Agent skill

Secure Code Review

by Hack23 in Hack23/cia

Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

Apache-2.0Auto-check passedSecurity

Install Secure Code Review

skills CLI
$ npx skills add Hack23/cia --skill secure-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia secure-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/secure-code-review .claude/skills/secure-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-code-review
GitHub stars
239
Token cost
~5.8k tokens
SKILL.md length
1,025 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

  • Works in 4 steps: Pre-Review Setup → Manual Code Review → Document Findings → …
  • Tasks that involve Security review
  • SKILL.md covers Purpose, When to Use This Skill, Decision Tree and OWASP Top 10 Security Review…, plus 8 more sections
  • Calls mvn and gh

What it does

Secure Code Review is an agent skill from Hack23/cia. Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Web application vulnerabilities and Code review. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Code review

Example prompts

  • “/secure-code-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Pre-Review Setup
  2. Manual Code Review
  3. Document Findings
  4. Request Changes or Approve

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • owasp.org
    • cwe.mitre.org
    • sans.org
    • iso.org
    • csrc.nist.gov
    • codeql.github.com
    • sonarcloud.io
    • find-sec-bugs.github.io
    • docs.spring.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure Code Review loads about 5.8k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,025 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 1,025 words, ~5,798 tokens.

Download SKILL.mdSave it as .claude/skills/secure-code-review/SKILL.md (or your agent's skills folder).
name
secure-code-review
description
Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy
license
Apache-2.0

Secure Code Review Skill

Purpose

This skill provides strategic guidance for conducting thorough security code reviews that identify vulnerabilities before they reach production. It implements defense-in-depth principles aligned with OWASP Top 10, SANS Top 25, and Hack23 ISMS Secure Development Policy.

When to Use This Skill

Apply this skill when:

  • ✅ Reviewing pull requests before merge
  • ✅ Conducting periodic security audits of existing code
  • ✅ Implementing new features that handle sensitive data
  • ✅ Integrating third-party libraries or APIs
  • ✅ Refactoring authentication/authorization logic
  • ✅ Before major releases or production deployments
  • ✅ After security incidents or vulnerability disclosures

Do NOT use for:

  • ❌ General code style reviews (use code-quality-checks skill)
  • ❌ Performance optimization (different concern)
  • ❌ Business logic validation (functional testing)

Decision Tree

START: Code Review Required
    │
    ├─→ Does code handle user input?
    │   ├─→ YES → Apply Input Validation Checklist
    │   └─→ NO → Continue
    │
    ├─→ Does code access database?
    │   ├─→ YES → Apply SQL Injection Prevention
    │   └─→ NO → Continue
    │
    ├─→ Does code handle authentication/authorization?
    │   ├─→ YES → Apply Authentication Security Checklist
    │   └─→ NO → Continue
    │
    ├─→ Does code process sensitive data?
    │   ├─→ YES → Apply Data Protection Checklist
    │   └─→ NO → Continue
    │
    ├─→ Does code interact with external systems?
    │   ├─→ YES → Apply API Security Checklist
    │   └─→ NO → Continue
    │
    └─→ Run SAST tools (SonarCloud, CodeQL)
        └─→ Document findings and mitigation

OWASP Top 10 Security Review Checklist

A01:2021 – Broken Access Control

What to Check:

  • ✅ Verify authorization checks exist before resource access
  • ✅ Ensure users cannot access resources outside their permissions
  • ✅ Check for insecure direct object references (IDOR)
  • ✅ Validate that horizontal and vertical privilege escalation is prevented
  • ✅ Confirm Spring Security annotations (@PreAuthorize, @Secured) are correctly applied

Code Patterns:

✅ SECURE - Proper Authorization Check:

java
@Service
public class DocumentService {
    @Autowired
    private SecurityContext securityContext;
    
    @PreAuthorize("hasRole('USER')")
    public Document getDocument(Long documentId) {
        Document doc = documentRepository.findById(documentId)
            .orElseThrow(() -> new ResourceNotFoundException("Document not found"));
        
        // Verify ownership before returning
        if (!doc.getOwnerId().equals(getCurrentUserId())) {
            throw new AccessDeniedException("Cannot access document owned by another user");
        }
        
        return doc;
    }
}

❌ INSECURE - Missing Authorization:

java
// BAD: No authorization check, anyone can access any document
@GetMapping("/documents/{id}")
public Document getDocument(@PathVariable Long id) {
    return documentRepository.findById(id).orElse(null);
}
A02:2021 – Cryptographic Failures

What to Check:

