Agent skill

Performing Security Code Review

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

MITAuto-check: notesSecurity

Install Performing Security Code Review

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill performing-security-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace performing-security-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/performing-security-code-review .claude/skills/performing-security-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-security-code-review
GitHub stars
2.8k
Used in
2 other repos
Token cost
~1.3k tokens
SKILL.md length
567 words
Files
8 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

  • Works in 7 steps: Identify the scope of the review:… → Scan for hardcoded secrets and credentials → Analyze code for injection vulnerabilities → …
  • Assessing security
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder; calls npm

What it does

Performing Security Code Review is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/example_code_secure.py` and `assets/example_code_vulnerable.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Web application vulnerabilities, Code review and Security review. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Assessing security
  • With phrases like security scan

Example prompts

  • “security scan”
  • “vulnerability”
  • “/performing-security-code-review”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(cmd:*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify the scope of the review: specific files, directories, or the entire codebase. Confirm the primary language(s) and framework(s) in…
  2. Scan for hardcoded secrets and credentials
  3. Analyze code for injection vulnerabilities
  4. Review authentication and authorization logic
  5. Audit dependencies for known vulnerabilities
  6. Check for insecure communication patterns
  7. Compile findings into a structured report sorted by severity (Critical, High, Medium, Low), including the vulnerable code location…

What it can do on your machine

Read from SKILL.md and the folder at commit 23ea8d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • blog.risingstack.com
    • cwe.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Performing Security Code Review loads about 1.3k tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 567 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:39
    - Flag any `.env` files or configuration files containing plaintext secrets.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 23ea8d4, republished under its MIT licence (© jeremylongshore). 567 words, ~1,344 tokens.

Download SKILL.mdSave it as .claude/skills/performing-security-code-review/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-security-code-review
description
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(cmd:*)
compatibility
Designed for Claude Code
version
1.28.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
example, security, authentication, audit

Performing Security Code Review

Overview

Conducts security-focused code reviews by scanning source files for common vulnerability patterns including SQL injection, XSS, authentication flaws, insecure dependencies, and secret exposure. Produces structured severity-rated reports with specific remediation guidance.

Prerequisites

  • Read access to all source files in the target project
  • grep available on PATH for pattern matching
  • Access to package.json or equivalent dependency manifest for dependency auditing
  • Familiarity with OWASP Top 10 vulnerability categories

Instructions

  1. Identify the scope of the review: specific files, directories, or the entire codebase. Confirm the primary language(s) and framework(s) in use.
  2. Scan for hardcoded secrets and credentials:
    • Search for patterns matching API keys, tokens, passwords, AWS access keys (AKIA...), and private key headers (BEGIN PRIVATE KEY).
    • Flag any .env files or configuration files containing plaintext secrets.
  3. Analyze code for injection vulnerabilities:
    • Identify raw SQL string concatenation (SQL injection risk).
    • Locate unsanitized user input rendered in HTML (XSS risk).
    • Check for eval(), exec(), or Function() calls with dynamic input (code injection risk).
  4. Review authentication and authorization logic:
    • Verify password hashing uses strong algorithms (bcrypt, argon2) rather than MD5/SHA1.
    • Check for missing authentication on sensitive endpoints.
    • Identify overly permissive CORS configurations.
  5. Audit dependencies for known vulnerabilities:
    • Run npm audit or equivalent package manager audit command.
    • Cross-reference dependency versions against known CVE databases.
  6. Check for insecure communication patterns:
    • Flag HTTP URLs where HTTPS is expected.
    • Identify disabled TLS certificate verification.
  7. Compile findings into a structured report sorted by severity (Critical, High, Medium, Low), including the vulnerable code location, explanation, and remediation steps.

Output

A structured security review report containing:

  • Summary with total findings count by severity level
  • Per-finding entries with: file path, line number, vulnerability type, severity, code snippet, explanation, and recommended fix
  • Dependency audit results with CVE identifiers where applicable
  • Overall risk assessment (Critical / High / Medium / Low / Clean)
Show full SKILL.md (262 more words)Show less

Error Handling

ErrorCauseSolution
No source files foundIncorrect scope path or empty directoryVerify the target directory path and confirm it contains source files
Binary files in scanNon-text files matched by search patternsExclude binary extensions and node_modules/ from scans
Dependency manifest missingNo package.json, requirements.txt, or equivalentSkip dependency audit; note in report that dependency analysis was not possible
Permission denied on filesRestricted file accessRequest read permissions or narrow the review scope to accessible files
False positive on secret patternBenign string matching secret regexVerify context before reporting; mark as potential false positive if the match appears in test fixtures or documentation

Examples

SQL injection review: Trigger: "Review this database query code for SQL injection vulnerabilities." Process: Scan all files containing SQL query construction. Identify string concatenation with user input ("SELECT * FROM users WHERE id = " + userId). Report as High severity with remediation: use parameterized queries or prepared statements.

