Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.
$ npx skills add symfony/symfony --skill symfony-security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install symfony/symfony symfony-security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/symfony-security-review .claude/skills/symfony-security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "symfony-security-review" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-review into .claude/skills/symfony-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symfony-security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add symfony/symfony --skill symfony-security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install symfony/symfony symfony-security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/symfony-security-review .agents/skills/symfony-security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "symfony-security-review" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-review into .agents/skills/symfony-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symfony-security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add symfony/symfony --skill symfony-security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install symfony/symfony symfony-security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/symfony-security-review .cursor/skills/symfony-security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "symfony-security-review" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-review into .cursor/skills/symfony-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symfony-security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/symfony/symfony.git --path .agents/skills/symfony-security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add symfony/symfony --skill symfony-security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install symfony/symfony symfony-security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/symfony-security-review .gemini/skills/symfony-security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "symfony-security-review" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-review into .gemini/skills/symfony-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symfony-security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install symfony/symfony symfony-security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add symfony/symfony --skill symfony-security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/symfony-security-review .github/skills/symfony-security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "symfony-security-review" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-review into .github/skills/symfony-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symfony-security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add symfony/symfony --skill symfony-security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install symfony/symfony symfony-security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/symfony-security-review .opencode/skills/symfony-security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "symfony-security-review" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/symfony-security-review into .opencode/skills/symfony-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "symfony-security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
symfony-security-reviewReview a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.
Symfony Security Review is an agent skill from symfony/symfony. Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. Reasons about trust boundaries from first principles, then checks the code against Symfony's hardening-invariant families and runs the .github/sa-tools gates. Use when the user says "security review", "security audit", "check hardening", "review this PR/branch for security", "audit <component for <vuln class", "is any hardening missing", or names a vulnerability…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `hardening-families.md`).
It sits in Security, covering Security review. It works with Symfony, GitHub and PHP. The repository describes itself as: The Symfony PHP framework. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit af79aa7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghphpFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Symfony Security Review loads about 2.9k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 1,535 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from symfony/symfony at commit af79aa7, republished under its MIT licence (© symfony). 1,535 words, ~2,932 tokens.
.claude/skills/symfony-security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Finds hardening that is missing or wrong, grounded in code. It runs in two modes:
src/ tree, for one or all families.Both modes run two passes: first reason about the change's trust boundaries from first
principles (to catch novel issues), then check it against the hardening-invariant families
catalogued in hardening-families.md. The catalogue is a checklist
of known classes, not the search space.
Whenever this skill says "Wait for confirmation", treat anything other than an explicit affirmative as no: stop and ask the user how they want to proceed.
When auditing the whole src/ tree or a large multi-file component, fan Step 1 and Step 4
out to subagents: one per family, or one per file-batch, each returning findings that point
at a concrete file and line (no speculative findings leaking in through parallelism). Keep
the rest in the main loop: aggregation, de-duplication, the completeness check, and the
report are synthesis and must see every finding at once. For a single PR or a small diff,
run every step inline; subagents are pure overhead there.
Review a change. Resolve the diff and the changed non-test files:
# A public PR
gh pr diff <n> --repo symfony/symfony
# The current branch against its base (e.g. 6.4)
git diff <base>...HEAD --statAudit a target. Take a component path (e.g. src/Symfony/Component/Mailer)
or the whole src/ tree. There is no diff; the "changed files" are the target files.
In both modes, build the file list and drop tests (*/Tests/*). Hardening
lives in the implementation; tests are checked separately in Step 3.
State the resolved mode and scope back to the user in one line before continuing.
This pass finds what the catalogue does not list. Do it before mapping to families, and do not let the anchors narrow it. For each file in scope, reason as an attacker, independent of any known family:
Record every input-to-sink path with a non-trivial worst case as a candidate finding, whether or not it matches a catalogued family. An unguarded path from untrusted input to a dangerous sink is a finding even if no anchor names it. This step uses no greps by design; it is meant to see sinks the dictionary misses.
Now apply the catalogue as a checklist, to confirm no known class slipped past Step 1. Treat each anchor's listed APIs as seed examples of an abstract role (an inbound authenticator, a secret comparison, a deserialization entry, an XML/URL sink, a file or process sink); extend to anything in scope that plays that role, including classes the grep does not name.
For each file in scope, decide which families it touches using the grep anchors in
hardening-families.md. Run the anchors against the scope, not
the whole tree, when reviewing a change:
# Example: which families does this branch touch?
git diff <base>...HEAD --name-only | grep -v /Tests/ > /tmp/scope.txt
grep -lf <(printf 'extends AbstractRequestParser\nfunction __unserialize\nhash_hmac(\nvalidateOnParse\nloadXML(\nescapeshellarg(\npreg_match') $(cat /tmp/scope.txt) 2>/dev/nullCarry forward both Step 1's boundary findings and the families with a sink in scope; they proceed to Step 4. List them.
These encode the already-shipped invariants. Run them first; anything they catch needs no manual argument.
Hardening-test convention (tokenizer only, always runs locally):
php .github/sa-tools/check-hardening-tests.phpFails if a concrete AbstractRequestParser lacks a RejectWebhookException test,
or a class with __unserialize() and a string property lacks a __toString
gadget test. Accepted gaps live in its ALLOWLIST const.
