Official agent skill

Security Review

by getsentry in getsentry/skills

Security code review for vulnerabilities. An agent skill from getsentry/skills.

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Security Review

skills CLI
$ npx skills add getsentry/skills --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/skills security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
1k
Used in
4 other repos
Token cost
~2.9k tokens
SKILL.md length
696 words
Files
22 (incl. references)
Skills in repo
27
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Security code review for vulnerabilities. An agent skill from getsentry/skills.

  • Works in 6 steps: Detect Context → Load Language Guide → Load Infrastructure Guide (if applicable) → …
  • Asked to security review
  • SKILL.md covers Scope: Research vs. Reporting, Confidence Levels, Do Not Flag and Review Process, plus 3 more sections
  • Needs AWS_SECRET_ACCESS_KEY

What it does

Security Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including reference files (for example `infrastructure/docker.md`, `languages/javascript.md` and `languages/python.md`).

It sits in Security, covering Security review, Web application vulnerabilities and Code review. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Asked to security review
  • Find vulnerabilities
  • Check for security issues
  • Review code for injection

Example prompts

  • “security review”
  • “find vulnerabilities”
  • “check for security issues”
  • “/security-review”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in AWS_SECRET_ACCESS_KEY
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Task

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect Context
  2. Load Language Guide
  3. Load Infrastructure Guide (if applicable)
  4. Research Before Flagging
  5. Verify Exploitability
  6. Report HIGH Confidence Only

What it can do on your machine

Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Task

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cheatsheetseries.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_SECRET_ACCESS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 2.9k tokens when it runs, and up to ~47k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 696 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~47k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Task

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getsentry/skills at commit d18b7aa, republished under its CC-BY-SA-4.0 licence (© getsentry). 696 words, ~2,943 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.
name
security-review
description
Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
allowed-tools
Read, Grep, Glob, Bash, Task
license
LICENSE
<!--
Reference material based on OWASP Cheat Sheet Series (CC BY-SA 4.0)
https://cheatsheetseries.owasp.org/
-->

Security Review Skill

Identify exploitable security vulnerabilities in code. Report only HIGH CONFIDENCE findings—clear vulnerable patterns with attacker-controlled input.

Scope: Research vs. Reporting

CRITICAL DISTINCTION:

  • Report on: Only the specific file, diff, or code provided by the user
  • Research: The ENTIRE codebase to build confidence before reporting

Before flagging any issue, you MUST research the codebase to understand:

  • Where does this input actually come from? (Trace data flow)
  • Is there validation/sanitization elsewhere?
  • How is this configured? (Check settings, config files, middleware)
  • What framework protections exist?

Do NOT report issues based solely on pattern matching. Investigate first, then report only what you're confident is exploitable.

Confidence Levels

LevelCriteriaAction
HIGHVulnerable pattern + attacker-controlled input confirmedReport with severity
MEDIUMVulnerable pattern, input source unclearNote as "Needs verification"
LOWTheoretical, best practice, defense-in-depthDo not report

Do Not Flag

General Rules
  • Test files (unless explicitly reviewing test security)
  • Dead code, commented code, documentation strings
  • Patterns using constants or server-controlled configuration
  • Code paths that require prior authentication to reach (note the auth requirement instead)
Server-Controlled Values (NOT Attacker-Controlled)

These are configured by operators, not controlled by attackers:

SourceExampleWhy It's Safe
Django settingssettings.API_URL, settings.ALLOWED_HOSTSSet via config/env at deployment
Environment variablesos.environ.get('DATABASE_URL')Deployment configuration
Config filesconfig.yaml, app.config['KEY']Server-side files
Framework constantsdjango.conf.settings.*Not user-modifiable
Hardcoded valuesBASE_URL = "https://api.internal"Compile-time constants

SSRF Example - NOT a vulnerability:

python
# SAFE: URL comes from Django settings (server-controlled)
response = requests.get(f"{settings.SEER_AUTOFIX_URL}{path}")

SSRF Example - IS a vulnerability:

python
# VULNERABLE: URL comes from request (attacker-controlled)
response = requests.get(request.GET.get('url'))
Framework-Mitigated Patterns

Check language guides before flagging. Common false positives:

PatternWhy It's Usually Safe
Django {{ variable }}Auto-escaped by default
React {variable}Auto-escaped by default
Vue {{ variable }}Auto-escaped by default
User.objects.filter(id=input)ORM parameterizes queries
cursor.execute("...%s", (input,))Parameterized query
innerHTML = "<b>Loading...</b>"Constant string, no user input

Only flag these when:

  • Django: {{ var|safe }}, {% autoescape off %}, mark_safe(user_input)
  • React: dangerouslySetInnerHTML={{__html: userInput}}
  • Vue: v-html="userInput"
  • ORM: .raw(), .extra(), RawSQL() with string interpolation

Review Process

1. Detect Context

What type of code am I reviewing?

