GitHub Review Iteration
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
Security-focused source code review. An agent skill from blacklanternsecurity/red-run.
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install blacklanternsecurity/red-run source-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web/source-code-review .claude/skills/source-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "source-code-review" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-review into .claude/skills/source-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install blacklanternsecurity/red-run source-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/web/source-code-review .agents/skills/source-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "source-code-review" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-review into .agents/skills/source-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install blacklanternsecurity/red-run source-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/web/source-code-review .cursor/skills/source-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "source-code-review" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-review into .cursor/skills/source-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/blacklanternsecurity/red-run.git --path skills/web/source-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install blacklanternsecurity/red-run source-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/web/source-code-review .gemini/skills/source-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "source-code-review" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-review into .gemini/skills/source-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install blacklanternsecurity/red-run source-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/web/source-code-review .github/skills/source-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "source-code-review" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-review into .github/skills/source-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install blacklanternsecurity/red-run source-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/web/source-code-review .opencode/skills/source-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "source-code-review" agent skill from https://github.com/blacklanternsecurity/red-run/tree/main/skills/web/source-code-review into .opencode/skills/source-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
source-code-reviewSecurity-focused source code review. An agent skill from blacklanternsecurity/red-run.
Source Code Review is an agent skill from blacklanternsecurity/red-run. Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review, Authentication and Subagents. The repository describes itself as: Offensive security toolkit for Claude Code. The licence is GPL-3.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 050ac1f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYAWS_ACCESS_KEYPRIVATE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Source Code Review loads about 1.8k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 584 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Config files (settings.py, .env, web.config, application.yml, etc.)**PHP/Laravel:** `.env` in webroot, `APP_DEBUG=true`, mass assignmentAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from blacklanternsecurity/red-run at commit 050ac1f, republished under its GPL-3.0 licence (© blacklanternsecurity). 584 words, ~1,770 tokens.
.claude/skills/source-code-review/SKILL.md (or your agent's skills folder).You are a vulnerability researcher reviewing application source code for security weaknesses. Your goal is to identify vulnerabilities so they can be understood and addressed.
Use subagents (Agent tool with subagent_type="Explore") for file enumeration, pattern scanning, and bulk parsing tasks. Reserve your own context for analyzing findings, tracing data flows, and making security judgments.
Check for ./engagement/ directory. If absent, proceed without logging.
When an engagement directory exists:
[source-code-review] Activated → <target> on activation.engagement/evidence/research/source-review-<app>.md.This skill covers static analysis of application source for security vulnerabilities. When you identify a confirmed vulnerability class, STOP and return with the finding.
Do not modify source files. Do not run the application. Analyze only.
Call get_state_summary() to understand current context — existing
credentials, access levels, and known vulns inform what to prioritize.
engagement/evidence/)Spawn an Explore subagent to map the codebase structure:
"List all files in <source_path> grouped by type. Identify:
- Framework (Django, Flask, Express, Spring, Laravel, .NET, etc.)
- Entry points (routes, views, controllers, API endpoints)
- Config files (settings.py, .env, web.config, application.yml, etc.)
- Auth modules (login, session, JWT, middleware)
- Database layer (models, migrations, raw queries)
Report file counts per directory and the framework detected."Spawn an Explore subagent to grep for hardcoded secrets — highest-value, lowest-effort pass:
"Search all files in <source_path> for hardcoded secrets. Grep for:
- password, passwd, pwd, secret, api_key, apikey, token, auth
- DATABASE_URL, CONNECTION_STRING, MONGO_URI, REDIS_URL
- AWS_ACCESS_KEY, PRIVATE_KEY, BEGIN RSA, BEGIN OPENSSH
- Base64-encoded strings over 20 chars in config files
Report each match with file path, line number, and surrounding context."Review the subagent's results. Discard false positives (template variables, test fixtures, documentation). For confirmed credentials:
[add-cred] for eachRead auth-related files yourself (these require security judgment):
Spawn an Explore subagent to find dangerous sinks:
"Search <source_path> for dangerous function calls. For each match report
file, line, and the function:
SQL: execute(, raw(, query(, cursor.execute, .extra(, $where, db.query
Command: os.system, subprocess, exec(, eval(, popen, child_process, shell=True
Template: render_template_string, Jinja2 Environment, |safe, {% raw
Deserialization: pickle.loads, yaml.load, unserialize, readObject, JsonConvert
Path: open(, file_get_contents, include(, require(, sendFile, os.path.join
SSRF: requests.get, urllib, fetch(, HttpClient with variable URL
XSS: innerHTML, document.write, v-html, dangerouslySetInnerHTML"For each finding, trace the data flow yourself:
Based on the framework detected in Step 1:
Python/Django: DEBUG = True, SECRET_KEY hardcoded, @csrf_exempt,
raw SQL in views, ALLOWED_HOSTS = ['*'], pickle sessions, custom template tags
Python/Flask: app.secret_key, debug=True, Jinja2 |safe filter,
render_template_string with user input, no CSRF protection
PHP/Laravel: .env in webroot, APP_DEBUG=true, mass assignment
($fillable/$guarded), blade {!! !!} unescaped, SQL in raw queries
Node/Express: eval() with user input, prototype pollution, NoSQL
injection ($gt, $ne), missing helmet headers, JWT secret in source
Java/Spring: SpEL injection, actuator endpoints exposed, insecure deserialization (ObjectInputStream), Thymeleaf SSTI, path traversal in resource handlers
.NET: ViewState MAC disabled, SQL string concatenation, BinaryFormatter
deserialization, weak machineKey, LDAP injection in DirectorySearcher
Review for logic flaws that aren't injection-based:
Write all findings to engagement/evidence/research/source-review-<app>.md.
