Agent skill

Security Review PR

by warpdotdev in warpdotdev/oz-for-oss

Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold…

MITAuto-check: notesSecurity

Install Security Review PR

skills CLI
$ npx skills add warpdotdev/oz-for-oss --skill security-review-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install warpdotdev/oz-for-oss security-review-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/warpdotdev/oz-for-oss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-review-pr .claude/skills/security-review-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review-pr
GitHub stars
313
Used in
1 other repo
Token cost
~2k tokens
SKILL.md length
1,067 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold…

  • Works in 5 steps: Read pr_description.md and pr_diff.txt… → For each changed hunk, consider which of… → Prefer evidence-based findings tied to… → …
  • Tasks that involve Pull requests
  • SKILL.md covers Goal, Inputs, When to apply this skill and Security concerns to audit, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Review PR is an agent skill from warpdotdev/oz-for-oss. Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold findings into the same review.json produced by the base PR review. Use as a supplement to review-pr whenever a code PR is being reviewed.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Pull requests, Security review and Secrets management. The repository describes itself as: Workflows and skills to help people and agents collaborate on open-source software with the power of Oz! The licence is MIT.

When your agent uses it

  • Tasks that involve Pull requests
  • Tasks that involve Security review
  • Tasks that involve Secrets management

Example prompts

  • “/security-review-pr”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read pr_description.md and pr_diff.txt to understand the scope and intent of the change.
  2. For each changed hunk, consider which of the concerns above could plausibly apply given the surrounding code in the checkout.
  3. Prefer evidence-based findings tied to specific changed lines. If a concern only applies to untouched code, describe it in the review…
  4. Do not flag purely stylistic or non-security issues here — those belong in the base review-pr pass.
  5. Do not repeat findings already covered by the base review; if the base pass would naturally catch it, leave it there.

What it can do on your machine

Read from SKILL.md and the folder at commit a2bb45f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review PR loads about 2k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 1,067 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:55
    - New secrets added to `.env`, fixtures, or test data that are real rather than clearly synthetic placeholders.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from warpdotdev/oz-for-oss at commit a2bb45f, republished under its MIT licence (© warpdotdev). 1,067 words, ~1,983 tokens.

Download SKILL.mdSave it as .claude/skills/security-review-pr/SKILL.md (or your agent's skills folder).
name
security-review-pr
description
Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold findings into the same review.json produced by the base PR review. Use as a supplement to `review-pr` whenever a code PR is being reviewed.

Security Review PR Skill

Audit the current pull request for security concerns and fold any findings into the same review.json produced by the base review-pr skill.

Goal

Provide a focused security pass on top of the general PR review. This is a supplement to review-pr, not a separate output. Findings must be merged into the single combined review.json so reviewers receive one cohesive review.

Inputs

  • The working directory is the PR branch checkout.
  • The workflow usually provides an annotated diff in pr_diff.txt.
  • The workflow usually provides the PR description in pr_description.md.
  • Focus on the files and lines changed by this PR.
  • Default behavior: do not post comments or reviews to GitHub directly.

When to apply this skill

  • Apply on code PRs whenever review-pr is applied.
  • Do not apply on spec-only PRs handled by review-spec.
  • Skip the skill entirely when no changed file introduces code or configuration that touches the concerns below; it is better to stay silent than to manufacture findings.
  • Do not duplicate findings the base review-pr pass will already raise. If the base review would naturally catch an issue, leave it there rather than re-reporting it from the security pass.

Security concerns to audit

Evaluate each changed hunk against the following concerns. Treat the list as a checklist, not a ceiling — flag other clearly security-relevant issues when they appear.

Input validation and untrusted data
  • User-supplied or network-supplied input used without validation, length limits, or type checks.
  • Deserialization of untrusted data (e.g. pickle, yaml.load, eval, Function, JSON.parse feeding into a command).
  • Path traversal risk: user input concatenated into filesystem paths without normalization or an allowlist.
  • SSRF risk: user-controlled URLs passed to outbound HTTP clients without scheme or host restrictions.
  • Unbounded resource use driven by untrusted input (memory, loops, regex with catastrophic backtracking).
Output encoding and sanitization
  • Untrusted data interpolated into SQL, shell commands, HTML, Markdown, log lines, or URLs without the right encoding or parameterization.
  • Use of shell=True, string concatenation into exec/spawn, or raw SQL strings.
  • Rendering user-supplied Markdown or HTML into a UI without sanitization.
Authentication and authorization
  • Missing or weakened authentication checks on new endpoints, RPC handlers, or CLI commands.
  • Authorization checks that trust client-supplied identifiers instead of the authenticated principal.
  • Permission checks removed or made more permissive without clear justification.
Secrets management
  • Hardcoded credentials, API keys, private keys, or tokens committed in source.
  • Secrets read from insecure locations (world-readable files, logs, environment dumps printed to stdout).
  • Secrets passed via command-line arguments where they would leak into process listings or shell history.
  • Secrets written to logs, error messages, analytics events, or serialized payloads.
  • New secrets added to .env, fixtures, or test data that are real rather than clearly synthetic placeholders.
Cryptography and randomness
  • Use of weak or deprecated primitives (MD5, SHA1 for security purposes, ECB mode, RC4).
  • Hand-rolled crypto when a vetted library is available.
  • Non-cryptographic randomness (random.random, Math.random) used for tokens, IDs, or security decisions.
  • Missing integrity or authenticity checks when decrypting or verifying tokens.
Dependencies and supply chain
  • New dependencies from unknown registries or forks without a clear rationale.
  • Pinning loosened in a way that allows untrusted upgrades (e.g. * or very broad ranges on a sensitive package).
  • Fetching scripts over HTTP or piping curl to a shell inside build or CI steps.
Data handling and privacy
  • Logging or echoing personally identifiable information, auth tokens, session IDs, or request bodies that may contain them.
  • New telemetry or analytics events that capture sensitive data without redaction.
  • Expanding the scope of stored data beyond what the feature requires.
Configuration and defaults
  • New feature flags or configuration options that default to insecure values (e.g. TLS disabled, auth optional).
  • CORS, cookies, or headers weakened in scope without an explicit justification.
  • Permissive file modes on newly created files that contain sensitive material.
Show full SKILL.md (446 more words)Show less

