Agent skill

Owasp Security Code Review

by SpecterOps in SpecterOps/skills

Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests.

Apache-2.0Auto-check passedSecurity

Install Owasp Security Code Review

skills CLI
$ npx skills add SpecterOps/skills --skill owasp-security-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills owasp-security-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/owasp-security-code-review .claude/skills/owasp-security-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
owasp-security-code-review
GitHub stars
702
Token cost
~2.3k tokens
SKILL.md length
982 words
Files
17 (incl. references)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests.

  • Works in 9 steps: Review architecture for security… → Analyze entry points and input validation. → Verify authentication and authorization. → …
  • Codex needs to audit source code for security flaws
  • SKILL.md covers Review Principles, References, Review Process and Finding Standard, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Owasp Security Code Review is an agent skill from SpecterOps/skills. Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests. Use when Codex needs to audit source code for security flaws, map trust boundaries, verify authentication or authorization, trace untrusted data to sensitive sinks, assess business logic or cryptography, or produce prioritized findings when no narrower language or platform review skill fits.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including reference files (for example `agents/openai.yaml`, `references/attack-trees.md` and `references/common-vulnerability-patterns.md`).

It sits in Security, covering Web application vulnerabilities, Code review and Cryptography. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Codex needs to audit source code for security flaws
  • Map trust boundaries
  • Verify authentication
  • Trace untrusted data to sensitive sinks

Example prompts

  • “/owasp-security-code-review”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Review architecture for security anti-patterns.
  2. Analyze entry points and input validation.
  3. Verify authentication and authorization.
  4. Trace data flows.
  5. Analyze business logic.
  6. Review cryptographic implementation.
  7. Verify error handling.
  8. Review configuration and deployment.
  9. Build the PoC artifacts.

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Owasp Security Code Review loads about 2.3k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 982 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 982 words, ~2,332 tokens.

Download SKILL.mdSave it as .claude/skills/owasp-security-code-review/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
owasp-security-code-review
description
Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests. Use when Codex needs to audit source code for security flaws, map trust boundaries, verify authentication or authorization, trace untrusted data to sensitive sinks, assess business logic or cryptography, or produce prioritized findings when no narrower language or platform review skill fits.

OWASP Security Code Review

Use this skill to perform a manual security review that starts from architecture and follows concrete execution paths. Prefer a narrower language, framework, CI, cloud, or infrastructure review skill when one clearly fits; use this skill for baseline coverage and cross-cutting review logic.

Review Principles

  • Build a threat model before reporting issues: identify actors, assets, trust boundaries, privilege levels, and attacker-controlled inputs.
  • Treat entry points, identity decisions, privilege changes, and sensitive data movement as primary anchors.
  • Confirm issues end to end from source through transformations and guards to sink or security decision.
  • Separate confirmed vulnerabilities from suspicious patterns and unanswered questions.
  • Prefer a small number of well-supported findings over speculative issue lists.
  • Keep coverage visible: record reviewed surfaces, skipped areas, and assumptions that affect confidence.
  • Always create or update one standalone poc_<finding_slug>.py artifact per confirmed finding in the review workspace.

References

Review Process

  1. Review architecture for security anti-patterns.

    • Inventory components, languages, frameworks, storage, external integrations, privileged jobs, and deployment boundaries.
    • Identify trust assumptions such as internal-network trust, shared admin paths, tenant co-mingling, unsafe plugin or deserialization surfaces, dynamic code execution, and secret-bearing services.
    • Note where security controls are centralized and where alternate paths may bypass them.
  2. Analyze entry points and input validation.

    • Enumerate HTTP/RPC routes, GraphQL resolvers, message consumers, webhooks, CLI commands, scheduled jobs, file imports, deserializers, and configuration inputs.
    • Trace parsing, normalization, canonicalization, schema checks, type checks, size limits, allowlists, and rejection behavior.
    • Look for alternate encodings, duplicate parameters, path confusion, object binding issues, and validation performed after a dangerous sink.
  3. Verify authentication and authorization.

