Agent skill

Cwe Code Review

by SpecterOps in SpecterOps/skills

Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

Apache-2.0Auto-check passedDevelopment

Install Cwe Code Review

skills CLI
$ npx skills add SpecterOps/skills --skill cwe-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills cwe-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cwe-code-review .claude/skills/cwe-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cwe-code-review
GitHub stars
702
Token cost
~2.4k tokens
SKILL.md length
1,069 words
Files
10 (incl. scripts, references)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

  • Works in 6 steps: Build a threat model and code inventory. → Trace security-relevant paths. → Discover candidate weaknesses. → …
  • Codex needs to audit source code
  • SKILL.md covers Review Principles, References, Lookup Workflow and Review Process, plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Cwe Code Review is an agent skill from SpecterOps/skills. Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema semantics. Use when Codex needs to audit source code or pull requests, identify root-cause weakness classes, distinguish broad symptoms from mappable CWEs, justify CWE IDs in findings, or review code against CWE views such as Software Development, Research Concepts, Top 25, OWASP, language-specific, or AI/ML weakness sets.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/cwe-catalog-metadata.json` and `references/cwe-catalog-summary.md`).

It sits in Development, covering Code review, Web application vulnerabilities and Pull requests. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Codex needs to audit source code
  • Identify root-cause weakness classes
  • Distinguish broad symptoms from mappable CWEs
  • Justify CWE IDs in findings

Example prompts

  • “/cwe-code-review”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Build a threat model and code inventory.
  2. Trace security-relevant paths.
  3. Discover candidate weaknesses.
  4. Validate the mapping.
  5. Report only confirmed findings.
  6. Build the PoC artifacts.

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cwe Code Review loads about 2.4k tokens when it runs, and up to ~1.7M if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 1,069 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7M

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 1,069 words, ~2,352 tokens.

Download SKILL.mdSave it as .claude/skills/cwe-code-review/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
cwe-code-review
description
Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema semantics. Use when Codex needs to audit source code or pull requests, identify root-cause weakness classes, distinguish broad symptoms from mappable CWEs, justify CWE IDs in findings, or review code against CWE views such as Software Development, Research Concepts, Top 25, OWASP, language-specific, or AI/ML weakness sets.

CWE Code Review

Use this skill for manual security review when the result needs defensible CWE mapping, not just a list of suspicious patterns. Prefer a narrower language, framework, CI, cloud, or infrastructure review skill when one clearly fits; use this skill to add CWE precision and cross-cutting review logic.

Review Principles

  • Start from architecture, trust boundaries, attacker-controlled inputs, sensitive assets, and reachable sinks.
  • Confirm a code path before assigning a CWE. A keyword match or a dangerous API alone is not a finding.
  • Use CWE as a root-cause taxonomy. Prefer the most precise supported weakness over a broad Pillar, Class, Category, or View.
  • Treat mapping notes as part of the evidence. Allowed and Allowed-with-Review entries are usually better finding mappings than Discouraged or Prohibited entries.
  • Use Top 25, OWASP, language, and lifecycle views for coverage and prioritization context, not as severity proof.
  • Keep unsupported hypotheses as open questions or coverage gaps instead of forcing a CWE mapping.
  • Always create or update one standalone poc_<finding_slug>.py artifact per confirmed finding in the review workspace, with exploit prerequisites and validation steps for that finding.

References

Lookup Workflow

Resolve this skill directory, then use the lookup helper from that directory:

bash
python3 scripts/cwe_lookup.py --query "server-side request forgery"
python3 scripts/cwe_lookup.py --id 918
python3 scripts/cwe_lookup.py --id CWE-79 --full
python3 scripts/cwe_lookup.py --view 1435 --limit 30
python3 scripts/cwe_lookup.py --phase Implementation --functional-area Authorization --limit 20
python3 scripts/cwe_lookup.py --impact "Execute Unauthorized Code or Commands" --mapping Allowed --limit 20

Use --query to discover candidates, then --id to read the mapping notes, relationships, consequences, detection methods, and mitigations before naming a CWE in a finding.

