Agent skill

Codewhale Security Review

by codewhale-hq in codewhale-hq/Codewhale

Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

MITAuto-check passedSecurity

Install Codewhale Security Review

skills CLI
$ npx skills add codewhale-hq/Codewhale --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codewhale-hq/Codewhale security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/tui/assets/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
41k
Token cost
~844 tokens
SKILL.md length
441 words
Files
1
Skills in repo
63
Repo updated
First seen
Licence
MIT

At a glance

Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

  • Works in 7 steps: Map entry points and sinks. rg for the… → Authn/authz. Every mutating or sensitive… → Injection. Command lines, SQL, template… → …
  • Reviewing a diff, module or network surface for exploitable defects
  • SKILL.md covers Scope the review first, Procedure, Findings format and Recovery and limits, plus 1 more section
  • Calls git, cargo and npm

What it does

This skill aims to produce findings a reviewer can verify rather than a vibes-based pass; every finding must name the file, the reachable path that makes it real, and the fix. It starts by stating the review's boundary out loud, a diff, a module, a plugin bundle or a network surface, and naming the trust boundaries where untrusted input enters, such as HTTP handlers, MCP tool arguments or file parsers, against where authority is exercised, such as filesystem writes, network egress or credential reads. It asks for credentials only when a live path needs them and never reads secrets from the environment itself.

The procedure follows data from entry point to sink before judging it: identity and object-level authorization checks present on one path but missing on a sibling; injection across command lines, SQL, template evaluation and markup that will later render, including generated HTML or Markdown carrying repository content into a browser; secrets left in the diff, git history, logs or exported error messages; the project's own dependency audit gate, reported with actual versions and CVEs; and abuse paths such as unbounded reads, missing network timeouts and retry storms.

Every finding is traced through a real call path or a minimal proof before being reported; a finding that only looks suspicious but has no reachable path becomes a note instead. The output orders findings by severity, each with file and line, the reachable path, a short explanation and the fix, followed by a checked-and-clean list naming what was audited and cleared.

When your agent uses it

  • Reviewing a diff, module or network surface for exploitable defects
  • Checking authentication and authorization coverage across sibling code paths
  • Searching for injection risks in generated SQL, shell commands or rendered markup
  • Auditing a change for leaked secrets or unbounded resource use

Example prompts

  • “Security-review this PR's new HTTP handler for authorization and injection issues.”
  • “Trace whether this file-parsing change has a reachable path to arbitrary file writes.”
  • “Check this diff for secrets that might get logged or embedded in an export.”
  • “Review the plugin bundle's network surface for trust-boundary gaps.”

Requirements

  • A checked-out tree and the project's own test runner
  • The project's dependency audit tool, such as cargo audit or npm audit, if available

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Map entry points and sinks. rg for the handlers, deserializers,
  2. Authn/authz. Every mutating or sensitive handler checks identity and
  3. Injection. Command lines, SQL, template eval, shell expansion,
  4. Secrets. rg for token/key/secret patterns and git log -p the
  5. Dependencies. Run the project's audit gate if it exists
  6. Denial and abuse paths. Unbounded reads/allocations, missing
  7. Verify a finding before reporting it. Trace the real call path or

What it can do on your machine

Read from SKILL.md and the folder at commit 8d2fb45. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • cargo
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codewhale Security Review loads about 844 tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 441 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~844

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codewhale-hq/Codewhale at commit 8d2fb45, republished under its MIT licence (© codewhale-hq). 441 words, ~844 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
Review a change, module, or surface for exploitable defects — trust boundaries, authn/authz, injection, secret exposure, filesystem and network reach, dependency risk. Use when the user asks for a security review, audit, or vulnerability check of concrete code. Not for general code review, lint, or compliance paperwork.
invocation
model+user

Security Review

Produce findings a reviewer can verify, not a vibes pass. Every finding names the file, the reachable path that makes it real, and the fix.

Scope the review first

  • What is under review: a diff, a module, a plugin bundle, a network surface. Say the boundary out loud before reading.
  • Trust boundaries: where untrusted input enters (HTTP handlers, MCP tool args, file parsers, CLI flags, env vars, rendered content) and where authority is exercised (fs writes, network egress, process spawn, credential reads, signing).
  • Prerequisites: a checked-out tree and the project's own test runner. Ask for credentials only if a live path genuinely needs them; never read secrets from the environment or keychain yourself.

Procedure

  1. Map entry points and sinks. rg for the handlers, deserializers, and exec/fs/net calls in scope. Follow data from entry to sink before judging it.
  2. Authn/authz. Every mutating or sensitive handler checks identity and object-level authorization. Look for checks that exist on one path but not its sibling, and for checks done on the client only.
  3. Injection. Command lines, SQL, template eval, shell expansion, path joins under user influence, and markup that will render later — including generated HTML/markdown that carries repo content into a browser surface.
  4. Secrets. rg for token/key/secret patterns and git log -p the diff for credentials. Also check what gets logged or embedded in receipts, exports, or error messages.
  5. Dependencies. Run the project's audit gate if it exists (cargo audit, npm audit, osv-scanner) — report versions and CVEs, not "deps look old".
  6. Denial and abuse paths. Unbounded reads/allocations, missing timeouts on network calls, resource leaks in error paths, retry storms.
  7. Verify a finding before reporting it. Trace the real call path or write a minimal proof. A finding that "looks suspicious" but has no reachable path is a note, not a finding.
Show full SKILL.md (135 more words)Show less

Findings format

For each: severity (exploitability × impact), file:line, the reachable path, a one-paragraph explanation, and the fix. Order by severity. Then a short "checked and clean" list naming what was audited and cleared — the scope statement means something only if the clear list is honest.

