Agent skill

Levyra Security Review

by LUC4N3X in LUC4N3X/Levyra-deepsound

Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF…

GPL-3.0Auto-check passedSecurity

Install Levyra Security Review

skills CLI
$ npx skills add LUC4N3X/Levyra-deepsound --skill levyra-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LUC4N3X/Levyra-deepsound levyra-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LUC4N3X/Levyra-deepsound.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/levyra-security-review .claude/skills/levyra-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
levyra-security-review
GitHub stars
590
Token cost
~2.3k tokens
SKILL.md length
1,076 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
GPL-3.0

At a glance

Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF…

  • Works in 6 steps: Threat model → Identification → Validation → …
  • Tasks that involve Security review
  • SKILL.md covers Required context, Finding lifecycle, Closed-loop security method and Evidence hygiene, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Levyra Security Review is an agent skill from LUC4N3X/Levyra-deepsound. Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF, MIME confusion, permissions, privacy, logging, workflows, dependency changes, update verification, and untrusted input. Use automatically for vulnerability scans, security findings, dependency risk, authentication, trust-boundary changes, sensitive data, or security-related pull requests.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Threat modeling and Web application vulnerabilities. The repository describes itself as: Open-source music player for Android and Windows with no accounts or tracking. Built for quick discovery, synced lyrics, radio, and rich artwork ♫. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Threat modeling
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/levyra-security-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Threat model
  2. Identification
  3. Validation
  4. Remediation
  5. Human review
  6. Revalidation

What it can do on your machine

Read from SKILL.md and the folder at commit fd13888. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Levyra Security Review loads about 2.3k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 1,076 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LUC4N3X/Levyra-deepsound at commit fd13888, republished under its GPL-3.0 licence (© LUC4N3X). 1,076 words, ~2,297 tokens.

Download SKILL.mdSave it as .claude/skills/levyra-security-review/SKILL.md (or your agent's skills folder).
name
levyra-security-review
description
Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF, MIME confusion, permissions, privacy, logging, workflows, dependency changes, update verification, and untrusted input. Use automatically for vulnerability scans, security findings, dependency risk, authentication, trust-boundary changes, sensitive data, or security-related pull requests.

Levyra security review workflow

Required context

  1. Read the root AGENTS.md and the nearest applicable AGENTS.md.
  2. Read .agents/claude/rules/security.md and docs/ai/CODEX_SECURITY.md.
  3. Inspect the complete diff plus surrounding code, tests, build files, manifests, dependency catalogs, clients, parsers, shell commands, persistence, signing, release, update, and GitHub workflow configuration.
  4. Load levyra-context-efficiency only for noisy non-sensitive output. Keep exploit evidence, security validation, signatures, checksums, secrets scans, and exact reproduction output raw inside the trusted working context.

Finding lifecycle

Every security candidate has an explicit evidence state:

  • SUSPECTED: a static pattern, warning, model observation, or incomplete path;
  • SUPPORTED: evidence is consistent with the finding but exploit/failure impact is not fully established;
  • VALIDATED: a concrete safe reproduction or equivalent evidence establishes the path and consequence;
  • DISPROVED: evidence shows the candidate does not represent the claimed failure;
  • RETRACTED: a previously reported/supported finding has been explicitly withdrawn after newer evidence invalidated it;
  • BLOCKED: decisive validation cannot be completed safely or with the available environment.

Do not silently drop a finding that was previously presented as real. If later evidence disproves it, mark it RETRACTED, state what new evidence changed the conclusion, and remove it from downstream remediation/severity decisions.

A warning, HTTP status, scanner hit, lint message, dependency advisory, or source-code pattern is not by itself a validated vulnerability.

Closed-loop security method

Use this workflow whether the review is performed manually, through the Codex Security plugin, or through the Codex Security CLI.

1. Threat model

Build or verify a codebase-specific threat model before claiming a finding:

  • identify attacker-controlled entry points;
  • identify trust boundaries and privileged components;
  • identify secrets, accounts, user data, signing material, update channels, and other high-impact assets;
  • identify Android, Desktop, CI, extractor, playback, storage, and network paths where untrusted data crosses a boundary;
  • state deployment assumptions and distinguish verified facts from assumptions.
2. Identification

Trace realistic attack paths from an entry point to a sensitive outcome. Do not promote a generic best-practice observation into a vulnerability without a concrete path, trigger, and consequence.

3. Validation

Attempt to reproduce the issue safely in an isolated or controlled environment. A suspected issue remains unconfirmed until evidence supports exploitability or a concrete security failure. Preserve the exact command, input, output, exit status, and relevant artifact or test result in the trusted working context.

