Agent skill

River Review Security Audit

by hashgraph-online in hashgraph-online/awesome-codex-plugins

Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。

MITAuto-check passedSecurity

Install River Review Security Audit

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill river-review-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins river-review-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/s977043/river-review/skills/agent-skills/river-review-security-audit .claude/skills/river-review-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
river-review-security-audit
GitHub stars
1.3k
Token cost
~4.2k tokens
SKILL.md length
1,740 words
Files
2 (incl. references)
Skills in repo
716
Repo updated
First seen
Licence
MIT

At a glance

Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。

  • Works in 12 steps: Select mode and freeze scope → Reconnaissance from source only → Plan applicable attack classes → …
  • Tasks that involve Security review
  • SKILL.md covers When to Use, Modes, Non-negotiable Source-only… and Responsibilities, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

River Review Security Audit is an agent skill from hashgraph-online/awesome-codex-plugins. Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。 通常の PR セキュリティレビューとは分離し、reconnaissance、scope 固定、既存 security skill への委譲、 evidence と unresolved hypothesis、observe-only SecurityAuditCoverage、coverage critic、 structured audit artifact と repeat-run coverage を扱う。target-controlled code は実行しない。

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/attack-classes.json`).

It sits in Security, covering Security review. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/river-review-security-audit”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Select mode and freeze scope
  2. Reconnaissance from source only
  3. Plan applicable attack classes
  4. Reuse existing security skills
  5. Treat findings as evidence-grounded candidates
  6. Preserve verification boundaries
  7. Record unresolved hypotheses explicitly
  8. Record observe-only SecurityAuditCoverage
  9. Run the Security Audit Coverage Critic
  10. Reconcile coverage against a prior run
  11. Emit the structured audit artifact set
  12. Report without claiming safety

What it can do on your machine

Read from SKILL.md and the folder at commit 3e1456a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

River Review Security Audit loads about 4.2k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,740 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 3e1456a, republished under its MIT licence (© hashgraph-online). 1,740 words, ~4,172 tokens.

Download SKILL.mdSave it as .claude/skills/river-review-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
river-review-security-audit
description
Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。 通常の PR セキュリティレビューとは分離し、reconnaissance、scope 固定、既存 security skill への委譲、 evidence と unresolved hypothesis、observe-only SecurityAuditCoverage、coverage critic、 structured audit artifact と repeat-run coverage を扱う。target-controlled code は実行しない。
id
river-review-security-audit
category
midstream
phase
upstream, midstream
severity
critical
applyTo
**/*
inputContext
diff, fullFile
outputKind
summary, findings, actions, questions
tags
security, audit, entry, routing, source-only
version
0.5.0
license
MIT

Security Audit Entry

Inspired by Cloudflare's security-audit-skill, but implemented as a River Review-native entry skill rather than a vendored audit engine.

This skill is the explicit entry point for repository or subsystem security audit work. It does not replace river-review-security, the normal diff-oriented security review entry.

When to Use

Use this skill only when the user explicitly asks for a security audit beyond an ordinary PR review. Typical requests include repository-wide security audit, subsystem security audit, security assessment, or a bounded source review of a security-sensitive surface.

Do not select this skill for a generic request such as "review this PR for security". Route that request to river-review-security.

Modes

Select exactly one mode before reviewing.

  • guidance: use when the user wants methodology, planning, or an audit approach. Explain the method and constraints. Do not claim that audit work was executed.
  • focused: use when the user names a bounded subsystem, path, component, or security surface. Freeze that scope and review only source evidence inside the boundary.
  • full-audit: use only when the user explicitly requests repository-wide audit coverage. Perform repository reconnaissance and source review across the repository. Semantic coverage is observe-only and never a safety guarantee.

If the request does not clearly justify full-audit, use focused or guidance.

Non-negotiable Source-only Policy

Version 0.5.0 is source-only.

Allowed evidence collection:

  • file reads
  • repository code search
  • static diff inspection
  • repository metadata and dependency manifests
  • configuration and documentation inspection
  • static history inspection when it supports source provenance

Prohibited execution:

  • package installation or dependency fetching
  • target repository build scripts
  • target repository test commands
  • package lifecycle scripts
  • dev servers or application startup
  • browsers or emulators that execute target code
  • fuzzing or dynamic probes
  • requests to production, shared, or external endpoints
  • use of ambient credentials to reproduce a finding

If runtime evidence is required but safe execution is unavailable, keep the hypothesis unresolved. Record the blocker and the minimum validation plan instead of executing target-controlled code.

