Security Reviewer
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
Agent skill
Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install thomast1906/github-copilot-agent-skills api-security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/api-security-review .claude/skills/api-security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "api-security-review" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-review into .claude/skills/api-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install thomast1906/github-copilot-agent-skills api-security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/api-security-review .agents/skills/api-security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "api-security-review" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-review into .agents/skills/api-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install thomast1906/github-copilot-agent-skills api-security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/api-security-review .cursor/skills/api-security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "api-security-review" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-review into .cursor/skills/api-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/thomast1906/github-copilot-agent-skills.git --path .github/skills/api-security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install thomast1906/github-copilot-agent-skills api-security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/api-security-review .gemini/skills/api-security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "api-security-review" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-review into .gemini/skills/api-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install thomast1906/github-copilot-agent-skills api-security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/api-security-review .github/skills/api-security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "api-security-review" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-review into .github/skills/api-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install thomast1906/github-copilot-agent-skills api-security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/api-security-review .opencode/skills/api-security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "api-security-review" agent skill from https://github.com/thomast1906/github-copilot-agent-skills/tree/main/.github/skills/api-security-review into .opencode/skills/api-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
api-security-reviewAudits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.
This skill has the agent review an Azure API Management instance for security gaps. It maps each of the ten OWASP API Security risks (2023 RC) to the APIM policy or network control that addresses it, such as validate-jwt for authentication and authorization checks, rate-limit-by-key for resource consumption, and VNet Internal mode with Private Link for SSRF.
A longer checklist in references/SECURITY_CONTROLS.md lists more than 60 controls across 9 categories, and a quick summary groups them into areas like network security, identity and access, and data protection. The review works from the configuration and policies you give it and fits pre-deployment checks, audits, post-incident reviews and compliance work against Azure Security Benchmark and CIS Azure.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 554ac0b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are xml and kql).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
login.microsoftonline.comAlso links to:
learn.microsoft.comowasp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure API Management Security Review loads about 3.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 1,000 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from thomast1906/github-copilot-agent-skills at commit 554ac0b, republished under its MIT licence (© thomast1906). 1,000 words, ~3,091 tokens.
.claude/skills/api-security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Performs comprehensive security reviews of Azure API Management configurations, policies, and network architecture with focus on OWASP API Security Top 10 and Azure Security Benchmark.
Activate this skill when users need:
| ID | Threat | APIM Mitigation |
|---|---|---|
| API1 | Broken Object Level Authorization | Policy: validate-jwt + check user claims for resource ownership |
| API2 | Broken Authentication | Policy: OAuth 2.0 (validate-jwt), no plaintext credentials |
| API3 | Broken Object Property Level Authorization | Policy: Validate input/output schemas, mask sensitive fields |
| API4 | Unrestricted Resource Consumption | Policy: rate-limit-by-key (per user/subscription), quota enforcement |
| API5 | Broken Function Level Authorization | Policy: Validate JWT scopes/roles per operation |
| API6 | Unrestricted Access to Sensitive Business Flows | Policy: Advanced rate limiting, CAPTCHA integration |
