Agent skill

Secure Code Review

by aiming-lab in aiming-lab/MetaClaw

A skill your agent uses when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries.

MITAuto-check passedSecurity

Install Secure Code Review

skills CLI
$ npx skills add aiming-lab/MetaClaw --skill secure-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiming-lab/MetaClaw secure-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiming-lab/MetaClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/memory_data/skills/secure-code-review .claude/skills/secure-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-code-review
GitHub stars
3.5k
Token cost
~249 tokens
SKILL.md length
90 words
Files
1
Skills in repo
36
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries.

  • Writing code that handles user input
  • Calls pip and npm
  • Network requests
  • Database queries

What it does

Secure Code Review is an agent skill from aiming-lab/MetaClaw. Use this skill when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries. Always check for common security vulnerabilities before considering the code complete.

Its SKILL.md is about 250 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The repository describes itself as: 🦞 Just talk to your agent — it learns and EVOLVES 🧬. The licence is MIT.

When your agent uses it

  • Writing code that handles user input
  • Network requests
  • Database queries

Example prompts

  • “/secure-code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 922caf3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure Code Review loads about 249 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 90 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~249

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aiming-lab/MetaClaw at commit 922caf3, republished under its MIT licence (© aiming-lab). 90 words, ~249 tokens.

Download SKILL.mdSave it as .claude/skills/secure-code-review/SKILL.md (or your agent's skills folder).
name
secure-code-review
description
Use this skill when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries. Always check for common security vulnerabilities before considering the code complete.
category
coding

Secure Code Review Checklist

Input Validation:

  • Never trust user-supplied input; validate type, length, and format at boundaries.
  • Use parameterized queries — never string-interpolate SQL.
  • Sanitize before rendering HTML to prevent XSS.

Secrets & Credentials:

  • No hardcoded passwords, API keys, or tokens in source code.
  • Use environment variables or a secrets manager.
  • Check .gitignore before adding any config files.

Dependencies:

  • Pin dependency versions; audit with pip audit or npm audit.
  • Minimize surface area: remove unused packages.

Auth:

  • Verify authorization on every protected endpoint, not just at login.
  • Use short-lived tokens; implement refresh flows.

© aiming-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in memory_data/skills/secure-code-review of aiming-lab/MetaClaw.

Open the folder on GitHubat commit 922caf3

Compare with similar skills

Secure Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure Code Review this skillaiming-lab/MetaClaw3.5k—~249Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 6 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from aiming-lab/MetaClaw

All 36 skills in this repo
  • Data Validation First

    aiming-lab/MetaClaw

    Use this skill before any data analysis, transformation, or modeling.

    3.5k GitHub stars~230 tokensUpdated 4 mo ago
    Auto-check passed
  • A skill your agent uses when implementing any endpoint, form handler, CLI tool, or function that accepts external input.

    3.5k GitHub stars~251 tokensUpdated 4 mo ago
    Auto-check passed
  • A skill your agent uses when writing shell scripts, Python automation, or any unattended batch job.

    3.5k GitHub stars~225 tokensUpdated 4 mo ago
    Auto-check passed
  • A skill your agent uses when building production services, pipelines, or automation that needs to be debugged, monitored, or audited.

    3.5k GitHub stars~247 tokensUpdated 4 mo ago
    Auto-check passed
  • Agent Task Handoff

    aiming-lab/MetaClaw

    A skill your agent uses when delegating a subtask to a sub-agent, spawning a parallel worker, or handing off work across sessions.

    3.5k GitHub stars~258 tokensUpdated 4 mo ago
    Auto-check passed
  • A skill your agent uses when writing messages in async channels (Slack, GitHub issues, email threads) where the reader may not have context and cannot ask follow-up questions immediately.

    3.5k GitHub stars~224 tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Secure Code Review

What does Secure Code Review do?

A skill your agent uses when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries. Secure Code Review is an agent skill from aiming-lab/MetaClaw. Use this skill when reviewing or writing code that handles user input, authentication, file I/O, network requests, or database queries.

When should I use Secure Code Review?

Secure Code Review fits situations like: writing code that handles user input; network requests; database queries.

How do I install Secure Code Review in Claude Code?

Run `npx skills add aiming-lab/MetaClaw --skill secure-code-review -a claude-code`. Or copy the skill folder (memory_data/skills/secure-code-review in aiming-lab/MetaClaw) into .claude/skills/secure-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Secure Code Review in Codex?

Run `npx skills add aiming-lab/MetaClaw --skill secure-code-review -a codex`. Or copy the skill folder (memory_data/skills/secure-code-review in aiming-lab/MetaClaw) into .agents/skills/secure-code-review in your project. Codex loads it when a task matches its description.

Can I use Secure Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiming-lab/MetaClaw --skill secure-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-code-review, .gemini/skills/secure-code-review, .github/skills/secure-code-review and .opencode/skills/secure-code-review in your project.

What does Secure Code Review need to run?

Going by SKILL.md and its folder, Secure Code Review needs the command-line tools its instructions call (pip and npm).

Does Secure Code Review access the network?

SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Secure Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure Code Review use?

Secure Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secure Code Review use?

About 249 tokens (SKILL.md is roughly 996 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure Code Review?

Skills that share tags, products or a category with Secure Code Review: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure Code Review?

aiming-lab (a GitHub organization) maintains it in aiming-lab/MetaClaw, which has 3,459 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on June 7, 2026.

Source: aiming-lab/MetaClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.