Array(101).fill(null).map(() =>
    fetch('/api/endpoint')
  )

  const responses = await Promise.all(requests)
  const tooManyRequests = responses.filter(r => r.status === 429)

  expect(tooManyRequests.length).toBeGreaterThan(0)
})

Deployment Öncesi Güvenlik Kontrol Listesi

HERHANGİ bir production deployment'ından önce:

  • Secret'lar: Hardcoded secret yok, hepsi env var'larda
  • Input Doğrulama: Tüm kullanıcı girdileri validate edilmiş
  • SQL Injection: Tüm sorgular parametreli
  • XSS: Kullanıcı içeriği sanitize edilmiş
  • CSRF: Koruma aktif
  • Kimlik Doğrulama: Doğru token işleme
  • Yetkilendirme: Rol kontrolleri yerinde
  • Rate Limiting: Tüm endpoint'lerde aktif
  • HTTPS: Production'da zorunlu
  • Güvenlik Başlıkları: CSP, X-Frame-Options yapılandırılmış
  • Hata İşleme: Hatalarda hassas veri yok
  • Loglama: Hassas veri loglanmıyor
  • Bağımlılıklar: Güncel, güvenlik açığı yok
  • Row Level Security: Supabase'de aktif
  • CORS: Düzgün yapılandırılmış
  • Dosya Yüklemeleri: Validate edilmiş (boyut, tip)
  • Wallet İmzaları: Doğrulanmış (blockchain varsa)

Kaynaklar


Unutmayın: Güvenlik opsiyonel değildir. Bir güvenlik açığı tüm platformu tehlikeye atabilir. Şüphe duyduğunuzda ihtiyatlı olun.

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/tr/skills/security-review of affaan-m/ECC.

Open the folder on GitHubat commit 2d515e4

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in affaan-m/ECC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skillaffaan-m/ECC277k1 repos~3.2kAutomated safety check: NotesMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
API Security ReviewOWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.0
Vibe Checkbenavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
MCP Implementation Security Reviewgithub/awesome-copilot40k—~5.2kAutomated safety check: PassMIT

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    188 GitHub stars~744 tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Vibe Check

    benavlabs/vibe-check

    Security audit for web apps, especially AI-built ("vibe coded") ones.

    118 GitHub stars~1.1k tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Official

    Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema…

    40k GitHub stars~5.2k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Audit

    Houseofmvps/ultraship

    Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.

    123 GitHub stars~3.9k tokensUpdated 3 mo ago
    SecurityAuto-check: notes

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Works with

Questions about Security Review

What does Security Review do?

Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. Security Review is an agent skill from affaan-m/ECC. Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

When should I use Security Review?

Security Review fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review; tasks that involve REST APIs.

How do I install Security Review in Claude Code?

Run `npx skills add affaan-m/ECC --skill security-review -a claude-code`. Or copy the skill folder (docs/tr/skills/security-review in affaan-m/ECC) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add affaan-m/ECC --skill security-review -a codex`. Or copy the skill folder (docs/tr/skills/security-review in affaan-m/ECC) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (npm and git) and credentials named OPENAI_API_KEY. Our summary lists: Node.js; A credential in OPENAI_API_KEY.

Does Security Review access the network?

SKILL.md names 4 domains. As links in the text: owasp.org, nextjs.org, supabase.com and portswigger.net. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Security Review (jewbetcha/opentrace, 116 stars), API Security Review (OWASP/secure-agent-playbook, 188 stars), Vibe Check (benavlabs/vibe-check, 118 stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,673 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 11, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.