Review Process

  1. Build a threat model and code inventory.

    • Identify components, entry points, identities, privilege levels, data stores, external integrations, sensitive assets, and deployment boundaries.
    • Record attacker-controlled inputs, security decisions, and trust assumptions.
  2. Trace security-relevant paths.

    • Follow untrusted data to queries, templates, files, archives, URLs, deserializers, process execution, logs, caches, and client responses.
    • Follow identity, authorization, session, secret, cryptographic, and business-state decisions through alternate routes and asynchronous handlers.
    • Record controls, normalization, validation, encoding, authorization checks, failure behavior, and privilege transitions.
  3. Discover candidate weaknesses.

    • Query by sink, violated control, impact, lifecycle phase, or functional area.
    • Use view references to widen coverage when the repository exposes a relevant language, platform, lifecycle, OWASP, Top 25, mobile, or AI/ML surface.
    • Use parent and child relationships to move from broad symptoms toward a precise root cause.
  4. Validate the mapping.

    • Read the candidate record with --id.
    • Check Abstraction, Status, Mapping Usage, mapping rationale, relationship context, and suggestions.
    • Prefer Base or Variant entries when the evidence supports them. Use Compound entries when the exploit requires the combined condition.
    • Avoid mapping a finding to a Category or View. Avoid a Pillar or broad Class when a supported child weakness matches the actual failure.
    • If the best entry is Allowed-with-Review, state why the code path fits that entry. If the best visible entry is Discouraged or Prohibited, keep searching or explain the mapping gap.
  5. Report only confirmed findings.

    • Tie each finding to file and line references, attacker influence, the missing or incorrect control, reachable impact, and a focused remediation.
    • Name one primary CWE mapping per finding. Mention secondary CWE relationships only when they explain a distinct contributing weakness or attack chain.
    • Include concise syntax-highlighted code blocks for the affected source or configuration sections that establish the input, missing control, sensitive sink, or authorization decision.
    • Include a regression test or validation step that would fail before the fix and pass after it.
  6. Build the PoC artifacts.

    • Create or update one standalone poc_<finding_slug>.py file in the review workspace for each confirmed finding.
    • Do not combine unrelated findings into one harness unless the user explicitly asks for a consolidated runner.
    • Make each path incremental: print or implement numbered steps for prerequisites, authentication or material acquisition, trigger, impact verification, and cleanup guidance.
    • State attacker position, required permissions, credentials or certificates, environmental dependencies, and any unproven prerequisite before sending requests.
    • Default to dry-run or harmless markers and require an explicit flag for state-changing validation. Do not overclaim impact when a later exploit step remains unproven.
    • If a confirmed finding has no runnable path, still create its per-finding PoC scaffold and explain the missing prerequisite or why exploitation was not confirmed.
Show full SKILL.md (322 more words)Show less

PoC Artifacts

Per-finding PoC scripts are part of the review output, not an optional appendix. Each script should help another reviewer reproduce one finding without reconstructing the exploit chain from prose.

  • Prefer standalone standard-library scripts named poc_<finding_slug>.py. Duplicating small amounts of transport or auth plumbing is acceptable when it keeps each PoC independently runnable.
  • Keep requirements discoverable through python3 poc_<finding_slug>.py --requirements or equivalent help text.
  • Model chained findings explicitly. If one finding yields the credential or primitive required by another, state the dependency and expose the steps separately.
  • Use safe default destinations, fake secrets, and non-destructive checks where they still prove the root cause. Put stronger impact demonstrations behind explicit arguments and document the side effects.
  • Validate each script locally with syntax checks and dry runs, then record which live steps were and were not executed.

Finding Standard

Lead with findings ordered by severity. For each finding include Severity, Location, Issue, CWE, Evidence, Exploit Path, Impact, Remediation, and Test.

For CWE, include the identifier, name, and one sentence explaining why that entry is the precise root-cause mapping. Note Allowed-with-Review caveats when applicable.

For Evidence, include line-scoped fenced code blocks with an appropriate language tag such as python, go, javascript, yaml, json, nginx, bash, or sql. Put the source path and line range immediately above each block. Keep excerpts narrow enough to show the relevant control flow without dumping whole modules, and include supporting configuration blocks when they are part of the exploit path.