| API7 | Server Side Request Forgery (SSRF) | Network: VNet Internal mode, Private Link to backends |
| API8 | Security Misconfiguration | Infrastructure: TLS 1.3, disable weak ciphers, NSG rules |
| API9 | Improper Inventory Management | Governance: Azure API Center, version tracking, deprecation |
| API10 | Unsafe Consumption of APIs | Policy: Validate backend responses, timeout policies |
See references/SECURITY_CONTROLS.md for complete 60+ control checklist across 9 categories
Tool: mcp_azure_mcp_get_azure_bestpractices
Intent: "Azure API Management security best practices"Tool: mcp_azure_mcp_documentation search
Query: "APIM security best practices OWASP"Tool: azure_resources-query_azure_resource_graph
Intent: "Get API Management instances with network configuration and SKU details"Check: APIM instances deployed in VNet Internal mode (no public IP)
// Azure Resource Graph Query
resources
| where type == 'microsoft.apimanagement/service'
| extend vnetType = properties.virtualNetworkType
| where vnetType != 'Internal'
| project name, resourceGroup, location, vnetType, sku=properties.sku.nameExpected: vnetType == 'Internal' for all production APIM instances
Risk if External: Gateway endpoint exposed to public internet, larger attack surface
Check: Azure Front Door connects to APIM via Private Link (not public origin)
Validation Steps:
Private Link (not Custom or Public)Approved (not Pending)Risk if Public: Traffic goes over public internet, no zero-trust architecture
Check: APIs use OAuth 2.0 (validate-jwt policy) or subscription keys (not both for sensitive APIs)
Policy Review:
<!-- GOOD: OAuth for sensitive APIs -->
<validate-jwt header-name="Authorization">
<openid-config url="https://login.microsoftonline.com/{tenant}/..." />
<required-claims>
<claim name="scp" match="any">
<value>api.read</value>
</claim>
</required-claims>
</validate-jwt>
<!-- BAD: No authentication -->
<policies>
<inbound>
<base />
<!-- No validate-jwt or check-header -->
</inbound>
</policies>Risk if Missing: Unauthenticated access to sensitive data, API abuse
Check: All APIs have rate limiting (rate-limit-by-key or quota-by-key)
Policy Review:
<!-- GOOD: Per-user rate limiting -->
<rate-limit-by-key calls="1000" renewal-period="3600"
counter-key="@((string)context.Variables['userId'])" />
<!-- BAD: No rate limiting -->
<policies>
<inbound>
<base />
<!-- No rate-limit-by-key -->
</inbound>
</policies>Risk if Missing: API4 Unrestricted Resource Consumption, DDoS vulnerability
Check: TLS 1.2+ only, no SSL 3.0/TLS 1.0/TLS 1.1
Azure Portal Validation:
Risk if Enabled: Vulnerable to BEAST, POODLE, CRIME attacks
Check: All secrets/certificates stored in Azure Key Vault (not in policies or code)
Policy Review:
<!-- GOOD: Secret from Key Vault -->
<set-header name="X-API-Key">
<value>{{api-backend-key}}</value> <!-- Named value linked to Key Vault -->
</set-header>
<!-- BAD: Hardcoded secret -->
<set-header name="X-API-Key">
<value>sk-abc123xyz789</value>
</set-header>Risk if Hardcoded: Secret exposure in logs, code repositories, APIM exports
Check: CORS policies have specific origins (not * wildcard for production)
<!-- GOOD: Specific origins -->
<cors allow-credentials="true">
<allowed-origins>
<origin>https://app.example.com</origin>
</allowed-origins>
</cors>
<!-- Warning: ACCEPTABLE FOR DEV: Wildcard -->
<cors allow-credentials="false">
<allowed-origins>
<origin>*</origin>
</allowed-origins>
</cors>
<!-- BAD: Wildcard with credentials -->
<cors allow-credentials="true">
<allowed-origins>
<origin>*</origin> <!-- Security risk! -->
</allowed-origins>
</cors>Risk: CSRF attacks, credential theft if misconfigured
Check: Error responses don't leak sensitive information (stack traces, internal IPs)
Policy Review:
<!-- GOOD: Generic error -->
<on-error>
<set-body>@{
return new JObject(
new JProperty("error", "Internal server error"),
new JProperty("correlationId", context.Variables["correlationId"])
).ToString();
}</set-body>
</on-error>
<!-- BAD: Detailed error -->
<on-error>
<set-body>@{
return context.LastError.Message; // Might contain stack trace, DB connection strings
}</set-body>
</on-error>Risk: Information disclosure (API3, API8)
When performing security review, structure findings as:
Example:
apim-api-marketplace-prod-uks deployed in VNet External mode with gateway endpoint 10.2.1.4 exposed via public IPaz apim update --name apim-api-marketplace-prod-uks --resource-group rg-apim-prod-uks \
--virtual-network-type Internalnslookup apim-api-marketplace-prod-uks.azure-api.net should return internal IP only| Control ID | Category | Requirement | APIM Implementation |
|---|---|---|---|
| NS-1 | Network Segmentation | Isolate workloads | VNet Internal mode |
| NS-2 | Private Connectivity | Private Link/Endpoints | Front Door → APIM Private Link |
| NS-4 | DDoS Protection | Enable DDoS Standard or ingress with DDoS | Front Door Premium (DDoS included) |
| IA-2 | Secure Authentication | OAuth/MFA | validate-jwt with Entra ID |
