Agent skill

Security Review

by shawnpang in shawnpang/startup-founder-skills

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…

MITAuto-check passedSecurity

Install Security Review

skills CLI
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shawnpang/startup-founder-skills security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
343
Token cost
~1.8k tokens
SKILL.md length
716 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…

  • Works in 5 steps: Scope definition — Establish attack… → Automated scanning — Execute tooling… → Manual code review — Conduct contextual… → …
  • Needs a security assessment — threat modeling
  • SKILL.md covers When to Use, Context Required, Workflow and Output Format, plus 3 more sections
  • Calls trivy, npm and semgrep

What it does

Security Review is an agent skill from shawnpang/startup-founder-skills. When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Threat modeling and Authentication. The repository describes itself as: AI agent skills for tech startup founders — fundraising, sales, product, recruiting, engineering, legal, ops, and growth. Works with Claude Code, Cursor, Codex, and any Agent… The licence is MIT.

When your agent uses it

  • Needs a security assessment — threat modeling
  • Vulnerability review
  • Auth flow audit
  • Dependency scanning

Example prompts

  • “is this secure”
  • “review for vulnerabilities”
  • “threat model”
  • “/security-review”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Scope definition — Establish attack surface boundaries. Identify all components, data flows, and trust boundaries. Confirm authorization…
  2. Automated scanning — Execute tooling before manual review
  3. Manual code review — Conduct contextual analysis that automated tools miss
  4. Validation and classification — Test findings and assign severity
  5. Reporting — Document vulnerabilities with precise locations, business impact, and corrective actions. Deliver a prioritized remediation…

What it can do on your machine

Read from SKILL.md and the folder at commit 4ad31b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • trivy
    • npm
    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 1.8k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 716 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shawnpang/startup-founder-skills at commit 4ad31b4, republished under its MIT licence (© shawnpang). 716 words, ~1,847 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".
related
code-review, architecture-design, soc2-prep
reads
startup-context

Security Review

When to Use

  • The user wants a security audit of their application, infrastructure, or specific feature
  • They need a threat model before launching or a penetration test preparation review
  • They have a dependency vulnerability alert and need remediation guidance
  • They are handling sensitive data (PII, payment, health) and need verification
  • Code audit, secrets detection, or compliance assessment is requested

Context Required

From startup-context: tech stack, deployment environment, compliance requirements, data types. Also ask:

  • Scope — Full app, feature, auth system, single PR, infrastructure, or cloud environment
  • Data types — PII, payment, health, credentials, or other sensitive data handled
  • Compliance requirements — SOC 2, HIPAA, PCI-DSS, GDPR, ISO 27001
  • Authorization — Confirm written authorization exists before any active testing

Workflow

Follow a five-phase methodology. Automated scanning precedes manual review. Authorization verification is mandatory before active testing.

  1. Scope definition — Establish attack surface boundaries. Identify all components, data flows, and trust boundaries. Confirm authorization. Define in-scope and out-of-scope.
  2. Automated scanning — Execute tooling before manual review:
    • SAST: semgrep --config=auto across the codebase
    • Dependency audit: npm audit / pip-audit / govulncheck / trivy fs .
    • Secrets detection: Scan for hardcoded credentials, API keys, tokens in source
    • Container scanning: trivy image for containerized deployments
    • Record all automated findings for validation in the next phase.
  3. Manual code review — Conduct contextual analysis that automated tools miss:
    • Authentication and authorization flow tracing end-to-end
    • Business logic vulnerabilities (price manipulation, race conditions, privilege escalation)
    • Data flow analysis for sensitive information (where does PII enter, transit, and persist?)
    • STRIDE threat modeling against each component and data flow
  4. Validation and classification — Test findings and assign severity:
    • Validate automated findings to eliminate false positives
    • Assign CVSS v3.1 scores; assess exploitability in context
    • Classify by business impact, not just technical severity
  5. Reporting — Document vulnerabilities with precise locations, business impact, and corrective actions. Deliver a prioritized remediation roadmap.