Before calling the candidate validated, challenge at least one plausible benign or non-exploitable explanation when one exists: expected authorization, input normalization, validation order, unreachable code, environment-only behavior, stale dependency metadata, or an already-enforced boundary. The purpose is to kill false positives, not to add ceremony when the failure path is already directly proven.

Never run destructive, persistence, credential-theft, external-target, or production-impacting proof-of-concept activity. Use minimal local fixtures and synthetic secrets.

4. Remediation

For a validated issue, propose the smallest compatible patch that fixes the root cause. Preserve unrelated behavior and add a focused regression test or verification. Do not weaken security controls merely to restore compatibility.

5. Human review

Codex Security findings and patches are proposals, not automatic authority. Inspect the complete patch, run the normal Levyra review and CI gates, and keep commit, push, PR, merge, release, and repository-setting actions under explicit owner control.

6. Revalidation

After remediation, rerun the original safe reproduction or equivalent regression test. State whether the attack path is closed, which checks passed, which checks were blocked, and what residual risk remains.

Evidence hygiene

Raw security evidence may contain more sensitive material than the finding itself. Before an artifact, excerpt, screenshot, HAR, log, request/response pair, stack trace, or command output is placed in a PR, issue, review comment, public report, or other durable shared location:

  • redact bearer/access/refresh tokens, cookies, authorization headers, API keys, passwords, signing material, private keys, and session identifiers;
  • redact unrelated PII and account identifiers; use synthetic values when the exact value is not material;
  • redact private/local provider URLs or signed URLs when disclosure would expose credentials, infrastructure, or user data;
  • preserve the evidence shape needed for review: status code, method, route shape, request ID, timestamp, non-sensitive headers, hash/checksum, error class, and minimal payload structure;
  • prefer placeholders such as <redacted-token> over deleting fields when field presence is relevant;
  • never "sanitize" by changing the behavior being demonstrated;
  • if redaction would destroy the proof, state that the sensitive artifact was withheld and describe the reproducible non-sensitive facts instead of publishing it raw.

Do not rely on a later reviewer to notice secrets after publication. Hygiene happens before evidence leaves the trusted working context.

Show full SKILL.md (343 more words)Show less

Review areas

  • credentials, tokens, cookies, keys, signed URLs, keystores, private configuration, environment variables, and sensitive logs;
  • provider-controlled URL scheme, host, port, user-info, DNS/IP destination, redirects, MIME, timeout, response-size, and file-name handling;
  • automatic redirects that bypass explicit validation;
  • SQL, shell, intent, deep-link, path, archive, and filename injection;
  • Android permissions, exported components, pending intents, file providers, WebView behavior, and least privilege;
  • Desktop local listeners, IPC, downloads, update channels, libVLC input, and filesystem boundaries;
  • GitHub workflow permissions, pull-request trust boundaries, secret exposure, artifact handling, action pinning, and untrusted checkout execution;
  • dependency additions, upgrades, transitive risk, license changes, known vulnerabilities, and supply-chain substitution;
  • update manifests, download integrity, SHA-256/signature verification, and downgrade or substitution risks;
  • local account, crash, analytics, history, library, and playback-data privacy.

Codex Security integration

When codex-security@openai-curated is available, use it for security scans and combine its output with this Levyra-specific skill. Review the generated threat model and correct assumptions before accepting findings. Prefer validated findings with a reproduced attack path and minimal remediation patch.

The repository also runs GitHub Dependency Review for pull requests. A green dependency review does not replace threat modeling, source review, runtime validation, or manual approval.

Finding standard

Report only evidence-backed findings. Every finding must include:

  • evidence state (SUSPECTED, SUPPORTED, VALIDATED, DISPROVED, RETRACTED, or BLOCKED);
  • severity and confidence;
  • exact file and line or symbol;
  • attacker-controlled input or triggering condition;
  • trust boundary crossed;
  • concrete exploit or failure path;
  • validation or reproduction evidence;
  • relevant alternative explanation checked when material;
  • user/system consequence;
  • smallest compatible fix;
  • regression test or revalidation needed;
  • residual risk or blocked evidence.

Do not report generic best-practice observations without a concrete path to harm. Do not label an unvalidated suspicion as confirmed.

Skill-intelligence discipline

Use docs/ai/SKILL_INTELLIGENCE.md when considering external security catalogs. Do not vendor broad offensive bundles into Levyra merely to obtain validation or reporting techniques. Import only narrow, defensive, evidence-based methods that preserve the repository's authorization and safety boundaries.

Provenance

The finding-state, explicit-retraction, false-positive challenge, and evidence-hygiene refinements are selectively informed by elementalsouls/Claude-BugHunter's validation/reporting discipline. No offensive payload catalog, target-hunting workflow, credential-capture behavior, or authorization assumption is imported into Levyra.