Recovery and limits

  • If you cannot prove reachability, downgrade the claim and say what evidence is missing.
  • Do not claim a formal audit, certification, or absence of vulnerabilities. This review finds defects; it does not prove none exist.
  • Never fix-and-stay-quiet on a security finding in someone else's in-flight code — report it first.

Completion criteria

  • Every entry point in scope was traced to its sinks.
  • Findings carry file:line + reachability + fix; the clear list names what was actually checked.
  • Severity ordering is defensible by exploitability, not by how loudly the code smells.

© codewhale-hq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/tui/assets/skills/security-review of codewhale-hq/Codewhale.

Open the folder on GitHubat commit 8d2fb45

Compare with similar skills

Codewhale Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codewhale Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codewhale Security Review this skillcodewhale-hq/Codewhale41k—~844Automated safety check: PassMIT
Security Review ChecklistZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Agent-Core Security ChecklistopenJiuwen-ai/agent-core446—~1.7kAutomated safety check: NotesApache-2.0
Vercel Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT
Cb Security HardeningBlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT

Similar skills

  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Agent-Core Security Checklist

    openJiuwen-ai/agent-core

    A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

    446 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check: notes
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: notes
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 6 days ago
    SecurityAuto-check: notes

More from codewhale-hq/Codewhale

All 63 skills in this repo
  • Codewhale Dogfood Install

    codewhale-hq/Codewhale

    Proves a Codewhale change in the real product: a stamped release build, an atomic local install, fresh-shell verification and manual QA that automated gates cannot cover.

    41k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Codewhale Session Handoff

    codewhale-hq/Codewhale

    Writes a paste-ready handoff for the next agent session, opening with a state-check command block and separating done, suspected and blocked work.

    41k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Codewhale Landing Workflow

    codewhale-hq/Codewhale

    Decides how verified work should reach main, directly, in a worktree or on an integration branch, while keeping contributor credit and respecting merge gates.

    41k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Sub-Agent Delegation

    codewhale-hq/Codewhale

    Guides when and how to split multi-step coding, research or verification work into focused sub-agent runs while the parent keeps integration and final checks.

    41k GitHub stars~790 tokensUpdated today
    Auto-check passed
  • Codewhale Fleet Manager

    codewhale-hq/Codewhale

    Triages and manages Codewhale fleet runs and workers with typed commands, classifying failures and choosing a safe restart, resume or escalation.

    41k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • GitHub Issue Bulk Assigner

    codewhale-hq/Codewhale

    Moves a list of GitHub issues into a milestone or assigns them to owners with the gh CLI, checking each one before and after the change.

    41k GitHub stars~953 tokensUpdated today
    Auto-check passed

Categories

Questions about Codewhale Security Review

What does Codewhale Security Review do?

Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix. This skill aims to produce findings a reviewer can verify rather than a vibes-based pass; every finding must name the file, the reachable path that makes it real, and the fix. It starts by stating the review's boundary out loud, a diff, a module, a plugin bundle or a network surface, and naming the trust boundaries where untrusted input enters, such as HTTP handlers, MCP tool arguments or file parsers, against where authority is exercised, such as filesystem writes, network egress or credential reads.

When should I use Codewhale Security Review?

Codewhale Security Review fits situations like: reviewing a diff, module or network surface for exploitable defects; checking authentication and authorization coverage across sibling code paths; searching for injection risks in generated SQL, shell commands or rendered markup; auditing a change for leaked secrets or unbounded resource use.

How do I install Codewhale Security Review in Claude Code?

Run `npx skills add codewhale-hq/Codewhale --skill security-review -a claude-code`. Or copy the skill folder (crates/tui/assets/skills/security-review in codewhale-hq/Codewhale) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Codewhale Security Review in Codex?

Run `npx skills add codewhale-hq/Codewhale --skill security-review -a codex`. Or copy the skill folder (crates/tui/assets/skills/security-review in codewhale-hq/Codewhale) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Codewhale Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewhale-hq/Codewhale --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Codewhale Security Review need to run?

Going by SKILL.md and its folder, Codewhale Security Review needs the command-line tools its instructions call (git, cargo and npm). Our summary lists: A checked-out tree and the project's own test runner; The project's dependency audit tool, such as cargo audit or npm audit, if available.

Does Codewhale Security Review access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codewhale Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codewhale Security Review use?

Codewhale Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codewhale Security Review use?

About 844 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codewhale Security Review?

Skills that share tags, products or a category with Codewhale Security Review: Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars), Security Audit (jellydn/my-ai-tools, 123 stars), Agent-Core Security Checklist (openJiuwen-ai/agent-core, 446 stars) and Vercel Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codewhale Security Review?

codewhale-hq (a GitHub organization) maintains it in codewhale-hq/Codewhale, which has 41,078 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 9, 2026.

Source: codewhale-hq/Codewhale on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.