  • ✅ Verify sensitive data is encrypted at rest and in transit
  • ✅ Ensure strong encryption algorithms (AES-256, RSA-2048+)
  • ✅ Check that passwords are hashed with bcrypt/argon2 (never plain text)
  • ✅ Validate TLS 1.2+ is enforced for all connections
  • ✅ Confirm encryption keys are managed securely (never hardcoded)

Code Patterns:

✅ SECURE - Proper Password Hashing:

java
@Service
public class UserService {
    @Autowired
    private PasswordEncoder passwordEncoder; // BCryptPasswordEncoder
    
    public void createUser(String username, String password) {
        String hashedPassword = passwordEncoder.encode(password);
        User user = new User(username, hashedPassword);
        userRepository.save(user);
    }
    
    public boolean verifyPassword(String rawPassword, String hashedPassword) {
        return passwordEncoder.matches(rawPassword, hashedPassword);
    }
}

❌ INSECURE - Plain Text Password:

java
// BAD: Storing passwords in plain text
public void createUser(String username, String password) {
    User user = new User(username, password); // NEVER DO THIS
    userRepository.save(user);
}
A03:2021 – Injection

What to Check:

  • ✅ All SQL queries use parameterized statements or JPA criteria queries
  • ✅ User input is validated before use in queries
  • ✅ Command injection is prevented (no Runtime.exec with user input)
  • ✅ LDAP, XML, and OS command injection vectors are addressed
  • ✅ ORM queries are not constructed with string concatenation

Code Patterns:

✅ SECURE - Parameterized Query:

java
@Repository
public interface PoliticianRepository extends JpaRepository<Politician, Long> {
    // JPA query with named parameter - safe from SQL injection
    @Query("SELECT p FROM Politician p WHERE p.firstName = :firstName AND p.lastName = :lastName")
    List<Politician> findByName(@Param("firstName") String firstName, 
                                @Param("lastName") String lastName);
}

// Using JPA Criteria API - also safe
public List<Politician> searchPoliticians(String searchTerm) {
    CriteriaBuilder cb = entityManager.getCriteriaBuilder();
    CriteriaQuery<Politician> query = cb.createQuery(Politician.class);
    Root<Politician> politician = query.from(Politician.class);
    
    query.where(cb.like(politician.get("firstName"), "%" + searchTerm + "%"));
    return entityManager.createQuery(query).getResultList();
}

❌ INSECURE - SQL Injection Vulnerable:

java
// BAD: String concatenation in query
@Query(value = "SELECT * FROM politician WHERE first_name = '" + firstName + "'", 
       nativeQuery = true)
List<Politician> findByName(String firstName); // SQL INJECTION RISK!

// BAD: Direct JDBC with concatenation
public List<Politician> search(String name) {
    String sql = "SELECT * FROM politician WHERE name = '" + name + "'";
    return jdbcTemplate.query(sql, new PoliticianMapper()); // VULNERABLE!
}
A04:2021 – Insecure Design

What to Check:

  • ✅ Security requirements defined before implementation
  • ✅ Threat modeling completed for sensitive features
  • ✅ Security controls are built into the architecture
  • ✅ Rate limiting implemented for sensitive operations
  • ✅ Business logic flaws identified and mitigated

Secure Design Principles:

java
// Example: Rate limiting for login attempts
@Service
public class LoginService {
    private static final int MAX_ATTEMPTS = 5;
    private static final Duration LOCKOUT_DURATION = Duration.ofMinutes(15);
    
    private final LoadingCache<String, Integer> loginAttempts = CacheBuilder.newBuilder()
        .expireAfterWrite(LOCKOUT_DURATION)
        .build(new CacheLoader<String, Integer>() {
            public Integer load(String key) {
                return 0;
            }
        });
    
    public void login(String username, String password) {
        // Check if account is locked
        int attempts = loginAttempts.get(username);
        if (attempts >= MAX_ATTEMPTS) {
            throw new AccountLockedException(
                "Account locked due to too many failed attempts. Try again in 15 minutes.");
        }
        
        // Attempt authentication
        boolean authenticated = authenticate(username, password);
        
        if (!authenticated) {
            loginAttempts.put(username, attempts + 1);
            throw new BadCredentialsException("Invalid credentials");
        }
        
        // Success - reset counter
        loginAttempts.invalidate(username);
    }
}
A05:2021 – Security Misconfiguration

What to Check:

  • ✅ Default credentials are changed
  • ✅ Error messages don't leak sensitive information
  • ✅ Debug mode disabled in production
  • ✅ Unnecessary features/services are disabled
  • ✅ Security headers configured (CSP, HSTS, X-Frame-Options)
  • ✅ Dependency versions are up to date

Configuration Checklist:

✅ SECURE - Production Configuration:

yaml
# application-production.yml
spring:
  profiles:
    active: production
  
  # Disable debug endpoints
  boot:
    admin:
      client:
        enabled: false
  
  # Secure session management
  session:
    timeout: 30m
    cookie:
      secure: true
      http-only: true
      same-site: strict
  
  # Hide implementation details
  mvc:
    throw-exception-if-no-handler-found: true
  resources:
    add-mappings: false

# Security headers
server:
  error:
    include-message: never
    include-stacktrace: never
    include-exception: false

❌ INSECURE - Development Settings in Production:

yaml
# BAD: Debug enabled in production
spring:
  profiles:
    active: development
  
  # Exposes sensitive endpoints
  boot:
    admin:
      client:
        enabled: true
  
  # Leak stack traces
server:
  error:
    include-stacktrace: always
    include-exception: true
A06:2021 – Vulnerable and Outdated Components

What to Check:

  • ✅ All dependencies scanned with OWASP Dependency-Check
  • ✅ No dependencies with known high/critical CVEs
  • ✅ Dependencies are from trusted sources
  • ✅ Unused dependencies are removed
  • ✅ Security patches applied promptly

Maven Security Check:

bash
# Run OWASP Dependency Check before adding new dependencies
mvn org.owasp:dependency-check-maven:check

# Review the report
ls -la target/dependency-check-report.html

# Fail build on high severity vulnerabilities
mvn verify -Dowasp.failOnCVSS=7

pom.xml Best Practices:

xml
<!-- Use dependencyManagement to control versions -->
<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>org.springframework</groupId>
            <artifactId>spring-framework-bom</artifactId>
            <version>5.3.34</version>
            <type>pom</type>
            <scope>import</scope>
        </dependency>
    </dependencies>
</dependencyManagement>

<!-- Enable OWASP Dependency Check -->
<plugin>
    <groupId>org.owasp</groupId>
    <artifactId>dependency-check-maven</artifactId>
    <version>9.0.7</version>
    <configuration>
        <failBuildOnCVSS>7</failBuildOnCVSS>
        <suppressionFiles>
            <suppressionFile>dependency-check-suppressions.xml</suppressionFile>
        </suppressionFiles>
    </configuration>
</plugin>
A07:2021 – Identification and Authentication Failures

What to Check:

  • ✅ Multi-factor authentication implemented for sensitive operations
  • ✅ Session management is secure (secure cookies, timeout)
  • ✅ Password requirements enforce strong passwords
  • ✅ Credential stuffing protection (rate limiting, CAPTCHA)
  • ✅ Session fixation attacks prevented

Code Patterns:

✅ SECURE - Spring Security Configuration:

java
@Configuration
@EnableWebSecurity
public class SecurityConfig {
    
    @Bean
    public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/public/**").permitAll()
                .requestMatchers("/admin/**").hasRole("ADMIN")
                .anyRequest().authenticated()
            )
            .formLogin(form -> form
                .loginPage("/login")
                .failureHandler(authenticationFailureHandler())
                .successHandler(authenticationSuccessHandler())
            )
            .logout(logout -> logout
                .logoutSuccessUrl("/login?logout")
                .invalidateHttpSession(true)
                .deleteCookies("JSESSIONID")
            )
            .sessionManagement(session -> session
                .sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED)
                .maximumSessions(1)
                .expiredUrl("/login?expired")
            )
            .csrf(csrf -> csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()));
        
        return http.build();
    }
    
    @Bean
    public PasswordEncoder passwordEncoder() {
        // BCrypt with strength 12
        return new BCryptPasswordEncoder(12);
    }
}
A08:2021 – Software and Data Integrity Failures

What to Check:

  • ✅ Deserialization of untrusted data is prevented
  • ✅ Code signing and integrity verification in CI/CD
  • ✅ Dependency checksums verified
  • ✅ No auto-updates without integrity verification
  • ✅ Git commits are signed

Secure Deserialization:

java
// Use safe deserialization with explicit type validation
@Bean
public ObjectMapper objectMapper() {
    ObjectMapper mapper = new ObjectMapper();
    
    // Do NOT use activateDefaultTyping for untrusted input
    // If polymorphism is required, use @JsonTypeInfo on specific DTOs
    // with a strict allowlist-based PolymorphicTypeValidator
    
    // Adjust serialization behavior if needed
    mapper.disable(SerializationFeature.FAIL_ON_EMPTY_BEANS);
    // Keep FAIL_ON_UNKNOWN_PROPERTIES enabled by default to catch unexpected/malicious fields
    
    return mapper;
}
A09:2021 – Security Logging and Monitoring Failures

What to Check:

  • ✅ Authentication/authorization failures are logged
  • ✅ High-value transactions are audited
  • ✅ Logs don't contain sensitive data (passwords, tokens)
  • ✅ Log injection attacks prevented
  • ✅ Alerting configured for suspicious activities

Secure Logging Pattern:

java
@Component
public class SecurityAuditLogger {
    private static final Logger auditLog = LoggerFactory.getLogger("SECURITY_AUDIT");
    
    public void logAuthenticationSuccess(String username, String ipAddress) {
        auditLog.info("Authentication successful - User: {}, IP: {}", 
            sanitizeForLog(username), 
            sanitizeForLog(ipAddress));
    }
    
    public void logAuthenticationFailure(String username, String ipAddress, String reason) {
        auditLog.warn("Authentication failed - User: {}, IP: {}, Reason: {}", 
            sanitizeForLog(username), 
            sanitizeForLog(ipAddress),
            reason);
    }
    
    public void logAccessDenied(String username, String resource) {
        auditLog.warn("Access denied - User: {}, Resource: {}", 
            sanitizeForLog(username), 
            sanitizeForLog(resource));
    }
    
    // Prevent log injection
    private String sanitizeForLog(String input) {
        if (input == null) return "null";
        return input.replaceAll("[\n\r\t]", "_");
    }
}
A10:2021 – Server-Side Request Forgery (SSRF)

What to Check:

  • ✅ URLs from user input are validated against allowlist
  • ✅ Network segmentation prevents access to internal resources
  • ✅ DNS rebinding attacks prevented
  • ✅ Disable unused URL schemas (file://, gopher://)

SSRF Prevention:

java
@Service
public class ExternalDataService {
    private static final Set<String> ALLOWED_HOSTS = Set.of(
        "api.riksdagen.se",
        "api.worldbank.org",
        "data.val.se"
    );
    
    public String fetchExternalData(String url) throws IOException {
        URL parsedUrl;
        try {
            parsedUrl = new URL(url);
        } catch (MalformedURLException e) {
            throw new IllegalArgumentException("Invalid URL", e);
        }
        
        // Validate protocol
        if (!parsedUrl.getProtocol().equals("https")) {
            throw new IllegalArgumentException("Only HTTPS URLs allowed");
        }
        
        // Validate host against allowlist
        if (!ALLOWED_HOSTS.contains(parsedUrl.getHost())) {
            throw new IllegalArgumentException("Host not in allowlist: " + parsedUrl.getHost());
        }
        
        // Fetch data with timeout
        HttpURLConnection conn = (HttpURLConnection) parsedUrl.openConnection();
        conn.setConnectTimeout(5000);
        conn.setReadTimeout(5000);
        
        return IOUtils.toString(conn.getInputStream(), StandardCharsets.UTF_8);
    }
}

SAST/DAST Integration

CodeQL Configuration

Ensure .github/workflows/codeql.yml includes:

yaml
name: "CodeQL Security Analysis"
on:
  push:
    branches: [ main, develop ]
  pull_request:
    branches: [ main ]
  schedule:
    - cron: '0 0 * * 0' # Weekly scan

jobs:
  analyze:
    name: Analyze
    runs-on: ubuntu-latest
    permissions:
      actions: read
      contents: read
      security-events: write
    
    steps:
    - name: Checkout repository
      uses: actions/checkout@v4
    
    - name: Initialize CodeQL
      uses: github/codeql-action/init@v3
      with:
        languages: java
        queries: security-and-quality
    
    - name: Build
      run: mvn clean compile -DskipTests
    
    - name: Perform CodeQL Analysis
      uses: github/codeql-action/analyze@v3
SonarCloud Quality Gates

Required quality gate thresholds:

  • ✅ Security Rating: A (0 vulnerabilities)
  • ✅ Security Hotspots: All reviewed
  • ✅ Coverage: > 80%
  • ✅ Duplications: < 3%
  • ✅ Maintainability Rating: A

ISMS Compliance Mapping

ISO 27001:2022 Controls
  • A.8.1 - User Endpoint Devices: Secure code prevents endpoint exploitation
  • A.8.2 - Privileged Access Rights: Authorization checks enforce least privilege
  • A.8.3 - Information Access Restriction: Access control mechanisms properly implemented
  • A.8.8 - Management of Technical Vulnerabilities: Vulnerability scanning and remediation
  • A.8.28 - Secure Coding: Adherence to secure coding standards
Show full SKILL.md (442 more words)Show less
NIST Cybersecurity Framework
  • PR.DS-6: Integrity checking mechanisms in place
  • PR.IP-1: Baseline security configurations
  • DE.CM-4: Malicious code detected
  • RS.AN-5: Processes for vulnerability response
CIS Controls v8
  • Control 16.11: Remediate detected vulnerabilities
  • Control 4.1: Establish and maintain secure configuration
  • Control 16.1: Application software security
  • Control 16.14: Establish process for accepting application risk