For each finding, also include PoC Requirements and reference the corresponding poc_<finding_slug>.py artifact and step sequence.

After findings, include Open Questions / Assumptions and Coverage. If no confirmed findings exist, say so explicitly and still state the reviewed surfaces, unresolved risks, test gaps, and that no per-finding PoC artifacts were created.

Regeneration

Rebuild the derived corpus when a newer CWE catalog or schema is provided:

bash
python3 scripts/build_cwe_references.py \
  --catalog /path/to/cwec.xml \
  --schema /path/to/cwe_schema.xsd

Keep the generated references aligned with the source catalog and schema version recorded in references/cwe-catalog-summary.md.

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in skills/cwe-code-review of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • references/cwe-catalog-metadata.json
  • references/cwe-catalog-summary.md
  • references/cwe-records.jsonl
  • references/cwe-review-views.md
  • references/cwe-schema-guide.md
  • references/cwe-weakness-index.md
  • scripts/build_cwe_references.py
  • scripts/cwe_lookup.py

Open the folder on GitHubat commit e655f93

Compare with similar skills

Cwe Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cwe Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cwe Code Review this skillSpecterOps/skills702—~2.4kAutomated safety check: PassApache-2.0
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Review SecurityOWASP/secure-agent-playbook186—~549Automated safety check: PassCC-BY-4.0
Code Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~1.4kAutomated safety check: NotesApache-2.0
Code Overviewtestdouble/han279—~8.5kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    186 GitHub stars~549 tokensUpdated 12 days ago
    DevelopmentAuto-check passed
  • Code Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.

    3.6k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Code Overview

    testdouble/han

    Produces a human-readable, progressive-disclosure overview of unfamiliar code or a pull request's changes — why it exists (the real problem it solves or goal it serves for the business or a user)…

    279 GitHub stars~8.5k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    702 GitHub stars~805 tokensUpdated 14 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    702 GitHub stars~1.5k tokensUpdated 14 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    702 GitHub stars~665 tokensUpdated 14 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    702 GitHub stars~738 tokensUpdated 14 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    702 GitHub stars~813 tokensUpdated 14 days ago
    Auto-check passed
  • Proxychains Tunnel

    SpecterOps/skills

    Run in-scope network commands through a SOCKS5 tunnel with proxychains4, including tunnel readiness checks and evidence capture.

    702 GitHub stars~826 tokensUpdated 14 days ago
    Auto-check passed

Categories

Questions about Cwe Code Review

What does Cwe Code Review do?

Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…. Cwe Code Review is an agent skill from SpecterOps/skills. Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema semantics.

When should I use Cwe Code Review?

Cwe Code Review fits situations like: Codex needs to audit source code; identify root-cause weakness classes; distinguish broad symptoms from mappable CWEs; justify CWE IDs in findings.

How do I install Cwe Code Review in Claude Code?

Run `npx skills add SpecterOps/skills --skill cwe-code-review -a claude-code`. Or copy the skill folder (skills/cwe-code-review in SpecterOps/skills) into .claude/skills/cwe-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Cwe Code Review in Codex?

Run `npx skills add SpecterOps/skills --skill cwe-code-review -a codex`. Or copy the skill folder (skills/cwe-code-review in SpecterOps/skills) into .agents/skills/cwe-code-review in your project. Codex loads it when a task matches its description.

Can I use Cwe Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill cwe-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cwe-code-review, .gemini/skills/cwe-code-review, .github/skills/cwe-code-review and .opencode/skills/cwe-code-review in your project.

What does Cwe Code Review need to run?

Going by SKILL.md and its folder, Cwe Code Review needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Cwe Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cwe Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cwe Code Review use?

Cwe Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cwe Code Review use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7M tokens, read only when the agent opens those files.

What are the alternatives to Cwe Code Review?

Skills that share tags, products or a category with Cwe Code Review: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review Security (OWASP/secure-agent-playbook, 186 stars), Code Reviewer (foryourhealth111-pixel/Vibe-Skills, 3.6k stars) and Code Overview (testdouble/han, 279 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cwe Code Review?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.