Output Format

markdown
# Security Review: [Scope Description]

## Executive Summary
Overall risk posture (Critical / High / Medium / Low), top findings count, and business impact summary.

## Threat Model (STRIDE)
| Threat | Category | Asset | Impact | Likelihood | Risk |

## Findings
### Critical / High / Medium / Low
- **[SEC-N] Title** — CVSS X.X — file:line — description, business impact, remediation with code example

## Auth Flow Assessment
End-to-end trace of authentication and authorization with findings.

## Dependency Vulnerabilities
| Package | Current Version | CVSS | Fix Version | Exploitable in Context? |

## Remediation Roadmap
Prioritized action list with timelines.

Frameworks & Best Practices

STRIDE Threat Modeling

Apply to every component and data flow:

  • Spoofing — Can attackers forge tokens or impersonate users? Are API keys rotatable?
  • Tampering — Can requests be modified in transit? Are webhooks signed? Is data integrity verified?
  • Repudiation — Are critical actions logged? Are logs tamper-evident?
  • Information Disclosure — Stack traces in error responses? PII encrypted at rest and in transit?
  • Denial of Service — Rate limits in place? Can one user exhaust resources for all?
  • Elevation of Privilege — Can regular users access admin functions? Are role checks server-side?
Show full SKILL.md (325 more words)Show less
OWASP Top 10 Checks
  1. Injection — Parameterize SQL/NoSQL; check OS commands, SSTI, LDAP
  2. Broken Auth — argon2id/bcrypt, session timeout, rate limiting on login
  3. Data Exposure — TLS 1.2+, PII encrypted at rest, HSTS headers
  4. XXE — Disable DTD processing, prefer JSON over XML
  5. Access Control — Server-side authz on every endpoint, no IDOR, CORS whitelist
  6. Misconfig — Debug mode off, default credentials removed, security headers present
  7. XSS — Output encoding, Content Security Policy, HTTP-only cookies
  8. Deserialization — Validate schema, prefer JSON, reject untrusted serialized objects
  9. Vulnerable Deps — npm audit, pip-audit, trivy, govulncheck
  10. Logging — Auth events, admin actions, access violations logged with alerts
CVSS v3.1 Scoring Guide
  • Critical (9.0-10.0): RCE, auth bypass, full data breach, complete system compromise
  • High (7.0-8.9): Privilege escalation, significant data exposure, SSRF to internal services
  • Medium (4.0-6.9): Stored XSS, CSRF, limited IDOR, information disclosure
  • Low (0.1-3.9): Missing security headers, minor info disclosure, verbose errors
Auth Flow Checklist
  • Passwords: argon2id or bcrypt (cost >= 10)
  • JWT: 15-min access tokens, 7-day refresh tokens rotated on use
  • Rate limiting: 5 attempts / 15 min on auth endpoints
  • Sessions invalidated on password change
  • OAuth state parameter validated, scoped API keys
  • MFA enforced for admin accounts
  • Password reset tokens are single-use and time-limited
Scanning Tools
  • SAST: semgrep --config=auto (all stacks), bandit (Python), gosec (Go), eslint-plugin-security (Node)
  • Dependencies: npm audit / pip-audit / govulncheck / trivy fs .
  • Containers: trivy image
Mandatory Constraints
  • Never test production without explicit written authorization
  • Never exploit beyond proof-of-concept demonstration
  • Always sequence automated scanning before manual review
Remediation Priority
  1. Actively exploitable + critical data — immediately
  2. Auth/authz bypass — 24 hours
  3. Injection — 48 hours
  4. Data exposure / critical CVEs — 1 week
  5. Config hardening — 2 weeks
  6. Defense-in-depth — next sprint
  • code-review — chain when findings require code-level fixes and review
  • architecture-design — chain when findings reveal architectural security flaws
  • soc2-prep — chain when review is part of compliance preparation

Examples

Example prompt: "Review the security of our user authentication system. We use JWT with Express."