Custom PHPStan rules (HardenedComparisonRule, UnserializeToStringTrampolineRule,
UnserializeMissingAllowedClassesRule). In CI these run base-vs-PR through
phpstan-diff.php, which only fails on errors new to the PR. To reproduce
locally you need PHPStan installed (it is not in composer.json; CI installs it
ad hoc). The source of truth for a rule's logic is a RuleTestCase, not an
ad-hoc phpstan analyse run:
# Only meaningful if phpstan is installed in the project
./vendor/bin/phpstan analyse --error-format=json --no-progress \
--autoload-file=.github/sa-tools/rules/bootstrap.phpDo not trust raw phpstan analyse counts for these rules: the result cache
plus parallel workers make them nondeterministic (a rule can report 0 then N for
the same input). See the gotchas.
For each in-scope family, apply its invariant from hardening-families.md.
The catalog gives, per family: the grep anchor, the invariant, the automated
coverage (if any), and the decision boundary.
Work the sinks, not the families in the abstract: for every sink site the anchor found, answer the family's check question. If the answer is "no guard / wrong guard", it is a candidate finding; confirm it is not excluded by the decision boundary before reporting.
Output a table, highest severity first:
| Location | Family | Severity | Invariant at risk | Suggested hardening | Hardening test |
|---|---|---|---|---|---|
Component/.../Foo.php:NN | webhook-verify | High | signature compared with !== | hash_equals() | extend parser reject test |
Severity rubric (match the corpus, not CVSS theatre):
When a finding moves on to security-triage, Critical and High both map to its
high label; Medium and Low map to medium and low.
For each real finding, state whether a hardening regression test is required so
check-hardening-tests.php (or a component test) keeps it from being dropped later.
Completeness check (before you finalise). State explicitly: is there an untrusted input, a sink, a deserialization, an authentication, or a trust boundary in scope that matched no anchor and was not already raised in Step 1? If so, reason about it from scratch before reporting. A clean family sweep is not a clean review.
The table holds findings from both passes: the Step 1 boundary pass (Family column = the
vulnerability class, or novel) and the Step 4 family review.
Separate confirmed findings from needs-human-judgement ones. Do not inflate.
This follows the house conventions:
./phpunit src/Symfony/Component/<Name> (never the whole suite).hardening-rule skill.Co-Authored-By, no Claude/Anthropic credit. Comments sparingly,
and do not reference issue numbers in code or tests.$secret that disables webhook
verification is documented behaviour, not a bug. A literal allowed_classes on
a first-party cache file was ruled not-a-security-issue. Pure DoS / memory
exhaustion is generally outside the CVE pipeline (treat as Low). The catalog
lists these; respect them or you will cry wolf.__unserialize(), int/float/bool
coercion throws TypeError without calling __toString. Do not flag non-string slots.RuleTestCase, and rely on the CI
base-vs-PR diff (phpstan-diff.php), not local counts.© symfony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/symfony-security-review of symfony/symfony.
Open the folder on GitHubat commit af79aa7
Symfony Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Symfony Security Review this skillsymfony/symfony | 31k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Security Advisory Rewriterobot-platform/obot | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Slowmist Agent Securityslowmist/slowmist-agent-security | 508 | — | ~1.4k | Automated safety check: Pass | MIT |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
obot-platform/obot
Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.
slowmist/slowmist-agent-security
Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
symfony/symfony
Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…
symfony/symfony
Decide whether open Bug PRs target the correct branch. An agent skill from symfony/symfony.
symfony/symfony
Cascade-merge maintained Symfony branches from oldest to newest (e.g.
symfony/symfony
Merge a reviewed pull request the way the Symfony core team does: one --no-ff merge commit per PR, whose message archives the whole discussion, with the review gates checked first.
symfony/symfony
Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).
symfony/symfony
Decide whether a recurring hardening invariant is worth a CI gate, and add it without hitting the traps.
Categories
Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. Symfony Security Review is an agent skill from symfony/symfony. Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.
Symfony Security Review fits situations like: the user says security review; check hardening; review this PR/branch for security; audit <component for <vuln class.
Run `npx skills add symfony/symfony --skill symfony-security-review -a claude-code`. Or copy the skill folder (.agents/skills/symfony-security-review in symfony/symfony) into .claude/skills/symfony-security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add symfony/symfony --skill symfony-security-review -a codex`. Or copy the skill folder (.agents/skills/symfony-security-review in symfony/symfony) into .agents/skills/symfony-security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add symfony/symfony --skill symfony-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/symfony-security-review, .gemini/skills/symfony-security-review, .github/skills/symfony-security-review and .opencode/skills/symfony-security-review in your project.
Going by SKILL.md and its folder, Symfony Security Review needs the command-line tools its instructions call (git, gh and php).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Symfony Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Symfony Security Review: Code Audit (3stoneBrother/code-audit, 892 stars), Kedro Security Review (kedro-org/kedro, 11k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Security Advisory Rewriter (obot-platform/obot, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
symfony (a GitHub organization) maintains it in symfony/symfony, which has 31,184 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.
Source: symfony/symfony on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.