Agent skill

Source Code Review

by blacklanternsecurity in blacklanternsecurity/red-run

Security-focused source code review. An agent skill from blacklanternsecurity/red-run.

GPL-3.0Auto-check: notesDevelopment

Install Source Code Review

skills CLI
$ npx skills add blacklanternsecurity/red-run --skill source-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install blacklanternsecurity/red-run source-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web/source-code-review .claude/skills/source-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
source-code-review
GitHub stars
286
Token cost
~1.8k tokens
SKILL.md length
584 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
GPL-3.0

At a glance

Security-focused source code review. An agent skill from blacklanternsecurity/red-run.

  • Works in 7 steps: Reconnaissance (use subagent) → Secrets Discovery (use subagent) → Auth & Session Review → …
  • Application source code is available for review
  • SKILL.md covers Engagement Logging, Scope Boundary, State Management and Prerequisites, plus 8 more sections
  • Needs SECRET_KEY and AWS_ACCESS_KEY

What it does

Source Code Review is an agent skill from blacklanternsecurity/red-run. Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Authentication and Subagents. The repository describes itself as: Offensive security toolkit for Claude Code. The licence is GPL-3.0.

When your agent uses it

  • Application source code is available for review
  • Tasks that involve Code review
  • Tasks that involve Authentication

Example prompts

  • “/source-code-review”

Requirements

  • A credential in AWS_ACCESS_KEY
  • A credential in PRIVATE_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Reconnaissance (use subagent)
  2. Secrets Discovery (use subagent)
  3. Auth & Session Review
  4. Injection Surface Mapping (use subagent)
  5. Framework-Specific Checks
  6. Business Logic
  7. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 050ac1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • AWS_ACCESS_KEY
    • PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Source Code Review loads about 1.8k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:70
    - Config files (settings.py, .env, web.config, application.yml, etc.)
  • NoteMentions a .env fileSKILL.md:138
    **PHP/Laravel:** `.env` in webroot, `APP_DEBUG=true`, mass assignment

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from blacklanternsecurity/red-run at commit 050ac1f, republished under its GPL-3.0 licence (© blacklanternsecurity). 584 words, ~1,770 tokens.

Download SKILL.mdSave it as .claude/skills/source-code-review/SKILL.md (or your agent's skills folder).
name
source-code-review
description
Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
keywords
source code review, code audit, git dump, git-dumper, .git exposure, hardcoded credentials, hardcoded password, application source, code review, SAST, static…
tools
grep, read, glob
opsec
low

Source Code Review

You are a vulnerability researcher reviewing application source code for security weaknesses. Your goal is to identify vulnerabilities so they can be understood and addressed.

Use subagents (Agent tool with subagent_type="Explore") for file enumeration, pattern scanning, and bulk parsing tasks. Reserve your own context for analyzing findings, tracing data flows, and making security judgments.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

When an engagement directory exists:

  • Print [source-code-review] Activated → <target> on activation.
  • Save findings to engagement/evidence/research/source-review-<app>.md.

Scope Boundary

This skill covers static analysis of application source for security vulnerabilities. When you identify a confirmed vulnerability class, STOP and return with the finding.

Do not modify source files. Do not run the application. Analyze only.

State Management

Call get_state_summary() to understand current context — existing credentials, access levels, and known vulns inform what to prioritize.

Prerequisites

  • Application source code accessible (typically in engagement/evidence/)
  • The lead provides: source path, technology hints, context

Step 1: Reconnaissance (use subagent)

Spawn an Explore subagent to map the codebase structure:

"List all files in <source_path> grouped by type. Identify:
 - Framework (Django, Flask, Express, Spring, Laravel, .NET, etc.)
 - Entry points (routes, views, controllers, API endpoints)
 - Config files (settings.py, .env, web.config, application.yml, etc.)
 - Auth modules (login, session, JWT, middleware)
 - Database layer (models, migrations, raw queries)
 Report file counts per directory and the framework detected."