Hack23 ISMS Policy References

Review these policies before code review:

Review Workflow

  1. Pre-Review Setup

    bash
    # Checkout PR branch
    gh pr checkout <PR-NUMBER>
    
    # Run security scans
    mvn clean verify
    mvn org.owasp:dependency-check-maven:check
    
    # Review CodeQL alerts
    gh api /repos/Hack23/cia/code-scanning/alerts --jq '.[] | select(.state=="open")'
  2. Manual Code Review

    • Apply OWASP Top 10 checklist to changed files
    • Review authentication/authorization changes
    • Verify input validation on all user inputs
    • Check for hardcoded secrets or credentials
    • Validate error handling doesn't leak sensitive info
  3. Document Findings

    markdown
    ## Security Review Findings
    
    ### Critical Issues
    - [ ] SQL injection in `PoliticianController.search()` - line 45
    
    ### High Priority
    - [ ] Missing authorization check in `DocumentService.getDocument()`
    
    ### Medium Priority
    - [ ] Weak password validation in `UserRegistrationForm`
    
    ### Low Priority / Informational
    - [ ] Consider adding rate limiting to login endpoint
  4. Request Changes or Approve

    • If critical/high issues found: Request changes with detailed explanation
    • If only medium/low: Approve with recommendations
    • Always provide actionable feedback with code examples

Security Review Exit Criteria

Before approving a PR, verify:

  • ✅ No new CodeQL alerts introduced
  • ✅ SonarCloud quality gate passed
  • ✅ OWASP Dependency Check shows no new high/critical CVEs
  • ✅ All authentication/authorization logic reviewed
  • ✅ Input validation present on all user inputs
  • ✅ No secrets or credentials in code
  • ✅ Security test cases added for sensitive features
  • ✅ Documentation updated if security architecture changed

Hack23 ISMS Policy References

Secure Development Framework:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

CIA Platform Architecture References

References

Official Standards
Tools & Frameworks

Success Metrics

Track these KPIs to measure secure code review effectiveness:

  • Zero security vulnerabilities in production
  • Mean time to remediate (MTTR) for vulnerabilities < 30 days
  • 100% of PRs pass security review before merge
  • Decrease in vulnerability count over time
  • Security training completion rate for all contributors

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/secure-code-review of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Secure Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure Code Review this skillHack23/cia239—~5.8kAutomated safety check: PassApache-2.0
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Trailmark Graph Evolutiontrailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Psalm Security Analysiscachethq/core230—~4.7kAutomated safety check: PassCustom licence

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    473 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Secure Code Review

What does Secure Code Review do?

Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy. Secure Code Review is an agent skill from Hack23/cia.

When should I use Secure Code Review?

Secure Code Review fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities; tasks that involve Code review.

How do I install Secure Code Review in Claude Code?

Run `npx skills add Hack23/cia --skill secure-code-review -a claude-code`. Or copy the skill folder (.github/skills/secure-code-review in Hack23/cia) into .claude/skills/secure-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Secure Code Review in Codex?

Run `npx skills add Hack23/cia --skill secure-code-review -a codex`. Or copy the skill folder (.github/skills/secure-code-review in Hack23/cia) into .agents/skills/secure-code-review in your project. Codex loads it when a task matches its description.

Can I use Secure Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill secure-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-code-review, .gemini/skills/secure-code-review, .github/skills/secure-code-review and .opencode/skills/secure-code-review in your project.

What does Secure Code Review need to run?

Going by SKILL.md and its folder, Secure Code Review needs the command-line tools its instructions call (mvn and gh).

Does Secure Code Review access the network?

SKILL.md names 10 domains. As links in the text: github.com, owasp.org, cwe.mitre.org, sans.org, iso.org, csrc.nist.gov, codeql.github.com, sonarcloud.io, find-sec-bugs.github.io and docs.spring.io. This is read from the text; nothing was executed.

Is Secure Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure Code Review use?

Secure Code Review is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secure Code Review use?

About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure Code Review?

Skills that share tags, products or a category with Secure Code Review: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Trailmark Graph Evolution (trailofbits/skills, 7.4k stars), Security Review (getsentry/skills, 1k stars) and Cyber Neo (Hainrixz/cyber-neo, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure Code Review?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.