Official agent skill

Review Security

by pydantic in pydantic/monty

Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

OfficialMITAuto-check passedSecurity

Install Review Security

skills CLI
$ npx skills add pydantic/monty --skill review-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pydantic/monty review-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pydantic/monty.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-security .claude/skills/review-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-security
GitHub stars
8.6k
Token cost
~852 tokens
SKILL.md length
416 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

  • Reviewing changes for security risk
  • Calls git
  • Before merging anything touching the heap/ module
  • Pathsecurity.rs

What it does

Review Security is an agent skill from pydantic/monty, published by the product's own GitHub organization. Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. Use when reviewing changes for security risk, or before merging anything touching the heap/ module, pathsecurity.rs, the wire protocol or the pool.

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with Python and Rust. The repository describes itself as: A minimal, secure Python interpreter written in Rust for use by AI. The licence is MIT.

When your agent uses it

  • Reviewing changes for security risk
  • Before merging anything touching the heap/ module
  • Pathsecurity.rs
  • The wire protocol

Example prompts

  • “/review-security”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 5915273. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Security loads about 852 tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 416 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~852

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pydantic/monty at commit 5915273, republished under its MIT licence (© pydantic). 416 words, ~852 tokens.

Download SKILL.mdSave it as .claude/skills/review-security/SKILL.md (or your agent's skills folder).
name
review-security
description
Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. Use when reviewing changes for security risk, or before merging anything touching the heap/ module, path_security.rs, the wire protocol or the pool.

Security review

Monty runs untrusted, potentially malicious Python. Review this branch on that basis.

bash
git diff origin/main...HEAD

Use a subagent to run .agents/skills/fix-pr-comments/pr-threads.sh (from the fix-pr-comments skill) for security findings already raised on the PR, and confirm each is properly addressed.

Cover the changes and any code they touch — a caller made unsafe by a changed callee is in scope even if it isn't in the diff. Ask:

  • Sandbox escape? Filesystem access outside a mount, path traversal, symlinks resolving out of bounds, network, subprocesses, import-system abuse, callback misuse, leaks through error messages or timing.
  • Memory errors? Worse than panics: nothing stops, state is silently corrupt, and it can become arbitrary execution. unsafe, refcount errors causing use-after-free or double-free, unchecked indexing, aliasing violations, integer overflow feeding a length or index.
  • Resource limits bypassed? Allocations dodging the ResourceTracker (String without StringBuilder), loops with no fuel check, small input → huge allocation.
  • Untrusted input still untrusted? Wire frames from a child are hostile: decoding and proto→Rust conversion must validate everything and never panic. Snapshot provenance and integrity are the host's responsibility. Invalid snapshots may panic, abort, hang or produce wrong results, but must not cause UB; do not require semantic validation solely for tampered snapshots. Keep checks needed for memory safety or transport compatibility.
  • Panics or aborts? unwrap/expect reachable from sandboxed input, unbounded recursion hitting a stack-overflow abort.
  • Mount escapes? Any behaviour that allows sandbox code to escape a filesystem mount and read or alter files outside the mount point. This is particularly severe since mounts are run on the host/client connecting to a sandbox - accessing that environment is a very serious breach of the sandbox and security issue.
Show full SKILL.md (144 more words)Show less

Weight both classes by where they land. In a pool worker the process dies, the parent replaces the child and raises an exception — contained. Nothing else is: in host/parent code (monty-pool, monty-proto decoding, monty-fs, the bindings), or in a Rust embedder calling the monty crate in-process, the same bug takes down the application. Scrutinise those hardest, especially anything handling a frame from a child.

The crates/monty/src/heap/ module and crates/monty-fs/src/path_security.rs are security-critical; any change to either needs careful justification. Also check the public API: could a pydantic_monty or @pydantic/monty user misuse this to expose their host?

Report

Per finding: the attack, file:line, the sandboxed Python or hostile frame that triggers it, and the impact. Demonstrate with python-playground rather than asserting where you can. Say which areas you checked and found clean — coverage matters as much as findings.

Report only, unless the user asks for fixes.

© pydantic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/review-security of pydantic/monty.

Open the folder on GitHubat commit 5915273

Compare with similar skills

Review Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Security this skillpydantic/monty8.6k—~852Automated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Hardenathola/claude-night-market341—~2.7kAutomated safety check: PassMIT
Common Security AuditHoangNguyen0403/agent-skills-standard571—~977Automated safety check: PassMIT

Similar skills

  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Harden

    athola/claude-night-market

    Applies NIST/CWE security hardening to Python and Rust code.

    341 GitHub stars~2.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Common Security Audit

    HoangNguyen0403/agent-skills-standard

    Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular…

    571 GitHub stars~977 tokensUpdated today
    SecurityAuto-check passed
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes

More from pydantic/monty

All 9 skills in this repo
  • Fix PR Comments

    pydantic/monty

    Official

    Read the review comments left by the known agent reviewers on the current PR, resolve and reply.

    8.6k GitHub stars~552 tokensUpdated yesterday
    Auto-check passed
  • Python Playground

    pydantic/monty

    Official

    Run and test Python code in a dedicated playground directory.

    8.6k GitHub stars~424 tokensUpdated yesterday
    Auto-check passed
  • Review General

    pydantic/monty

    Official

    Review the current branch against its merge base for bugs, CPython divergence, sandbox escapes, resource-limit escapes, performance regressions, verbose comments and missing ./limitations/ or docs/…

    8.6k GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • Writing Style

    pydantic/monty

    Official

    How to write prose that reads like human technical documentation rather than LLM output.

    8.6k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Review Usability

    pydantic/monty

    Official

    Check whether the common Python code an LLM would plausibly write still works on this branch, testing real cases in ./playground against CPython.

    8.6k GitHub stars~410 tokensUpdated yesterday
    Auto-check passed
  • Coverage

    pydantic/monty

    Official

    Fetch coverage diff from Codecov for the current branch or a specific PR.

    8.6k GitHub stars~282 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Review Security

What does Review Security do?

Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. Review Security is an agent skill from pydantic/monty, published by the product's own GitHub organization. Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

When should I use Review Security?

Review Security fits situations like: reviewing changes for security risk; before merging anything touching the heap/ module; pathsecurity.rs; the wire protocol.

How do I install Review Security in Claude Code?

Run `npx skills add pydantic/monty --skill review-security -a claude-code`. Or copy the skill folder (.agents/skills/review-security in pydantic/monty) into .claude/skills/review-security in your project. Claude Code loads it when a task matches its description.

How do I install Review Security in Codex?

Run `npx skills add pydantic/monty --skill review-security -a codex`. Or copy the skill folder (.agents/skills/review-security in pydantic/monty) into .agents/skills/review-security in your project. Codex loads it when a task matches its description.

Can I use Review Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pydantic/monty --skill review-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-security, .gemini/skills/review-security, .github/skills/review-security and .opencode/skills/review-security in your project.

What does Review Security need to run?

Going by SKILL.md and its folder, Review Security needs the command-line tools its instructions call (git). Our summary lists: Python 3.

Does Review Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Security use?

Review Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Security use?

About 852 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Security?

Skills that share tags, products or a category with Review Security: Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Security Review (github/awesome-copilot, 40k stars) and Harden (athola/claude-night-market, 341 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Security?

pydantic (a GitHub organization, an official publisher) maintains it in pydantic/monty, which has 8,607 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.

Source: pydantic/monty on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.