Step 2: Secrets Discovery (use subagent)

Spawn an Explore subagent to grep for hardcoded secrets — highest-value, lowest-effort pass:

"Search all files in <source_path> for hardcoded secrets. Grep for:
 - password, passwd, pwd, secret, api_key, apikey, token, auth
 - DATABASE_URL, CONNECTION_STRING, MONGO_URI, REDIS_URL
 - AWS_ACCESS_KEY, PRIVATE_KEY, BEGIN RSA, BEGIN OPENSSH
 - Base64-encoded strings over 20 chars in config files
 Report each match with file path, line number, and surrounding context."

Review the subagent's results. Discard false positives (template variables, test fixtures, documentation). For confirmed credentials:

  • Message state-mgr: [add-cred] for each
  • Note which service each credential is for

Step 3: Auth & Session Review

Read auth-related files yourself (these require security judgment):

  • Login flow — password comparison (timing-safe?), lockout logic, MFA
  • Session handling — cookie flags, token generation, session fixation
  • JWT — algorithm confusion (none/HS256 vs RS256), secret strength, claim validation
  • Role checks — are admin endpoints checking roles? Decorator/middleware gaps?
  • Password reset — predictable tokens, host header injection, rate limiting
  • Registration — mass assignment, privilege parameters in signup

Step 4: Injection Surface Mapping (use subagent)

Spawn an Explore subagent to find dangerous sinks:

"Search <source_path> for dangerous function calls. For each match report
 file, line, and the function:

 SQL: execute(, raw(, query(, cursor.execute, .extra(, $where, db.query
 Command: os.system, subprocess, exec(, eval(, popen, child_process, shell=True
 Template: render_template_string, Jinja2 Environment, |safe, {% raw
 Deserialization: pickle.loads, yaml.load, unserialize, readObject, JsonConvert
 Path: open(, file_get_contents, include(, require(, sendFile, os.path.join
 SSRF: requests.get, urllib, fetch(, HttpClient with variable URL
 XSS: innerHTML, document.write, v-html, dangerouslySetInnerHTML"

For each finding, trace the data flow yourself:

  • Does user input reach the sink without sanitization?
  • Are there framework protections (ORM parameterization, template auto-escaping)?
  • What is the severity and impact?
Show full SKILL.md (260 more words)Show less

Step 5: Framework-Specific Checks

Based on the framework detected in Step 1:

Python/Django: DEBUG = True, SECRET_KEY hardcoded, @csrf_exempt, raw SQL in views, ALLOWED_HOSTS = ['*'], pickle sessions, custom template tags

Python/Flask: app.secret_key, debug=True, Jinja2 |safe filter, render_template_string with user input, no CSRF protection

PHP/Laravel: .env in webroot, APP_DEBUG=true, mass assignment ($fillable/$guarded), blade {!! !!} unescaped, SQL in raw queries

Node/Express: eval() with user input, prototype pollution, NoSQL injection ($gt, $ne), missing helmet headers, JWT secret in source

Java/Spring: SpEL injection, actuator endpoints exposed, insecure deserialization (ObjectInputStream), Thymeleaf SSTI, path traversal in resource handlers

.NET: ViewState MAC disabled, SQL string concatenation, BinaryFormatter deserialization, weak machineKey, LDAP injection in DirectorySearcher

Step 6: Business Logic

Review for logic flaws that aren't injection-based:

  • IDOR — are object lookups filtered by the current user?
  • Race conditions — TOC/TOU in payment, voting, token generation
  • Privilege escalation — can a regular user's request include admin params?
  • Information disclosure — error messages, stack traces, debug endpoints

Step 7: Report Findings

Write all findings to engagement/evidence/research/source-review-<app>.md.

For each finding:

### <Finding Title>
- **Severity:** critical/high/medium/low
- **File:** <path>:<line>
- **Type:** <sqli/cmdi/auth-bypass/hardcoded-cred/etc.>
- **Description:** <what the vulnerability is>
- **Impact:** <what could go wrong>
- **Remediation:** <how to fix it>

Message state-mgr with [add-vuln] for each confirmed vulnerability. Message lead with the findings file path and one-line summary.