| IA-5 | MFA Enforcement | Require MFA | Entra ID Conditional Access |
| DP-1 | Data at Rest Encryption | Encrypt sensitive data | Azure Managed Disks encryption |
| DP-3 | Data in Transit Encryption | TLS 1.2+ | APIM TLS 1.3, disable weak protocols |
| DP-4 | Encryption Key Management | Azure Key Vault | All secrets in Key Vault |
| LT-1 | Centralized Logging | Log all security events | App Insights, Azure Monitor |
| LT-4 | Audit Logging | Tamper-proof audit trail | Azure Activity Log, diagnostic logs |
| IM-1 | Managed Identities | Avoid service accounts | APIM Managed Identity |
| IM-3 | Least Privilege | RBAC | Custom roles per environment |
| GS-1 | Policy Enforcement | Azure Policy | Require VNet Internal, TLS 1.2+ |
Skill Version: 1.0
Last Updated: 29 January 2026
Primary Knowledge: SECURITY_CONTROLS_CHECKLIST.md, references/SECURITY_CONTROLS.md
© thomast1906, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .github/skills/api-security-review of thomast1906/github-copilot-agent-skills.
Open the folder on GitHubat commit 554ac0b
Azure API Management Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure API Management Security Review this skillthomast1906/github-copilot-agent-skills | 202 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Security Analyzeraiskillstore/marketplace | 430 | — | ~1.2k | Automated safety check: Notes | None | |
| Security Auditoraiskillstore/marketplace | 430 | 6 repos | ~2.6k | Automated safety check: Pass | None | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT |
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
aiskillstore/marketplace
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
cachethq/core
Runs and interprets Psalm security (taint) analysis on a Laravel project.
thomast1906/github-copilot-agent-skills
Guides creating, updating, reviewing and validating GitHub Copilot agent skills, from deciding whether a skill is the right tool to structuring bundled resources.
thomast1906/github-copilot-agent-skills
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
thomast1906/github-copilot-agent-skills
Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.
thomast1906/github-copilot-agent-skills
Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.
thomast1906/github-copilot-agent-skills
Looks up live Azure retail prices by SKU, service or region through the Azure MCP pricing tool, estimates template costs and compares regions, price types and savings plans.
thomast1906/github-copilot-agent-skills
Create and edit diagrams on a live Excalidraw canvas using the Excalidraw MCP server.
Works with
Categories
Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. This skill has the agent review an Azure API Management instance for security gaps. It maps each of the ten OWASP API Security risks (2023 RC) to the APIM policy or network control that addresses it, such as validate-jwt for authentication and authorization checks, rate-limit-by-key for resource consumption, and VNet Internal mode with Private Link for SSRF.
Azure API Management Security Review fits situations like: security audit of an APIM instance before it goes live; confirming APIM runs in VNet Internal mode with Private Link to backends; compliance review against the OWASP API Top 10 or Azure Security Benchmark; reviewing API Management configuration after a security incident.
Run `npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a claude-code`. Or copy the skill folder (.github/skills/api-security-review in thomast1906/github-copilot-agent-skills) into .claude/skills/api-security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a codex`. Or copy the skill folder (.github/skills/api-security-review in thomast1906/github-copilot-agent-skills) into .agents/skills/api-security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-review, .gemini/skills/api-security-review, .github/skills/api-security-review and .opencode/skills/api-security-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure API Management Security Review is instructions for the agent only. Our summary lists: Access to the APIM configuration and policies to be reviewed.
SKILL.md names 3 domains. In commands or code: login.microsoftonline.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com and owasp.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure API Management Security Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 700 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Azure API Management Security Review: Security Reviewer (AratKruglik/claude-laravel, 155 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Security Analyzer (aiskillstore/marketplace, 430 stars) and Security Auditor (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
thomast1906 (a GitHub user) maintains it in thomast1906/github-copilot-agent-skills, which has 202 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.
Source: thomast1906/github-copilot-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.