Code TypeLoad These References
API endpoints, routesauthorization.md, authentication.md, injection.md
Frontend, templatesxss.md, csrf.md
File handling, uploadsfile-security.md
Crypto, secrets, tokenscryptography.md, data-protection.md
Data serializationdeserialization.md
External requestsssrf.md
Business workflowsbusiness-logic.md
GraphQL, REST designapi-security.md
Config, headers, CORSmisconfiguration.md
CI/CD, dependenciessupply-chain.md
Error handlingerror-handling.md
Audit, logginglogging.md
2. Load Language Guide

Based on file extension or imports:

IndicatorsGuide
.py, django, flask, fastapilanguages/python.md
.js, .ts, express, react, vue, nextlanguages/javascript.md
.go, go.modlanguages/go.md
.rs, Cargo.tomllanguages/rust.md
.java, spring, @Controllerlanguages/java.md
3. Load Infrastructure Guide (if applicable)
File TypeGuide
Dockerfile, .dockerignoreinfrastructure/docker.md
K8s manifests, Helm chartsinfrastructure/kubernetes.md
.tf, Terraforminfrastructure/terraform.md
GitHub Actions, .gitlab-ci.ymlinfrastructure/ci-cd.md
AWS/GCP/Azure configs, IAMinfrastructure/cloud.md
Show full SKILL.md (274 more words)Show less
4. Research Before Flagging

For each potential issue, research the codebase to build confidence:

  • Where does this value actually come from? Trace the data flow.
  • Is it configured at deployment (settings, env vars) or from user input?
  • Is there validation, sanitization, or allowlisting elsewhere?
  • What framework protections apply?

Only report issues where you have HIGH confidence after understanding the broader context.

5. Verify Exploitability

For each potential finding, confirm:

Is the input attacker-controlled?

Attacker-Controlled (Investigate)Server-Controlled (Usually Safe)
request.GET, request.POST, request.argssettings.X, app.config['X']
request.json, request.data, request.bodyos.environ.get('X')
request.headers (most headers)Hardcoded constants
request.cookies (unsigned)Internal service URLs from config
URL path segments: /users/<id>/Database content from admin/system
File uploads (content and names)Signed session data
Database content from other usersFramework settings
WebSocket messages

Does the framework mitigate this?

  • Check language guide for auto-escaping, parameterization
  • Check for middleware/decorators that sanitize

Is there validation upstream?

  • Input validation before this code
  • Sanitization libraries (DOMPurify, bleach, etc.)
6. Report HIGH Confidence Only

Skip theoretical issues. Report only what you've confirmed is exploitable after research.


Severity Classification

SeverityImpactExamples
CriticalDirect exploit, severe impact, no auth requiredRCE, SQL injection to data, auth bypass, hardcoded secrets
HighExploitable with conditions, significant impactStored XSS, SSRF to metadata, IDOR to sensitive data
MediumSpecific conditions required, moderate impactReflected XSS, CSRF on state-changing actions, path traversal
LowDefense-in-depth, minimal direct impactMissing headers, verbose errors, weak algorithms in non-critical context

Quick Patterns Reference

Always Flag (Critical)
eval(user_input)           # Any language
exec(user_input)           # Any language
pickle.loads(user_data)    # Python
yaml.load(user_data)       # Python (not safe_load)
unserialize($user_data)    # PHP
deserialize(user_data)     # Java ObjectInputStream
shell=True + user_input    # Python subprocess
child_process.exec(user)   # Node.js
Always Flag (High)
innerHTML = userInput              # DOM XSS
dangerouslySetInnerHTML={user}     # React XSS
v-html="userInput"                 # Vue XSS
f"SELECT * FROM x WHERE {user}"    # SQL injection
`SELECT * FROM x WHERE ${user}`    # SQL injection
os.system(f"cmd {user_input}")     # Command injection
Always Flag (Secrets)
password = "hardcoded"
api_key = "sk-..."
AWS_SECRET_ACCESS_KEY = "..."
private_key = "-----BEGIN"
Check Context First (MUST Investigate Before Flagging)
# SSRF - ONLY if URL is from user input, NOT from settings/config
requests.get(request.GET['url'])     # FLAG: User-controlled URL
requests.get(settings.API_URL)       # SAFE: Server-controlled config
requests.get(f"{settings.BASE}/{x}") # CHECK: Is 'x' user input?

# Path traversal - ONLY if path is from user input
open(request.GET['file'])            # FLAG: User-controlled path
open(settings.LOG_PATH)              # SAFE: Server-controlled config
open(f"{BASE_DIR}/{filename}")       # CHECK: Is 'filename' user input?