Dependency vulnerability scan: Trigger: "Check this project's dependencies for known security vulnerabilities." Process: Run npm audit on the project. Parse output for vulnerabilities. Report each finding with CVE identifier, affected package, installed version, and patched version. Recommend npm audit fix or manual version pinning.

Full codebase security audit: Trigger: "Run a security scan on this codebase." Process: Execute all seven scan categories (secrets, injection, auth, dependencies, communication, dangerous commands, obfuscation). Produce a comprehensive report with findings grouped by category and sorted by severity.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/performing-security-code-review of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • assets/example_code_secure.py
  • assets/example_code_vulnerable.py
  • assets/report_template.md
  • references/README.md
  • scripts/README.md
  • scripts/code_analyzer.py

Open the folder on GitHubat commit 23ea8d4

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in jeremylongshore/tons-of-skills-marketplace, which our catalogue first saw on October 8, 2026.

Compare with similar skills

Performing Security Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Security Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Security Code Review this skilljeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Security Reviewdeadlock-mod-manager/deadlock-mod-manager574—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Code Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~1.4kAutomated safety check: NotesApache-2.0
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Security Auditorpavel-molyanov/molyanov-ai-dev296—~566Automated safety check: PassMIT

Similar skills

  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    574 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Code Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.

    3.6k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Security Auditor

    pavel-molyanov/molyanov-ai-dev

    Analyzes changed security boundaries against applicable OWASP risks and project contracts.

    296 GitHub stars~566 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

    3.6k GitHub stars~523 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Analyzing Text With NLP

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to perform natural language processing and text analysis using the nlp-text-analyzer plugin.

    2.8k GitHub starsUsed in 1 repo~819 tokens
    Auto-check passed
  • Building Neural Networks

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill allows AI assistant to construct and configure neural network architectures using the neural-network-builder plugin.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Detecting Data Anomalies

    jeremylongshore/tons-of-skills-marketplace

    Process identify anomalies and outliers in datasets using machine learning algorithms.

    2.8k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Explaining Machine Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to provide interpretability and explainability for machine learning models.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Optimizing Prompts

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill optimizes prompts for large language models (llms) to reduce token usage, lower costs, and improve performance.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Skill Creator

    jeremylongshore/tons-of-skills-marketplace

    Create production-grade agent skills aligned with the 2026 AgentSkills.io spec and Anthropic best practices (2026).

    2.8k GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes

Questions about Performing Security Code Review

What does Performing Security Code Review do?

Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. Performing Security Code Review is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

When should I use Performing Security Code Review?

Performing Security Code Review fits situations like: assessing security; with phrases like security scan.

How do I install Performing Security Code Review in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill performing-security-code-review -a claude-code`. Or copy the skill folder (skills/.curated/performing-security-code-review in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/performing-security-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Performing Security Code Review in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill performing-security-code-review -a codex`. Or copy the skill folder (skills/.curated/performing-security-code-review in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/performing-security-code-review in your project. Codex loads it when a task matches its description.

Can I use Performing Security Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill performing-security-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-security-code-review, .gemini/skills/performing-security-code-review, .github/skills/performing-security-code-review and .opencode/skills/performing-security-code-review in your project.

What does Performing Security Code Review need to run?

Going by SKILL.md and its folder, Performing Security Code Review needs Python for the scripts in its folder and the command-line tools its instructions call (npm). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Performing Security Code Review access the network?

SKILL.md names 3 domains. As links in the text: owasp.org, blog.risingstack.com and cwe.mitre.org. This is read from the text; nothing was executed.

Is Performing Security Code Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Security Code Review use?

Performing Security Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Security Code Review use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15 tokens, read only when the agent opens those files.

What are the alternatives to Performing Security Code Review?

Skills that share tags, products or a category with Performing Security Code Review: Security Review (deadlock-mod-manager/deadlock-mod-manager, 574 stars), Code Reviewer (foryourhealth111-pixel/Vibe-Skills, 3.6k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars) and Security Review (getsentry/skills, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Security Code Review?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,821 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 8, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.