Responsibilities

This skill performs entry-level audit coordination only. It must reuse existing River Review capabilities instead of creating a second workflow engine.

text
Explicit audit request
  -> mode selection
  -> scope freeze
  -> source reconnaissance
  -> attack-class planning
  -> existing security skills
  -> candidate findings / unresolved hypotheses
  -> existing finding verification path when available
  -> observe-only SecurityAuditCoverage ledger
  -> unknown-coverage-review (security-audit profile)
  -> repeat-run coverage reconciliation (when a prior run exists)
  -> structured audit artifact set
  -> audit summary

The following responsibilities remain outside this skill:

  • generic reviewer fan-out: existing reviewer orchestration
  • ordinary PR security review: river-review-security
  • deterministic finding verification: existing verifier
  • adversarial candidate state machine: #1978 / finding-critic.mjs
  • execution coverage: #2212 Review Coverage
  • materiality and disposition: #1857 Semantic Precision
  • final Gate decision: existing deterministic Gate
  • independent final-record verification: later #2267 phase
  • sandboxed target execution: later dedicated phase

Audit Flow

1. Select mode and freeze scope

State the selected mode and the audit boundary before collecting findings. For focused, name the bounded path, subsystem, component, or trust boundary. For full-audit, state that the scope is repository-wide and source-only.

Do not silently broaden a focused audit into a repository-wide audit.

2. Reconnaissance from source only

Build a compact source map before hunting for issues. At minimum identify, when present:

  • externally reachable entry points
  • authentication and authorization boundaries
  • tenant or account boundaries
  • sensitive data stores and flows
  • privileged operations
  • external integrations
  • dependency and deployment configuration surfaces
  • browser or client trust boundaries
  • AI or agent tool boundaries

Reconnaissance is an investigation plan, not proof of safety.

3. Plan applicable attack classes

Use references/attack-classes.json as the taxonomy SSoT for audit planning. Select only classes supported by reconnaissance evidence; do not run all classes mechanically. For every applicable class, preserve the registry evidence contract:

text
principal
  -> input or action
  -> control or missing control
  -> trust boundary
  -> affected resource or principal
  -> concrete security outcome

An attack class is an investigation hypothesis, not a checklist completion badge. A class with zero findings is not automatically covered, and a non-applicable class must be explained rather than silently omitted.

4. Reuse existing security skills

Use existing River Review skills when their domain applies.

  • security-basic: application security patterns such as injection, unsafe sinks, secrets, validation, and common application risks.
  • security-privacy-design: privacy and sensitive-data design such as retention, deletion, encryption, residency, and privacy rights.
  • trust-boundaries-authz: trust boundaries and authorization responsibilities, claims propagation, and tenant boundaries.
  • river-review-security: ordinary changed-code security review. Use only when the task is actually diff-oriented rather than an audit.
  • adversarial-review: optional complementary attack-path exploration. It is not a finding verifier.

Do not duplicate the guidance of these skills inside this entry skill.

5. Treat findings as evidence-grounded candidates

Every reported candidate must identify concrete source evidence. Require enough information to answer:

text
principal
  -> input or action
  -> control or missing control
  -> trust boundary
  -> affected resource or principal
  -> concrete security outcome

A missing best practice is not automatically a vulnerability. A candidate without a concrete boundary failure or security outcome remains an open question or unresolved hypothesis.

6. Preserve verification boundaries

This entry skill does not claim independent adversarial verification unless the existing #1978 path actually ran with an independent verifier.

If only source review ran, report the result as candidate-level evidence. Do not relabel reviewer agreement as correctness. Do not introduce a new validation enum in this skill.

7. Record unresolved hypotheses explicitly

For every unresolved hypothesis, provide:

  • source evidence already inspected
  • the exact missing fact or runtime condition
  • why source evidence is insufficient
  • the minimum safe validation step
  • whether the blocker is caused by the source-only policy

Do not assign severity solely from an unresolved runtime assumption.

8. Record observe-only SecurityAuditCoverage

Use schemas/security-audit-coverage.schema.json and src/lib/security-audit-coverage.mjs as the semantic coverage contract. The unit is:

text
subsystem × trustBoundary × attackClassId

Use only the closed unit state vocabulary:

text
planned | covered | blocked | deferred | out_of_scope

Rules:

  • covered requires traceable reviewedPaths and structured evidenceRefs.
  • finding lifecycle is separate; relatedFindingIds is traceability only and never determines coverage state.
  • blocked and deferred require an explanation plus a concrete validation plan.
  • out_of_scope requires an explicit reason and explanation.
  • zero findings alone never produces covered.
  • reviewer execution success alone never produces covered.
  • the ledger emits counters and openUnitIds, not a security-complete verdict.