Good output snippet:

# Security Review: JWT Authentication System

## Executive Summary
Risk posture: **Critical**. Hardcoded JWT secret and non-expiring tokens.

## Findings
### Critical (CVSS 9.8)
- **[SEC-1] Hardcoded JWT secret** — auth/config.js:3 — Secret is
  "supersecret123". Attacker can forge any token.
  **Fix:** Move to env var, generate with `openssl rand -base64 64`.

### Critical (CVSS 9.1)
- **[SEC-2] Tokens never expire** — auth/jwt.js:12 — No `expiresIn`.
  **Fix:** Set `expiresIn: '15m'`, implement refresh token rotation.

© shawnpang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-review of shawnpang/startup-founder-skills.

Open the folder on GitHubat commit 4ad31b4

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skillshawnpang/startup-founder-skills343—~1.8kAutomated safety check: PassMIT
Commit Security Scancodexstar69/bug-hunter520—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills157—~3.2kAutomated safety check: PassMIT
Threat Mitigation Mappingwshobson/agents40k8 repos~742Automated safety check: PassMIT
Audit Browser Security Boundariesnordstjernen-web/northstar-browser127—~920Automated safety check: PassGPL-3.0
Security Auditblueberrycongee/termcanvas405—~966Automated safety check: NotesMIT

Similar skills

  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    520 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed
  • Audit Browser Security Boundaries

    nordstjernen-web/northstar-browser

    Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

    127 GitHub stars~920 tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    blueberrycongee/termcanvas

    Security audit skill. An agent skill from blueberrycongee/termcanvas.

    405 GitHub stars~966 tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Security Review

    codexstar69/bug-hunter

    Run a focused STRIDE-based security review using Bug Hunter-native artifacts.

    520 GitHub stars~567 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from shawnpang/startup-founder-skills

All 50 skills in this repo
  • Accelerator Application

    shawnpang/startup-founder-skills

    When the user wants to apply to startup accelerators, incubators, or fellowship programs.

    343 GitHub stars~2.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Architecture Design

    shawnpang/startup-founder-skills

    When the user needs to design or evaluate system architecture — service boundaries, data models, API contracts, infrastructure topology, database selection, or dependency analysis.

    343 GitHub stars~2.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Board Update

    shawnpang/startup-founder-skills

    When the user needs to write a monthly or quarterly investor update, prepare a board deck, or communicate company progress to stakeholders.

    343 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Churn Analysis

    shawnpang/startup-founder-skills

    When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.

    343 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Cicd Setup

    shawnpang/startup-founder-skills

    When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".

    343 GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Code Review

    shawnpang/startup-founder-skills

    When the user asks for a code review, shares code for feedback, or says "review this", "check my code", "what's wrong with this".

    343 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Security Review

What does Security Review do?

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…. Security Review is an agent skill from shawnpang/startup-founder-skills. When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".

When should I use Security Review?

Security Review fits situations like: needs a security assessment — threat modeling; vulnerability review; auth flow audit; dependency scanning.

How do I install Security Review in Claude Code?

Run `npx skills add shawnpang/startup-founder-skills --skill security-review -a claude-code`. Or copy the skill folder (skills/security-review in shawnpang/startup-founder-skills) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add shawnpang/startup-founder-skills --skill security-review -a codex`. Or copy the skill folder (skills/security-review in shawnpang/startup-founder-skills) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shawnpang/startup-founder-skills --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (trivy, npm and semgrep).

Does Security Review access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Commit Security Scan (codexstar69/bug-hunter, 520 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars) and Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

shawnpang (a GitHub user) maintains it in shawnpang/startup-founder-skills, which has 343 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on March 16, 2026.

Source: shawnpang/startup-founder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.