    • Map how identities are established, refreshed, propagated, and revoked across user, service, and background-job flows.
    • Check session, token, API key, mTLS, and service-account validation assumptions.
    • Verify every read, write, export, and state transition enforces the required role, tenant, ownership, and object-level checks, including alternate routes and asynchronous handlers.
    • Test fail-open behavior when middleware, policy engines, or upstream identity data is absent or malformed.
  4. Trace data flows.

    • Follow untrusted data to SQL/NoSQL queries, templates, filesystem paths, archives, redirects, outbound requests, command execution, logs, serialization, caches, and client responses.
    • Follow sensitive data such as credentials, tokens, personal data, and keys through storage, telemetry, errors, exports, and third-party boundaries.
    • Record sanitizers, encoders, escaping, parameterization, and privilege boundaries on each path; verify that each control is appropriate for the sink.
  5. Analyze business logic.

    • Model critical workflows as states and invariants: approvals, payments, invitations, password resets, account recovery, quotas, entitlements, tenant isolation, and admin actions.
    • Check replay, race, ordering, stale-state, double-spend, partial-failure, and TOCTOU behavior.
    • Look for ways to skip steps, reuse artifacts, change identifiers, or invoke a privileged transition through an unexpected channel.
  6. Review cryptographic implementation.

    • Identify password hashing, encryption, signatures, MACs, randomness, key derivation, key storage, certificate validation, and token construction.
    • Verify modern primitives, secure parameters, nonce/IV uniqueness, constant-time comparisons where relevant, key separation, rotation, and failure behavior.
    • Treat custom crypto, hardcoded keys, weak randomness, disabled TLS verification, and unsigned or partially verified tokens as priority review areas.
  7. Verify error handling.

    • Check whether errors fail closed at authentication, authorization, validation, and transaction boundaries.
    • Review exception swallowing, fallback behavior, retries, partial commits, default values, verbose responses, stack traces, and secret-bearing logs.
    • Confirm that security-relevant failures are observable without leaking sensitive details.
  8. Review configuration and deployment.

    • Inspect defaults and environment parsing for debug modes, CORS, trusted proxies, host validation, cookie flags, security headers, logging, feature flags, and secret loading.
    • Review container/runtime privileges, filesystem permissions, network exposure, cloud/IAM bindings, CI/CD secrets, build-time substitutions, and production-vs-development drift when those artifacts are in scope.
    • Identify insecure defaults that make a secure deployment depend on undocumented operator behavior.
  9. Build the PoC artifacts.

    • Create or update one standalone poc_<finding_slug>.py file for each confirmed finding.
    • Keep each PoC incremental: print or implement numbered steps for prerequisites, authentication or material acquisition, trigger, impact verification, and cleanup guidance.
    • State attacker position, required permissions, credentials or certificates, environmental dependencies, and any unproven prerequisite before sending requests.
    • Default to dry-run or harmless markers and require an explicit flag for state-changing validation.
    • If a finding has no safe runnable path, still create its per-finding PoC scaffold and explain the missing prerequisite or unsafe step.
    • Validate each script with syntax checks and dry runs, then record which live steps were and were not executed.
Show full SKILL.md (156 more words)Show less

Finding Standard

Report a finding only when the review can state:

  • the affected code path with file and line references
  • the attacker-controlled input or violated trust assumption
  • the missing, bypassed, or incorrect control
  • the reachable impact and required prerequisites
  • a concrete remediation direction
  • a focused regression test or validation step

If a concern lacks a complete path or depends on missing runtime context, label it as an open question or coverage gap instead of a confirmed vulnerability.

Output

Lead with findings ordered by severity. For each finding, include Severity, Location, Issue, Exploit Path, Impact, Remediation, Test, and PoC Requirements.

For each confirmed finding, reference the corresponding poc_<finding_slug>.py artifact in the report and include the minimum attacker position, required permissions or credentials, environmental conditions, safe default behavior, and example invocation.