# Open redirect - ONLY if URL is from user input
redirect(request.GET['next'])        # FLAG: User-controlled redirect
redirect(settings.LOGIN_URL)         # SAFE: Server-controlled config

# Weak crypto - ONLY if used for security purposes
hashlib.md5(file_content)            # SAFE: File checksums, caching
hashlib.md5(password)                # FLAG: Password hashing
random.random()                      # SAFE: Non-security uses (UI, sampling)
random.random() for token            # FLAG: Security tokens need secrets module

Output Format

markdown
## Security Review: [File/Component Name]

### Summary
- **Findings**: X (Y Critical, Z High, ...)
- **Risk Level**: Critical/High/Medium/Low
- **Confidence**: High/Mixed

### Findings

#### [VULN-001] [Vulnerability Type] (Severity)
- **Location**: `file.py:123`
- **Confidence**: High
- **Issue**: [What the vulnerability is]
- **Impact**: [What an attacker could do]
- **Evidence**:
  ```python
  [Vulnerable code snippet]
  • Fix: [How to remediate]
Needs Verification
[VERIFY-001] [Potential Issue]
  • Location: file.py:456
  • Question: [What needs to be verified]

If no vulnerabilities found, state: "No high-confidence vulnerabilities identified."

---

## Reference Files

### Core Vulnerabilities (`references/`)
| File | Covers |
|------|--------|
| `injection.md` | SQL, NoSQL, OS command, LDAP, template injection |
| `xss.md` | Reflected, stored, DOM-based XSS |
| `authorization.md` | Authorization, IDOR, privilege escalation |
| `authentication.md` | Sessions, credentials, password storage |
| `cryptography.md` | Algorithms, key management, randomness |
| `deserialization.md` | Pickle, YAML, Java, PHP deserialization |
| `file-security.md` | Path traversal, uploads, XXE |
| `ssrf.md` | Server-side request forgery |
| `csrf.md` | Cross-site request forgery |
| `data-protection.md` | Secrets exposure, PII, logging |
| `api-security.md` | REST, GraphQL, mass assignment |
| `business-logic.md` | Race conditions, workflow bypass |
| `modern-threats.md` | Prototype pollution, LLM injection, WebSocket |
| `misconfiguration.md` | Headers, CORS, debug mode, defaults |
| `error-handling.md` | Fail-open, information disclosure |
| `supply-chain.md` | Dependencies, build security |
| `logging.md` | Audit failures, log injection |

### Language Guides (`languages/`)
- `python.md` - Django, Flask, FastAPI patterns
- `javascript.md` - Node, Express, React, Vue, Next.js
- `go.md` - Go-specific security patterns
- `rust.md` - Rust unsafe blocks, FFI security
- `java.md` - Spring, Java EE patterns

### Infrastructure (`infrastructure/`)
- `docker.md` - Container security
- `kubernetes.md` - K8s RBAC, secrets, policies
- `terraform.md` - IaC security
- `ci-cd.md` - Pipeline security
- `cloud.md` - AWS/GCP/Azure security

© getsentry, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 21 other files (references) in skills/security-review of getsentry/skills.

  • SKILL.md
  • LICENSE
  • infrastructure/docker.md
  • languages/javascript.md
  • languages/python.md
  • references/api-security.md
  • references/authentication.md
  • references/authorization.md
  • references/business-logic.md
  • references/cryptography.md
  • references/csrf.md
  • references/data-protection.md
  • references/deserialization.md
  • references/error-handling.md
  • references/file-security.md
  • references/injection.md
  • references/logging.md
  • references/misconfiguration.md
  • … and 4 more

Open the folder on GitHubat commit d18b7aa

Used in 4 other repositories

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in getsentry/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skillgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Security Reviewdeadlock-mod-manager/deadlock-mod-manager574—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    SecurityAuto-check: notes
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    574 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes

More from getsentry/skills

All 27 skills in this repo
  • Gh Review Requests

    getsentry/skills

    Official

    Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.

    1k GitHub starsUsed in 4 repos~621 tokens
    Auto-check: notes
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check: warnings
  • Skill Writer

    getsentry/skills

    Official

    Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.

    1k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check: notes
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    Auto-check: notes
  • Code Simplifier

    getsentry/skills

    Official

    Simplifies and refines code for clarity, consistency, and maintainability while preserving all functionality.

    1k GitHub starsUsed in 6 repos~991 tokens
    Auto-check passed

Categories

Questions about Security Review

What does Security Review do?

Security code review for vulnerabilities. An agent skill from getsentry/skills. Security Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. Security code review for vulnerabilities.

When should I use Security Review?

Security Review fits situations like: asked to security review; find vulnerabilities; check for security issues; review code for injection.

How do I install Security Review in Claude Code?

Run `npx skills add getsentry/skills --skill security-review -a claude-code`. Or copy the skill folder (skills/security-review in getsentry/skills) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add getsentry/skills --skill security-review -a codex`. Or copy the skill folder (skills/security-review in getsentry/skills) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

Going by SKILL.md and its folder, Security Review needs credentials named AWS_SECRET_ACCESS_KEY. Our summary lists: Python 3; Node.js; Docker; A credential in AWS_SECRET_ACCESS_KEY. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Task.

Does Security Review access the network?

SKILL.md names 1 domain. As links in the text: cheatsheetseries.owasp.org. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the CC-BY-SA-4.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 44k tokens, read only when the agent opens those files.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Review (deadlock-mod-manager/deadlock-mod-manager, 574 stars) and Code Security (semgrep/skills, 322 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,038 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.

Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.