© LUC4N3X, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/levyra-security-review of LUC4N3X/Levyra-deepsound.

Open the folder on GitHubat commit fd13888

Compare with similar skills

Levyra Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Levyra Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Levyra Security Review this skillLUC4N3X/Levyra-deepsound590—~2.3kAutomated safety check: PassGPL-3.0
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
CybersecurityAgriciDaniel/claude-cybersecurity228—~11kAutomated safety check: WarnMIT
Securitygaragon/nanostack207—~3.7kAutomated safety check: NotesApache-2.0
Csono-session/pstack136—~12kAutomated safety check: NotesMIT
Commit Security ScanFactory-AI/factory-plugins111—~2.3kAutomated safety check: PassNone

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    228 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    136 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Commit Security Scan

    Factory-AI/factory-plugins

    Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns.

    111 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • 007

    sickn33/agentic-awesome-skills

    Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

    47k GitHub starsUsed in 2 repos~410 tokens
    SecurityAuto-check passed

More from LUC4N3X/Levyra-deepsound

All 22 skills in this repo
  • Levyra Android Intent Security

    LUC4N3X/Levyra-deepsound

    Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work.

    591 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Levyra Context Efficiency

    LUC4N3X/Levyra-deepsound

    A skill your agent uses for genuinely high-volume Levyra work such as builds, tests, lint, logs, broad searches, dependency output, Git/GitHub or CodeRabbit inspection, CI diagnostics, agent setup…

    591 GitHub stars~1.3k tokensUpdated today
    Auto-check: notes
  • Levyra R8 Proguard

    LUC4N3X/Levyra-deepsound

    Automatically use for Levyra R8, Proguard, minification, resource shrinking, keep rules, consumer rules, release-only crashes, reflection/serialization/JNI shrinking issues, APK size, mapping files…

    591 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Levyra Android Performance

    LUC4N3X/Levyra-deepsound

    Automatically use for Android runtime performance investigations involving Perfetto/System Trace, jank, latency, startup, CPU scheduling, blocking, memory, I/O, IPC, graphics, power, or measured…

    591 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Levyra CI Workflows

    LUC4N3X/Levyra-deepsound

    Automatically use for Levyra GitHub Actions, CI, F-Droid, Gradle/AGP/Kotlin/KSP compatibility, build performance, configuration/build cache, artifacts, release automation, workflow security, or…

    591 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Levyra Design Taste

    LUC4N3X/Levyra-deepsound

    Automatically use together with the matching Levyra UI skill for any visual redesign, UI polish, visual hierarchy, spacing, typography, color, shape, motion, screenshot/reference recreation, or…

    591 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Levyra Security Review

What does Levyra Security Review do?

Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF…. Levyra Security Review is an agent skill from LUC4N3X/Levyra-deepsound. Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF, MIME confusion, permissions, privacy, logging, workflows, dependency changes, update verification, and untrusted input.

When should I use Levyra Security Review?

Levyra Security Review fits situations like: tasks that involve Security review; tasks that involve Threat modeling; tasks that involve Web application vulnerabilities.

How do I install Levyra Security Review in Claude Code?

Run `npx skills add LUC4N3X/Levyra-deepsound --skill levyra-security-review -a claude-code`. Or copy the skill folder (.agents/skills/levyra-security-review in LUC4N3X/Levyra-deepsound) into .claude/skills/levyra-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Levyra Security Review in Codex?

Run `npx skills add LUC4N3X/Levyra-deepsound --skill levyra-security-review -a codex`. Or copy the skill folder (.agents/skills/levyra-security-review in LUC4N3X/Levyra-deepsound) into .agents/skills/levyra-security-review in your project. Codex loads it when a task matches its description.

Can I use Levyra Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LUC4N3X/Levyra-deepsound --skill levyra-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/levyra-security-review, .gemini/skills/levyra-security-review, .github/skills/levyra-security-review and .opencode/skills/levyra-security-review in your project.

What does Levyra Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Levyra Security Review is instructions for the agent only.

Does Levyra Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Levyra Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Levyra Security Review use?

Levyra Security Review is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Levyra Security Review use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Levyra Security Review?

Skills that share tags, products or a category with Levyra Security Review: Security Audit Scanner (ruvnet/ruflo, 74k stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 228 stars), Security (garagon/nanostack, 207 stars) and Cso (no-session/pstack, 136 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Levyra Security Review?

LUC4N3X (a GitHub user) maintains it in LUC4N3X/Levyra-deepsound, which has 590 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 10, 2026.

Source: LUC4N3X/Levyra-deepsound on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.