Agent skill

Security Reviewer

by AratKruglik in AratKruglik/claude-laravel

A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

No licenceAuto-check: notesSecurity

Install Security Reviewer

skills CLI
$ npx skills add AratKruglik/claude-laravel --skill security-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AratKruglik/claude-laravel security-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AratKruglik/claude-laravel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-reviewer .claude/skills/security-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-reviewer
GitHub stars
155
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
345 words
Files
7 (incl. references)
Skills in repo
17
Repo updated
First seen
Licence
None found

At a glance

A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

  • Works in 6 steps: Scope - Attack surface and critical paths → Automated scan - SAST and dependency tools → Manual review - Auth, input handling,… → …
  • Conducting security audits
  • SKILL.md covers Role Definition, When to Use This Skill, Core Workflow and Reference Guide, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Reviewer is an agent skill from AratKruglik/claude-laravel. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews. Українською: безпека коду, аудит безпеки, вразливості, XSS, SQL ін'єкція, авторизація, автентифікація, CSRF, шифрування, перевір безпеку, знайди вразливість, DevSecOps, пентест

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/infrastructure-security.md`, `references/penetration-testing.md` and `references/report-template.md`).

It sits in Security, covering Web application vulnerabilities, Static analysis and SAST and Penetration testing. It works with SQL.

When your agent uses it

  • Conducting security audits
  • Reviewing code for vulnerabilities
  • Analyzing infrastructure security

Example prompts

  • “/security-reviewer”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Scope - Attack surface and critical paths
  2. Automated scan - SAST and dependency tools
  3. Manual review - Auth, input handling, crypto
  4. Active testing - Validation and exploitation (authorized only)
  5. Categorize - Rate severity (Critical/High/Medium/Low)
  6. Report - Document findings with remediation

What it can do on your machine

Read from SKILL.md and the folder at commit 00e8b99. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Reviewer loads about 1.1k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 345 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 345 words (~1,059 tokens).

“Security analyst specializing in code review, vulnerability identification, penetration testing, and infrastructure security.”

— opening of SKILL.md by AratKruglik
name
security-reviewer
allowed-tools
Read, Grep, Glob, Bash
triggers
- security review - vulnerability scan - SAST - security audit - penetration test - code audit - security analysis - infrastructure security - DevSecOps…
role
specialist
scope
review
output-format
report

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (references) in .claude/skills/security-reviewer of AratKruglik/claude-laravel.

  • SKILL.md
  • references/infrastructure-security.md
  • references/penetration-testing.md
  • references/report-template.md
  • references/sast-tools.md
  • references/secret-scanning.md
  • references/vulnerability-patterns.md

Open the folder on GitHubat commit 00e8b99

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in AratKruglik/claude-laravel, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Reviewer this skillAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Security Auditstaruhub/ClaudeSkills728—~1.3kAutomated safety check: NotesMIT
Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Code Security AuditorLeoYeAI/openclaw-master-skills2.2k—~3.7kAutomated safety check: NotesMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Security Audit

    staruhub/ClaudeSkills

    全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

    728 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Code Security Auditor

    LeoYeAI/openclaw-master-skills

    Comprehensive code security audit with AI-powered vulnerability detection.

    2.2k GitHub stars~3.7k tokensUpdated 2 mo ago
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from AratKruglik/claude-laravel

All 17 skills in this repo
  • Laravel Actions Patterns

    AratKruglik/claude-laravel

    A skill your agent uses when working with lorisleiva/laravel-actions package - AsController, AsJob, AsObject, AsListener patterns, handle() signatures, and deciding which trait combination to use…

    155 GitHub stars~1.3k tokensUpdated 5 mo ago
    Auto-check passed
  • Architecture Designer

    AratKruglik/claude-laravel

    A skill your agent uses when designing new system architecture, reviewing existing designs, or making architectural decisions.

    155 GitHub starsUsed in 1 repo~895 tokens
    Auto-check passed
  • Octane Frankenphp Gotchas

    AratKruglik/claude-laravel

    A skill your agent uses when debugging unexpected behavior in Laravel Octane with FrankenPHP - stale data between requests, memory leaks, singleton contamination, static property state, or anything…

    155 GitHub stars~732 tokensUpdated 5 mo ago
    Auto-check passed
  • Pest Testing

    AratKruglik/claude-laravel

    Tests applications using the Pest 4 PHP framework. An agent skill from AratKruglik/claude-laravel.

    155 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Playwright Skill

    AratKruglik/claude-laravel

    Complete browser automation with Playwright. An agent skill from AratKruglik/claude-laravel.

    155 GitHub starsUsed in 10 repos~3.5k tokens
    Auto-check passed
  • Architect Review

    AratKruglik/claude-laravel

    Master software architect specializing in modern architecture patterns, clean architecture, microservices, event-driven systems, and DDD.

    155 GitHub starsUsed in 8 repos~2.2k tokens
    Auto-check passed

Works with

Categories

Questions about Security Reviewer

What does Security Reviewer do?

A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Security Reviewer is an agent skill from AratKruglik/claude-laravel. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

When should I use Security Reviewer?

Security Reviewer fits situations like: conducting security audits; reviewing code for vulnerabilities; analyzing infrastructure security.

How do I install Security Reviewer in Claude Code?

Run `npx skills add AratKruglik/claude-laravel --skill security-reviewer -a claude-code`. Or copy the skill folder (.claude/skills/security-reviewer in AratKruglik/claude-laravel) into .claude/skills/security-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Security Reviewer in Codex?

Run `npx skills add AratKruglik/claude-laravel --skill security-reviewer -a codex`. Or copy the skill folder (.claude/skills/security-reviewer in AratKruglik/claude-laravel) into .agents/skills/security-reviewer in your project. Codex loads it when a task matches its description.

Can I use Security Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AratKruglik/claude-laravel --skill security-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-reviewer, .gemini/skills/security-reviewer, .github/skills/security-reviewer and .opencode/skills/security-reviewer in your project.

What does Security Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Reviewer is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Security Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Reviewer safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Reviewer use?

No licence was found for Security Reviewer or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Reviewer use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7k tokens, read only when the agent opens those files.

What are the alternatives to Security Reviewer?

Skills that share tags, products or a category with Security Reviewer: Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Security Audit (staruhub/ClaudeSkills, 728 stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Code Security Auditor (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Reviewer?

AratKruglik (a GitHub user) maintains it in AratKruglik/claude-laravel, which has 155 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on April 20, 2026.

Source: AratKruglik/claude-laravel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.