Commit Security Scan
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install shawnpang/startup-founder-skills security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-review .claude/skills/security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-review" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-review into .claude/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install shawnpang/startup-founder-skills security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-review .agents/skills/security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-review" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-review into .agents/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install shawnpang/startup-founder-skills security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-review .cursor/skills/security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-review" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-review into .cursor/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/shawnpang/startup-founder-skills.git --path skills/security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install shawnpang/startup-founder-skills security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-review .gemini/skills/security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-review into .gemini/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install shawnpang/startup-founder-skills security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-review .github/skills/security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-review into .github/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shawnpang/startup-founder-skills --skill security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install shawnpang/startup-founder-skills security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-review .opencode/skills/security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/security-review into .opencode/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-reviewWhen the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…
Security Review is an agent skill from shawnpang/startup-founder-skills. When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review, Threat modeling and Authentication. The repository describes itself as: AI agent skills for tech startup founders — fundraising, sales, product, recruiting, engineering, legal, ops, and growth. Works with Claude Code, Cursor, Codex, and any Agent… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4ad31b4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
trivynpmsemgrepFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Review loads about 1.8k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 716 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from shawnpang/startup-founder-skills at commit 4ad31b4, republished under its MIT licence (© shawnpang). 716 words, ~1,847 tokens.
.claude/skills/security-review/SKILL.md (or your agent's skills folder).From startup-context: tech stack, deployment environment, compliance requirements, data types. Also ask:
Follow a five-phase methodology. Automated scanning precedes manual review. Authorization verification is mandatory before active testing.
semgrep --config=auto across the codebasenpm audit / pip-audit / govulncheck / trivy fs .trivy image for containerized deployments# Security Review: [Scope Description]
## Executive Summary
Overall risk posture (Critical / High / Medium / Low), top findings count, and business impact summary.
## Threat Model (STRIDE)
| Threat | Category | Asset | Impact | Likelihood | Risk |
## Findings
### Critical / High / Medium / Low
- **[SEC-N] Title** — CVSS X.X — file:line — description, business impact, remediation with code example
## Auth Flow Assessment
End-to-end trace of authentication and authorization with findings.
## Dependency Vulnerabilities
| Package | Current Version | CVSS | Fix Version | Exploitable in Context? |
## Remediation Roadmap
Prioritized action list with timelines.Apply to every component and data flow:
npm audit, pip-audit, trivy, govulnchecksemgrep --config=auto (all stacks), bandit (Python), gosec (Go), eslint-plugin-security (Node)npm audit / pip-audit / govulncheck / trivy fs .trivy imagecode-review — chain when findings require code-level fixes and reviewarchitecture-design — chain when findings reveal architectural security flawssoc2-prep — chain when review is part of compliance preparationExample prompt: "Review the security of our user authentication system. We use JWT with Express."
Good output snippet:
# Security Review: JWT Authentication System
## Executive Summary
Risk posture: **Critical**. Hardcoded JWT secret and non-expiring tokens.
## Findings
### Critical (CVSS 9.8)
- **[SEC-1] Hardcoded JWT secret** — auth/config.js:3 — Secret is
"supersecret123". Attacker can forge any token.
**Fix:** Move to env var, generate with `openssl rand -base64 64`.
### Critical (CVSS 9.1)
- **[SEC-2] Tokens never expire** — auth/jwt.js:12 — No `expiresIn`.
**Fix:** Set `expiresIn: '15m'`, implement refresh token rotation.© shawnpang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-review of shawnpang/startup-founder-skills.
Open the folder on GitHubat commit 4ad31b4
Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Review this skillshawnpang/startup-founder-skills | 343 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Commit Security Scancodexstar69/bug-hunter | 520 | — | ~629 | Automated safety check: Pass | MIT | |
| Auditing Code For Vulnerabilitiestrilwu/secskills | 157 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Threat Mitigation Mappingwshobson/agents | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | |
| Audit Browser Security Boundariesnordstjernen-web/northstar-browser | 127 | — | ~920 | Automated safety check: Pass | GPL-3.0 | |
| Security Auditblueberrycongee/termcanvas | 405 | — | ~966 | Automated safety check: Notes | MIT |
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
wshobson/agents
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
nordstjernen-web/northstar-browser
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
blueberrycongee/termcanvas
Security audit skill. An agent skill from blueberrycongee/termcanvas.
codexstar69/bug-hunter
Run a focused STRIDE-based security review using Bug Hunter-native artifacts.
shawnpang/startup-founder-skills
When the user wants to apply to startup accelerators, incubators, or fellowship programs.
shawnpang/startup-founder-skills
When the user needs to design or evaluate system architecture — service boundaries, data models, API contracts, infrastructure topology, database selection, or dependency analysis.
shawnpang/startup-founder-skills
When the user needs to write a monthly or quarterly investor update, prepare a board deck, or communicate company progress to stakeholders.
shawnpang/startup-founder-skills
When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.
shawnpang/startup-founder-skills
When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".
shawnpang/startup-founder-skills
When the user asks for a code review, shares code for feedback, or says "review this", "check my code", "what's wrong with this".
Categories
When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…. Security Review is an agent skill from shawnpang/startup-founder-skills. When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".
Security Review fits situations like: needs a security assessment — threat modeling; vulnerability review; auth flow audit; dependency scanning.
Run `npx skills add shawnpang/startup-founder-skills --skill security-review -a claude-code`. Or copy the skill folder (skills/security-review in shawnpang/startup-founder-skills) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add shawnpang/startup-founder-skills --skill security-review -a codex`. Or copy the skill folder (skills/security-review in shawnpang/startup-founder-skills) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shawnpang/startup-founder-skills --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.
Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (trivy, npm and semgrep).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Review: Commit Security Scan (codexstar69/bug-hunter, 520 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars) and Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
shawnpang (a GitHub user) maintains it in shawnpang/startup-founder-skills, which has 343 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on March 16, 2026.
Source: shawnpang/startup-founder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.