Troubleshooting

Source is partial (individual files, not full repo)

Focus on the files you have. Config files alone can yield creds and architecture insights. Single controller files can reveal injection points.

Codebase is too large (>1000 files)

Prioritize: config → auth → routes/controllers → models → middleware. Use subagents aggressively for grep passes. Only read files that grep flagged.

Obfuscated/minified code

For JavaScript: look for source maps (.map files). For PHP: check for eval(base64_decode( patterns. For compiled languages: note in findings and recommend decompilation.

© blacklanternsecurity, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/web/source-code-review of blacklanternsecurity/red-run.

Open the folder on GitHubat commit 050ac1f

Compare with similar skills

Source Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Source Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Source Code Review this skillblacklanternsecurity/red-run286—~1.8kAutomated safety check: NotesGPL-3.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0
Cherry Studio PR ReviewCherryHQ/cherry-studio52k—~3.9kAutomated safety check: PassAGPL-3.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
PR Reviewjaemk/cached2.1k—~2.5kAutomated safety check: NotesMIT
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT

Similar skills

  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    52k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/cached

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.

    2.1k GitHub stars~2.5k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes

More from blacklanternsecurity/red-run

  • Infrastructure Enumeration

    blacklanternsecurity/red-run

    Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

    286 GitHub stars~2.4k tokensUpdated 9 days ago
    Auto-check: notes
  • Kerberos Roasting

    blacklanternsecurity/red-run

    Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

    286 GitHub stars~3.5k tokensUpdated 9 days ago
    Auto-check: notes
  • Smb Enumeration

    blacklanternsecurity/red-run

    SMB share enumeration, access testing, password policy extraction, and content searching.

    286 GitHub stars~3k tokensUpdated 9 days ago
    Auto-check passed
  • Trust Attacks

    blacklanternsecurity/red-run

    Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.

    286 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check: notes
  • Av Edr Evasion

    blacklanternsecurity/red-run

    Bypass antivirus and EDR detection for payload delivery during exploitation.

    286 GitHub stars~5.4k tokensUpdated 9 days ago
    Auto-check: notes

Categories

Questions about Source Code Review

What does Source Code Review do?

Security-focused source code review. An agent skill from blacklanternsecurity/red-run. Source Code Review is an agent skill from blacklanternsecurity/red-run. Security-focused source code review.

When should I use Source Code Review?

Source Code Review fits situations like: application source code is available for review; tasks that involve Code review; tasks that involve Authentication.

How do I install Source Code Review in Claude Code?

Run `npx skills add blacklanternsecurity/red-run --skill source-code-review -a claude-code`. Or copy the skill folder (skills/web/source-code-review in blacklanternsecurity/red-run) into .claude/skills/source-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Source Code Review in Codex?

Run `npx skills add blacklanternsecurity/red-run --skill source-code-review -a codex`. Or copy the skill folder (skills/web/source-code-review in blacklanternsecurity/red-run) into .agents/skills/source-code-review in your project. Codex loads it when a task matches its description.

Can I use Source Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blacklanternsecurity/red-run --skill source-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/source-code-review, .gemini/skills/source-code-review, .github/skills/source-code-review and .opencode/skills/source-code-review in your project.

What does Source Code Review need to run?

Going by SKILL.md and its folder, Source Code Review needs credentials named SECRET_KEY, AWS_ACCESS_KEY and PRIVATE_KEY. Our summary lists: A credential in AWS_ACCESS_KEY; A credential in PRIVATE_KEY.

Does Source Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Source Code Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Source Code Review use?

Source Code Review is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Source Code Review use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Source Code Review?

Skills that share tags, products or a category with Source Code Review: GitHub Review Iteration (prisma/orm, 48k stars), Cherry Studio PR Review (CherryHQ/cherry-studio, 52k stars), PR Review (jaemk/self_update, 961 stars) and PR Review (jaemk/cached, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Source Code Review?

blacklanternsecurity (a GitHub organization) maintains it in blacklanternsecurity/red-run, which has 286 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 28, 2026.

Source: blacklanternsecurity/red-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.