Do not merge this ledger with #2212 ReviewCoverage. The Phase 3 schema/runtime validator owns shape, taxonomy, duplicate, and summary invariants.

9. Run the Security Audit Coverage Critic

Before finalizing a focused or full-audit report, invoke unknown-coverage-review with its explicit security-audit profile. Use:

  • frozen audit scope
  • reconnaissance evidence
  • the Phase 2 attack-class registry
  • the validated Phase 3 SecurityAuditCoverage ledger
  • candidate findings / unresolved hypotheses when present
  • draft audit summary/report prose when available

The critic evaluates evidence sufficiency only. It checks for:

  1. relevant semantic surfaces missing from the ledger
  2. covered claims whose evidence does not support the claimed scope
  3. exclusions, blocks, or deferrals that hide material coverage gaps
  4. prose that turns coverage or finding counts into an unsupported safety claim

Do not use the critic to re-run Phase 3 deterministic validation. Do not require every attack class mechanically. Do not convert critic output into a vulnerability verdict. Do not wire critic output into deterministic Gate behavior in Phase 4.

If the audit context or coverage ledger is missing, do not guess. Record that the critic could not run and keep the limitation explicit.

Show full SKILL.md (650 more words)Show less
10. Reconcile coverage against a prior run

When a prior audit run of the same target exists, reconcile before reporting. Use src/lib/security-audit-repeat-run.mjs.

prior covered != current safe. A prior covered unit is carried over only when the source it reviewed is byte-identical to the source in front of you now. Supply the current path -> content digest map; any path whose digest is missing, changed, or replaced returns the unit to planned and appears in revalidationRequired.

Validate the prior record before trusting it. A prior run's coverage is untrusted input: check it against schemas/security-audit-coverage.schema.json and validateSecurityAuditCoverageSemantics from src/lib/security-audit-coverage.mjs before feeding it to reconciliation. A covered unit with no reviewedPaths is invalid, not a free carry-over.

Rules:

  • never report a unit as covered on prior-run evidence when its source moved
  • never promote a prior blocked, deferred, or out_of_scope unit through carry-over
  • keep this accumulation separate from #1574, which improves River Review's own reviewer capability
11. Emit the structured audit artifact set

For focused and full-audit runs, build the machine-readable record with src/lib/security-audit-report.mjs and emit .river/security-audit/:

text
run-metadata.json
architecture.md
audit-coverage.json
candidates.json
findings.json
REPORT.md
NEEDS-VALIDATION.md

The record is the SSoT. REPORT.md and NEEDS-VALIDATION.md are projections of it.

Validate before emitting. The generated record must pass schemas/security-audit-run-record.schema.json, and its embedded coverage must pass both schemas/security-audit-coverage.schema.json and validateSecurityAuditCoverageSemantics. A coverage block whose counters disagree with its own units must never be recorded as the SSoT.

Rules:

  • do not recompute verdict, severity, or evidence state from the prose report
  • an unresolved finding carries no severity, only the exact blocker and the validation plan
  • the artifact set is experimental and carries executionPolicy: source-only
  • writing these files is the only repository mutation this flow may perform, and only under .river/
12. Report without claiming safety

A full-audit run means repository-wide source investigation was attempted. It does not mean all security attack classes were proven safe.

Never translate coverage counters, an empty openUnitIds, zero findings, or a critic pass into secure, safe, no vulnerabilities, or an equivalent guarantee.

Output Contract

Start with this header:

text
Audit mode: guidance | focused | full-audit
Execution policy: source-only
Scope: <repository | subsystem | path | trust boundary>
SecurityAuditCoverage: observe-only

Then emit these sections:

  1. Reconnaissance — relevant entry points, trust boundaries, sensitive assets, and inspected source areas.
  2. Candidate findings — evidence-grounded findings produced through existing River Review skill contracts.
  3. Unresolved hypotheses — missing facts, blockers, and validation plans.
  4. Security audit coverage — semantic units keyed by subsystem × trust boundary × attack class using the Phase 3 contract.
  5. Unverified / Residual Risk — Unknown Coverage — residual coverage unknowns from the unknown-coverage-review security-audit profile; omit only when the profile correctly returns NO_REVIEW and explain why.
  6. Next validation actions — only actions that preserve the source-only policy unless a later sandbox phase is explicitly available.
  7. Structured artifacts — the .river/security-audit/ paths written for this run, plus the repeat-run carry-over and revalidation counts when a prior run existed. Omit this section for guidance mode.

