Agent skill

Security Review

by ktnyt in ktnyt/cclsp

Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

MITAuto-check passedSecurity

Install Security Review

skills CLI
$ npx skills add ktnyt/cclsp --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ktnyt/cclsp security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ktnyt/cclsp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
675
Token cost
~565 tokens
SKILL.md length
200 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

  • Works in 6 steps: Command injection: Are user-supplied… → Path traversal: Can file paths from LSP… → Resource exhaustion: Are there timeouts… → …
  • The Reviewer identifies security-sensitive changes in the MCP-LSP bridge
  • SKILL.md covers When to trigger, Review checklist, How to invoke and Output expectations
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Review is an agent skill from ktnyt/cclsp. Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. Use when the Reviewer identifies security-sensitive changes in the MCP-LSP bridge.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code (or similar products)

It sits in Security, covering Security review, Secrets management and MCP servers. It works with Model Context Protocol. The repository describes itself as: Claude Code LSP: enhance your Claude Code experience with non-IDE dependent LSP integration. The licence is MIT.

When your agent uses it

  • The Reviewer identifies security-sensitive changes in the MCP-LSP bridge
  • Tasks that involve Security review
  • Tasks that involve Secrets management

Example prompts

  • “/security-review”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code (or similar products)

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Command injection: Are user-supplied values (config file paths, server
  2. Path traversal: Can file paths from LSP responses escape the project
  3. Resource exhaustion: Are there timeouts on LSP server responses? Can a
  4. Config trust boundary: Is cclsp.json treated as trusted input? What
  5. Process cleanup: Are child processes reliably terminated on shutdown?
  6. Symlink attacks: Does file resolution follow symlinks outside the

What it can do on your machine

Read from SKILL.md and the folder at commit 93414a1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code (or similar products)

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Review loads about 565 tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 200 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~565

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ktnyt/cclsp at commit 93414a1, republished under its MIT licence (© ktnyt). 200 words, ~565 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. Use when the Reviewer identifies security-sensitive changes in the MCP-LSP bridge.
compatibility
Designed for Claude Code (or similar products)
metadata.author
ktnyt
metadata.version
1.0

Security Review

Invoke the security-reviewer agent to assess security-sensitive changes.

When to trigger

  • Child process spawning or lifecycle changes (src/lsp-client.ts)
  • File system read/write operations (src/file-editor.ts, src/file-scanner.ts)
  • Configuration file loading or parsing (cclsp.json, CCLSP_CONFIG_PATH)
  • Environment variable handling
  • New or modified LSP server adapter (src/lsp/adapters/)
  • Setup wizard input handling (src/setup.ts)

Review checklist

  1. Command injection: Are user-supplied values (config file paths, server commands) sanitized before being passed to child_process spawn?
  2. Path traversal: Can file paths from LSP responses escape the project root? Are file:// URIs validated before resolving?
  3. Resource exhaustion: Are there timeouts on LSP server responses? Can a malicious LSP server cause unbounded memory growth?
  4. Config trust boundary: Is cclsp.json treated as trusted input? What happens if it contains unexpected fields or types?
  5. Process cleanup: Are child processes reliably terminated on shutdown? Can orphaned processes persist?
  6. Symlink attacks: Does file resolution follow symlinks outside the project directory?

How to invoke

Use the everything-claude-code:security-reviewer agent via the Task tool:

Task(
  subagent_type: "everything-claude-code:security-reviewer",
  prompt: "Review the following changes for security concerns: <describe changes>"
)

Output expectations

The security reviewer should produce:

  • CRITICAL: Must fix before merge (injection, traversal, credential leak)
  • HIGH: Should fix before merge (missing timeouts, incomplete cleanup)
  • MEDIUM: Fix when possible (defensive checks, hardening opportunities)
  • LOW: Informational (best practice suggestions)

© ktnyt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/security-review of ktnyt/cclsp.

Open the folder on GitHubat commit 93414a1

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skillktnyt/cclsp675—~565Automated safety check: PassMIT
MCP Security Auditgithub/awesome-copilot40k—~3.1kAutomated safety check: PassMIT
MCP Security Auditboshi-xixixi/TraeSkill276—~2.2kAutomated safety check: PassMIT
Ripwire Security Scanredhat-et/ripwire2.4k—~2.8kAutomated safety check: WarnApache-2.0
Azure Compliancemicrosoft/GitHub-Copilot-for-Azure2552 repos~997Automated safety check: PassMIT
Security Passcyanheads/pubmed-mcp-server158—~6.4kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Security Audit

    github/awesome-copilot

    Official

    Audit MCP (Model Context Protocol) server configurations for security issues.

    40k GitHub stars~3.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • MCP Security Audit

    boshi-xixixi/TraeSkill

    Audit MCP (Model Context Protocol) server configurations for security issues.

    276 GitHub stars~2.2k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed
  • Ripwire Security Scan

    redhat-et/ripwire

    Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a…

    2.4k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: warnings
  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed
  • Security Pass

    cyanheads/pubmed-mcp-server

    Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…

    158 GitHub stars~6.4k tokensUpdated today
    SecurityAuto-check passed
  • Tool Defs Analysis

    cyanheads/pubmed-mcp-server

    Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions.

    158 GitHub stars~4.9k tokensUpdated today
    SecurityAuto-check passed

More from ktnyt/cclsp

  • Architecture

    ktnyt/cclsp

    Guides the design of safely disposable code through contracts (traits/interfaces) and dependency inversion.

    675 GitHub stars~1.6k tokensUpdated 7 mo ago
    Auto-check passed
  • Hands On Test

    ktnyt/cclsp

    Performs manual hands-on testing of a web application using playwright-cli.

    675 GitHub stars~1.7k tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Security Review

What does Security Review do?

Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. Security Review is an agent skill from ktnyt/cclsp. Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

When should I use Security Review?

Security Review fits situations like: the Reviewer identifies security-sensitive changes in the MCP-LSP bridge; tasks that involve Security review; tasks that involve Secrets management.

How do I install Security Review in Claude Code?

Run `npx skills add ktnyt/cclsp --skill security-review -a claude-code`. Or copy the skill folder (.claude/skills/security-review in ktnyt/cclsp) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add ktnyt/cclsp --skill security-review -a codex`. Or copy the skill folder (.claude/skills/security-review in ktnyt/cclsp) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ktnyt/cclsp --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Review is instructions for the agent only. Compatibility (from SKILL.md): Designed for Claude Code (or similar products).

Does Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 565 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: MCP Security Audit (github/awesome-copilot, 40k stars), MCP Security Audit (boshi-xixixi/TraeSkill, 276 stars), Ripwire Security Scan (redhat-et/ripwire, 2.4k stars) and Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

ktnyt (a GitHub user) maintains it in ktnyt/cclsp, which has 675 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on February 22, 2026.

Source: ktnyt/cclsp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.