Vibe Check
benavlabs/vibe-check
Security audit for web apps, especially AI-built ("vibe coded") ones.
Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli.
$ npx skills add kklimuk/docx-cli --skill security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kklimuk/docx-cli security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kklimuk/docx-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-review .claude/skills/security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-review" agent skill from https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-review into .claude/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kklimuk/docx-cli --skill security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kklimuk/docx-cli security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kklimuk/docx-cli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/security-review .agents/skills/security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-review" agent skill from https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-review into .agents/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kklimuk/docx-cli --skill security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kklimuk/docx-cli security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kklimuk/docx-cli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/security-review .cursor/skills/security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-review" agent skill from https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-review into .cursor/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kklimuk/docx-cli.git --path .claude/skills/security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kklimuk/docx-cli --skill security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kklimuk/docx-cli security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kklimuk/docx-cli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/security-review .gemini/skills/security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-review into .gemini/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kklimuk/docx-cli security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kklimuk/docx-cli --skill security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kklimuk/docx-cli.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/security-review .github/skills/security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-review into .github/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kklimuk/docx-cli --skill security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kklimuk/docx-cli security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kklimuk/docx-cli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/security-review .opencode/skills/security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/kklimuk/docx-cli/tree/main/.claude/skills/security-review into .opencode/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-reviewReview code for security vulnerabilities. An agent skill from kklimuk/docx-cli.
Security Review is an agent skill from kklimuk/docx-cli. Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review and Web application vulnerabilities. It works with Git. The repository describes itself as: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4cd0388. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBash(git diff:*)Bash(git log:*)Bash(git status:*)Bash(git show:*)WebFetchFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitbunnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Review loads about 1.7k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 901 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kklimuk/docx-cli at commit 4cd0388, republished under its MIT licence (© kklimuk). 901 words, ~1,741 tokens.
.claude/skills/security-review/SKILL.md (or your agent's skills folder).Audit changed files for security vulnerabilities, focusing on the OWASP Top 10 and issues specific to the project's stack.
When running locally as a forked subagent, the main session does not see any files you read or any reasoning you do — only the final report you return. When running in CI (e.g. via claude-code-action), the workflow takes the report and turns it into GitHub PR review comments. Either way, take your time, read every changed file completely, and produce a thorough, actionable report. The consumer of this report uses it as a worklist, so it must be complete and self-contained.
Determine the diff to review:
git diff main...HEAD --name-only to get files changed on this branch vs main.main, detached worktree, etc.), fall back to git diff HEAD --name-only for uncommitted changes, then git diff --cached --name-only for staged files.Read every changed file completely before starting the review. Read CLAUDE.md first to understand the project's stack and any subsystems with security-sensitive surface area (auth, real-time, payments, file uploads).
Bun.$, child_process, subprocess, os.system) without sanitization.dangerouslySetInnerHTML, or reflected into HTML/JS without escaping. Check contentEditable fields that accept pasted HTML... traversal.Object.assign or spread on user-controlled objects without allowlisting keys.(Only relevant if the project has a WebSocket layer — see CLAUDE.md.)
Math.random() / random.random() used for security-sensitive operations instead of crypto.randomUUID() / secrets.token_*().ws:// in production contexts.bun audit / npm audit / pip-audit is available, check for known CVEs.Return the complete formatted report as your final message — not a summary or TL;DR. Whatever consumes the report (a main Claude session locally, or a CI workflow that posts inline GitHub PR comments) uses it as a worklist, so it must be self-contained.
Organize findings by severity:
Exploitable now with no authentication required. Data loss, unauthorized access, or remote code execution.
Exploitable with some preconditions (e.g., needs authenticated user, specific timing). Privilege escalation, significant data leakage.
Defense-in-depth issues. Missing validation that's currently protected by another layer but shouldn't rely on it.
Hardening recommendations. Not exploitable today but reduce attack surface.
For each finding, include enough detail that the consumer can apply the fix without re-reading the entire file:
path:line (or path:start-end for ranges); list every site for cross-file findingsThe fix phase (or PR-comment-posting phase) happens in whatever consumes this report — not here. Your job ends when you return the report. Make sure it has enough information for that consumer to act on findings without re-reading the codebase. Locally, the main session will work through findings in severity order with minimal, targeted fixes and run bun run check + bun test after each. In CI, the workflow will turn each finding into a GitHub PR review comment.
© kklimuk, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/security-review of kklimuk/docx-cli.
Open the folder on GitHubat commit 4cd0388
Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Review this skillkklimuk/docx-cli | 216 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Vibe Checkbenavlabs/vibe-check | 118 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Security Reviewsd0xdev/sd0x-harness | 192 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Security AuditPostHog/posthog | 40k | — | ~8.1k | Automated safety check: Warn | Custom licence | |
| Security Reviewdanielvm-git/bigpowers | 258 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 |
benavlabs/vibe-check
Security audit for web apps, especially AI-built ("vibe coded") ones.
sd0xdev/sd0x-harness
Security review via Codex exec. An agent skill from sd0xdev/sd0x-harness.
PostHog/posthog
Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings.
danielvm-git/bigpowers
AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
kklimuk/docx-cli
Run the weak-agent adversarial test harness against docx-cli.
kklimuk/docx-cli
Read, edit, redline, comment on, and create Microsoft Word .docx files.
kklimuk/docx-cli
Create well-structured git commits from the current working tree.
Works with
Categories
Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli. Security Review is an agent skill from kklimuk/docx-cli. Review code for security vulnerabilities.
Security Review fits situations like: the user says security review; check for vulnerabilities; pentest the code; any variation of wanting a security assessment.
Run `npx skills add kklimuk/docx-cli --skill security-review -a claude-code`. Or copy the skill folder (.claude/skills/security-review in kklimuk/docx-cli) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kklimuk/docx-cli --skill security-review -a codex`. Or copy the skill folder (.claude/skills/security-review in kklimuk/docx-cli) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kklimuk/docx-cli --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.
Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (git, bun and npm). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git diff:*), Bash(git log:*), Bash(git status:*), Bash(git show:*), WebFetch.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Review: Vibe Check (benavlabs/vibe-check, 118 stars), Security Review (sd0xdev/sd0x-harness, 192 stars), Security Audit (PostHog/posthog, 40k stars) and Security Review (danielvm-git/bigpowers, 258 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kklimuk (a GitHub user) maintains it in kklimuk/docx-cli, which has 216 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.
Source: kklimuk/docx-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.