For each finding:
### <Finding Title>
- **Severity:** critical/high/medium/low
- **File:** <path>:<line>
- **Type:** <sqli/cmdi/auth-bypass/hardcoded-cred/etc.>
- **Description:** <what the vulnerability is>
- **Impact:** <what could go wrong>
- **Remediation:** <how to fix it>Message state-mgr with [add-vuln] for each confirmed vulnerability.
Message lead with the findings file path and one-line summary.
Focus on the files you have. Config files alone can yield creds and architecture insights. Single controller files can reveal injection points.
Prioritize: config → auth → routes/controllers → models → middleware. Use subagents aggressively for grep passes. Only read files that grep flagged.
For JavaScript: look for source maps (.map files). For PHP: check for
eval(base64_decode( patterns. For compiled languages: note in findings
and recommend decompilation.
© blacklanternsecurity, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/web/source-code-review of blacklanternsecurity/red-run.
Open the folder on GitHubat commit 050ac1f
Source Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Source Code Review this skillblacklanternsecurity/red-run | 286 | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Cherry Studio PR ReviewCherryHQ/cherry-studio | 52k | — | ~3.9k | Automated safety check: Pass | AGPL-3.0 | |
| PR Reviewjaemk/self_update | 961 | — | ~1.5k | Automated safety check: Notes | MIT | |
| PR Reviewjaemk/cached | 2.1k | — | ~2.5k | Automated safety check: Notes | MIT | |
| Cursor Composer Task DelegateChachamaru127/claude-code-harness | 3.2k | — | ~4.4k | Automated safety check: Notes | MIT |
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
CherryHQ/cherry-studio
Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.
jaemk/self_update
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.
jaemk/cached
Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
openinterpreter/openinterpreter
Run a final code review on a pull request
blacklanternsecurity/red-run
Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.
blacklanternsecurity/red-run
Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.
blacklanternsecurity/red-run
SMB share enumeration, access testing, password policy extraction, and content searching.
blacklanternsecurity/red-run
Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.
blacklanternsecurity/red-run
Bypass antivirus and EDR detection for payload delivery during exploitation.
Categories
Security-focused source code review. An agent skill from blacklanternsecurity/red-run. Source Code Review is an agent skill from blacklanternsecurity/red-run. Security-focused source code review.
Source Code Review fits situations like: application source code is available for review; tasks that involve Code review; tasks that involve Authentication.
Run `npx skills add blacklanternsecurity/red-run --skill source-code-review -a claude-code`. Or copy the skill folder (skills/web/source-code-review in blacklanternsecurity/red-run) into .claude/skills/source-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add blacklanternsecurity/red-run --skill source-code-review -a codex`. Or copy the skill folder (skills/web/source-code-review in blacklanternsecurity/red-run) into .agents/skills/source-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blacklanternsecurity/red-run --skill source-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/source-code-review, .gemini/skills/source-code-review, .github/skills/source-code-review and .opencode/skills/source-code-review in your project.
Going by SKILL.md and its folder, Source Code Review needs credentials named SECRET_KEY, AWS_ACCESS_KEY and PRIVATE_KEY. Our summary lists: A credential in AWS_ACCESS_KEY; A credential in PRIVATE_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Source Code Review is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Source Code Review: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars) and PR Review (jaemk/cached, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
blacklanternsecurity (a GitHub organization) maintains it in blacklanternsecurity/red-run, which has 286 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 28, 2026.
Source: blacklanternsecurity/red-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.