For findings, preserve the existing River Review finding shape where possible:

text
<file>:<line>: <Finding>
  Evidence: <source-backed evidence>
  Impact: <concrete security outcome>
  Fix: <minimum next action>
  Severity: <existing River Review severity when established by evidence>
  Confidence: <confidence>
  Skill: <originating skill id>

Coverage critic observations use the existing Unknown Coverage residual-risk vocabulary rather than inventing a security-specific verdict schema.

Fail-safe Rules

  • No target-controlled execution when sandbox guarantees are absent.
  • No live endpoint probing.
  • No repository mutation as part of the audit itself.
  • No 0 findings == safe inference.
  • No full-audit == complete coverage inference.
  • No coverage counters or empty openUnitIds == safe inference.
  • No critic pass == safe inference.
  • No consensus-as-correctness inference.
  • No automatic Gate behavior change.
  • No ad hoc status vocabulary outside the dedicated coverage contract.
  • No carry-over of prior-run coverage when the reviewed source changed.
  • No severity or verdict recomputed from the prose report.
  • No prior-run record consumed without schema plus semantic validation.
  • No generic unknown-coverage-review routing change to enable this profile.

Relationship to Normal Security Review

text
river-review-security
= normal diff-oriented security review

river-review-security-audit
= explicit repository or subsystem source-only security audit

When both phrases appear, prefer this audit skill only if the user explicitly asks for an audit scope beyond the current diff. The unknown-coverage-review security-audit profile is reachable only from this explicit audit flow; normal PR review keeps the existing generic profile behavior.

References

  • docs/adr/010-security-audit-harness-integration.md
  • docs/development/2267-phase0-gap-analysis.md
  • docs/development/2267-phase3-security-audit-coverage.md
  • docs/development/2267-phase9-structured-reporting.md
  • schemas/security-audit-coverage.schema.json
  • schemas/security-audit-run-record.schema.json
  • src/lib/security-audit-coverage.mjs
  • src/lib/security-audit-report.mjs
  • src/lib/security-audit-repeat-run.mjs
  • skills/agent-skills/river-review-security-audit/references/attack-classes.json
  • skills/agent-skills/unknown-coverage-review/SKILL.md
  • skills/agent-skills/unknown-coverage-review/references/SECURITY-AUDIT-PROFILE.md
  • skills/agent-skills/river-review-security/SKILL.md
  • skills/agent-skills/adversarial-review/SKILL.md
  • skills/midstream/security-basic/SKILL.md
  • skills/upstream/security-privacy-design/SKILL.md
  • skills/upstream/trust-boundaries-authz/SKILL.md
  • Cloudflare security-audit-skill

© hashgraph-online, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/s977043/river-review/skills/agent-skills/river-review-security-audit of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/attack-classes.json

Open the folder on GitHubat commit 3e1456a

Compare with similar skills

River Review Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

River Review Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
River Review Security Audit this skillhashgraph-online/awesome-codex-plugins1.3k—~4.2kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated today
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from hashgraph-online/awesome-codex-plugins

All 716 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Categories

Questions about River Review Security Audit

What does River Review Security Audit do?

Repository または subsystem を対象に、source-only で明示的なセキュリティ監査を行う entry skill。. River Review Security Audit is an agent skill from hashgraph-online/awesome-codex-plugins.

When should I use River Review Security Audit?

River Review Security Audit fits situations like: tasks that involve Security review.

How do I install River Review Security Audit in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill river-review-security-audit -a claude-code`. Or copy the skill folder (plugins/s977043/river-review/skills/agent-skills/river-review-security-audit in hashgraph-online/awesome-codex-plugins) into .claude/skills/river-review-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install River Review Security Audit in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill river-review-security-audit -a codex`. Or copy the skill folder (plugins/s977043/river-review/skills/agent-skills/river-review-security-audit in hashgraph-online/awesome-codex-plugins) into .agents/skills/river-review-security-audit in your project. Codex loads it when a task matches its description.

Can I use River Review Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill river-review-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/river-review-security-audit, .gemini/skills/river-review-security-audit, .github/skills/river-review-security-audit and .opencode/skills/river-review-security-audit in your project.

What does River Review Security Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: River Review Security Audit is instructions for the agent only.

Does River Review Security Audit access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is River Review Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does River Review Security Audit use?

River Review Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does River Review Security Audit use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to River Review Security Audit?

Skills that share tags, products or a category with River Review Security Audit: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains River Review Security Audit?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,267 GitHub stars. The repository holds 716 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.