Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

Apache-2.0Auto-check passedSecurity

Install Security Reviewer

skills CLI
$ npx skills add foryourhealth111-pixel/Vibe-Skills --skill security-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install foryourhealth111-pixel/Vibe-Skills security-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/foryourhealth111-pixel/Vibe-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/bundled/skills/security-reviewer .claude/skills/security-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-reviewer
GitHub stars
3.6k
Token cost
~523 tokens
SKILL.md length
220 words
Files
1
Skills in repo
81
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Routing Boundary, Security Review Workflow and Vibe Integration
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Security review

What it does

Security Reviewer is an agent skill from foryourhealth111-pixel/Vibe-Skills. Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review.

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Security review and Code review. The repository describes itself as: Intelligent Skill routing and workflow orchestration for AI agents — +21.12 pp reward, −29.6% tokens on SkillsBench with DeepSeekV4Flash-VE. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Security review
  • Tasks that involve Code review

Example prompts

  • “/security-reviewer”

What it can do on your machine

Read from SKILL.md and the folder at commit ddcaa2a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Reviewer loads about 523 tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~523

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from foryourhealth111-pixel/Vibe-Skills at commit ddcaa2a, republished under its Apache-2.0 licence (© foryourhealth111-pixel). 220 words, ~523 tokens.

Download SKILL.mdSave it as .claude/skills/security-reviewer/SKILL.md (or your agent's skills folder).
name
security-reviewer
description
Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review.

security-reviewer (Codex Compatibility)

Use this skill after code changes that touch input handling, auth, APIs, data access, uploads, payments, or external integrations.

Routing Boundary

Use this skill when security is the main question:

  • OWASP/security audit/security review
  • secret leak, token exposure, unsafe logging
  • auth bypass, authorization gaps, session/token handling
  • injection, XSS, SSRF, unsafe file upload or command execution

Do not use this as the default owner for ordinary maintainability review. If security is only one item in a general PR review, code-reviewer can flag it, but explicit security-audit wording should route here.

Security Review Workflow

  1. Initial Scan
  • Locate auth, API endpoints, DB queries, file handling, and external calls.
  • Check for hardcoded secrets and unsafe config defaults.
  1. OWASP-Oriented Checks
  • Injection: parameterized queries, sanitized inputs.
  • AuthZ/AuthN: enforce authorization per route, secure session/token handling.
  • Data exposure: secrets/PII protection and safe logging.
  • XSS/SSRF: output encoding, URL allowlist, no blind fetch of user URLs.
  • Dependency risk: audit vulnerable dependencies.
  1. High-Risk Pattern Audit
  • Hardcoded secrets/tokens
  • Command execution with user input
  • SQL string concatenation
  • Missing auth check
  • Missing rate limiting on sensitive endpoints
  • Unsafe crypto/password handling
  1. Remediation Output
  • Severity (CRITICAL/HIGH/MEDIUM/LOW)
  • Evidence (file + line + risk)
  • Concrete fix proposal
  • Verification steps after fix

Vibe Integration

  • Security gate skill usable at any grade.
  • Pair with security-best-practices for language/framework-specific guidance.
  • Pair with code-reviewer for combined correctness + security review.

© foryourhealth111-pixel, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in bundled/skills/security-reviewer of foryourhealth111-pixel/Vibe-Skills.

Open the folder on GitHubat commit ddcaa2a

Compare with similar skills

Security Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Reviewer this skillforyourhealth111-pixel/Vibe-Skills3.6k—~523Automated safety check: PassApache-2.0
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Security Reviewdeadlock-mod-manager/deadlock-mod-manager478—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Security Auditorpavel-molyanov/molyanov-ai-dev297—~566Automated safety check: PassMIT

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    SecurityAuto-check: notes
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    478 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Auditor

    pavel-molyanov/molyanov-ai-dev

    Analyzes changed security boundaries against applicable OWASP risks and project contracts.

    297 GitHub stars~566 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

    239 GitHub stars~5.8k tokensUpdated yesterday
    SecurityAuto-check passed

More from foryourhealth111-pixel/Vibe-Skills

All 81 skills in this repo
  • Market Research Reports

    foryourhealth111-pixel/Vibe-Skills

    Produces long consulting-style market research and industry reports covering market sizing, competitive landscape, market entry and investment theses.

    3.6k GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Academic Venue Templates

    foryourhealth111-pixel/Vibe-Skills

    Supplies venue-specific LaTeX templates and formatting rules for journals, conferences and posters, and checks a manuscript against page limits and submission requirements.

    3.6k GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Digital Brain

    foryourhealth111-pixel/Vibe-Skills

    This skill should be used when the user asks to "write a post", "check my voice", "look up contact", "prepare for meeting", "weekly review", "track goals", or mentions personal brand, content…

    3.6k GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Smart File Writer

    foryourhealth111-pixel/Vibe-Skills

    Diagnoses why a file write failed (permissions, disk space, path length, locks, read-only mounts) before retrying, instead of repeating the same call blindly.

    3.6k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Automated Video Studio

    foryourhealth111-pixel/Vibe-Skills

    Turns footage, audio and a storyboard plan into a finished short video with FFmpeg jump-cuts, subtitle burn-in and a final polish pass.

    3.6k GitHub stars~838 tokensUpdated 1 mo ago
    Auto-check passed
  • Citation Management

    foryourhealth111-pixel/Vibe-Skills

    Turns DOIs, PMIDs and arXiv IDs into clean BibTeX, searches Google Scholar and PubMed, and checks and deduplicates a reference list.

    3.6k GitHub stars~7.6k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Security Reviewer

What does Security Reviewer do?

Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Security Reviewer is an agent skill from foryourhealth111-pixel/Vibe-Skills. Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

When should I use Security Reviewer?

Security Reviewer fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review; tasks that involve Code review.

How do I install Security Reviewer in Claude Code?

Run `npx skills add foryourhealth111-pixel/Vibe-Skills --skill security-reviewer -a claude-code`. Or copy the skill folder (bundled/skills/security-reviewer in foryourhealth111-pixel/Vibe-Skills) into .claude/skills/security-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Security Reviewer in Codex?

Run `npx skills add foryourhealth111-pixel/Vibe-Skills --skill security-reviewer -a codex`. Or copy the skill folder (bundled/skills/security-reviewer in foryourhealth111-pixel/Vibe-Skills) into .agents/skills/security-reviewer in your project. Codex loads it when a task matches its description.

Can I use Security Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add foryourhealth111-pixel/Vibe-Skills --skill security-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-reviewer, .gemini/skills/security-reviewer, .github/skills/security-reviewer and .opencode/skills/security-reviewer in your project.

What does Security Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Reviewer is instructions for the agent only.

Does Security Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Reviewer use?

Security Reviewer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Reviewer use?

About 523 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Reviewer?

Skills that share tags, products or a category with Security Reviewer: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Security Review (getsentry/skills, 1k stars), Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Security Review (deadlock-mod-manager/deadlock-mod-manager, 478 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Reviewer?

foryourhealth111-pixel (a GitHub user) maintains it in foryourhealth111-pixel/Vibe-Skills, which has 3,627 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on August 31, 2026.

Source: foryourhealth111-pixel/Vibe-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.