After findings, include Open Questions / Assumptions and Coverage. If no confirmed findings exist, say so explicitly and still state the reviewed surfaces, unresolved risks, and test gaps.

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (references) in skills/owasp-security-code-review of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • references/attack-trees.md
  • references/common-vulnerability-patterns.md
  • references/owasp-authentication.md
  • references/owasp-authorization.md
  • references/owasp-cryptographic-storage.md
  • references/owasp-deserialization.md
  • references/owasp-file-upload.md
  • references/owasp-input-validation.md
  • references/owasp-nosql-security.md
  • references/owasp-os-command-injection.md
  • references/owasp-secure-code-review.md
  • references/owasp-session-management.md
  • references/owasp-sql-injection.md
  • references/owasp-xss.md
  • references/owasp-xxe.md

Open the folder on GitHubat commit e655f93

Compare with similar skills

Owasp Security Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Owasp Security Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Owasp Security Code Review this skillSpecterOps/skills702—~2.3kAutomated safety check: PassApache-2.0
Code Review SecurityOWASP/secure-agent-playbook186—~549Automated safety check: PassCC-BY-4.0
Code Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~1.4kAutomated safety check: NotesApache-2.0
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Review Securitynicepkg/auto-company1921 repos~3.9kAutomated safety check: PassMIT

Similar skills

  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    186 GitHub stars~549 tokensUpdated 12 days ago
    DevelopmentAuto-check passed
  • Code Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Default code-quality route for broad code review, PR review, maintainability, correctness, and regression-risk checks.

    3.6k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review Security

    nicepkg/auto-company

    Security-focused code review checklist and automated scanning patterns.

    192 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check passed
  • Trailmark Review Gate

    trailofbits/skills

    Official

    Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.

    7.4k GitHub stars~1.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    702 GitHub stars~805 tokensUpdated 14 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    702 GitHub stars~1.5k tokensUpdated 14 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    702 GitHub stars~2.4k tokensUpdated 14 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    702 GitHub stars~665 tokensUpdated 14 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    702 GitHub stars~738 tokensUpdated 14 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    702 GitHub stars~813 tokensUpdated 14 days ago
    Auto-check passed

Questions about Owasp Security Code Review

What does Owasp Security Code Review do?

Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests. Owasp Security Code Review is an agent skill from SpecterOps/skills. Perform evidence-driven security code reviews across application repositories, services, libraries, and pull requests.

When should I use Owasp Security Code Review?

Owasp Security Code Review fits situations like: Codex needs to audit source code for security flaws; map trust boundaries; verify authentication; trace untrusted data to sensitive sinks.

How do I install Owasp Security Code Review in Claude Code?

Run `npx skills add SpecterOps/skills --skill owasp-security-code-review -a claude-code`. Or copy the skill folder (skills/owasp-security-code-review in SpecterOps/skills) into .claude/skills/owasp-security-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Owasp Security Code Review in Codex?

Run `npx skills add SpecterOps/skills --skill owasp-security-code-review -a codex`. Or copy the skill folder (skills/owasp-security-code-review in SpecterOps/skills) into .agents/skills/owasp-security-code-review in your project. Codex loads it when a task matches its description.

Can I use Owasp Security Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill owasp-security-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/owasp-security-code-review, .gemini/skills/owasp-security-code-review, .github/skills/owasp-security-code-review and .opencode/skills/owasp-security-code-review in your project.

What does Owasp Security Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Owasp Security Code Review is instructions for the agent only.

Does Owasp Security Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Owasp Security Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Owasp Security Code Review use?

Owasp Security Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Owasp Security Code Review use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Owasp Security Code Review?

Skills that share tags, products or a category with Owasp Security Code Review: Code Review Security (OWASP/secure-agent-playbook, 186 stars), Code Reviewer (foryourhealth111-pixel/Vibe-Skills, 3.6k stars), Security Review (getsentry/skills, 1k stars) and Code Reviewer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Owasp Security Code Review?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.