Process

  1. Read pr_description.md and pr_diff.txt to understand the scope and intent of the change.
  2. For each changed hunk, consider which of the concerns above could plausibly apply given the surrounding code in the checkout.
  3. Prefer evidence-based findings tied to specific changed lines. If a concern only applies to untouched code, describe it in the review summary instead of as an inline comment.
  4. Do not flag purely stylistic or non-security issues here — those belong in the base review-pr pass.
  5. Do not repeat findings already covered by the base review; if the base pass would naturally catch it, leave it there.

Outputs

  • Do not create a separate report file.
  • Fold security findings into the same review.json produced by review-pr.
  • Prefix every security finding's comment body with a [SECURITY] tag after the severity label so reviewers can tell the source of the concern. For example:
    • 🚨 [CRITICAL] [SECURITY] SQL injection: ...
    • ⚠️ [IMPORTANT] [SECURITY] Secret written to logs: ...
    • 💡 [SUGGESTION] [SECURITY] Prefer parameterized query: ...
  • In the review summary, add a dedicated ## Security subsection when there are security findings. List the most important security concerns there in addition to any inline comments. If there are no security findings, do not add the subsection.
  • Count security findings toward the existing Found: X critical, Y important, Z suggestions tally in the summary. Do not add a separate security counter.
  • Upgrade the overall verdict if a security finding materially demands it. A critical security finding should generally result in Request changes.

Severity mapping

  • 🚨 [CRITICAL] for issues that are likely exploitable in production (e.g. shell injection with attacker-controlled input, committed live secret, missing auth on a destructive endpoint).
  • ⚠️ [IMPORTANT] for plausible security weaknesses that should be fixed before merge (e.g. missing input validation on an internal-only endpoint, weak hashing for non-password data, overly broad CORS).
  • 💡 [SUGGESTION] for defense-in-depth improvements that are clearly worthwhile but not immediate risks.
  • 🧹 [NIT] is rarely appropriate for security findings; use only when the comment includes a concrete suggestion block and the issue is genuinely cosmetic.

Inline comment requirements

  • Follow the same diff-line rules as review-pr: inline comments must target lines that exist in this PR's diff.
  • Keep comments concise, direct, and actionable. Explain the threat, then the fix.
  • When proposing code changes, use the same suggestion block format as review-pr.

Boundaries

  • Do not run dynamic scans, fetch remote advisories, or call external security APIs.
  • Do not speculate about vulnerabilities that cannot be tied to the diff or the checked-out files.
  • Do not gate the PR on theoretical risks; prefer 💡 [SUGGESTION] when the risk is low or the fix is optional.
  • Do not post to GitHub directly. Your only output is the merged review.json from the base review pass.

© warpdotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security-review-pr of warpdotdev/oz-for-oss.

Open the folder on GitHubat commit a2bb45f

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in warpdotdev/oz-for-oss, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Review PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review PR this skillwarpdotdev/oz-for-oss3131 repos~2kAutomated safety check: NotesMIT
Azure Compliancemicrosoft/GitHub-Copilot-for-Azure2552 repos~997Automated safety check: PassMIT
Code Review Webrampstackco/claude-skills935—~2.7kAutomated safety check: PassMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Security AuditaAAaqwq/AGI-Super-Team1052 repos~619Automated safety check: NotesMIT
Reviewing Code Changestrilwu/secskills156—~2.3kAutomated safety check: PassMIT

Similar skills

  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed
  • Code Review Web

    rampstackco/claude-skills

    Review web application code for bugs, security issues, performance problems, and stack-specific anti-patterns.

    935 GitHub stars~2.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Security Audit

    aAAaqwq/AGI-Super-Team

    Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub starsUsed in 2 repos~619 tokens
    SecurityAuto-check: notes
  • Reviewing Code Changes

    trilwu/secskills

    Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline.

    156 GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Review

    ktnyt/cclsp

    Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

    675 GitHub stars~565 tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from warpdotdev/oz-for-oss

All 17 skills in this repo
  • Update Dedupe

    warpdotdev/oz-for-oss

    Update the repo-local dedupe-issue-local companion skill using closed-as-duplicate signals.

    313 GitHub stars~927 tokensUpdated 20 days ago
    Auto-check passed
  • Update PR Review

    warpdotdev/oz-for-oss

    Update the repo-local review-pr-local and review-spec-local companion skills using human feedback left on pull request conversations.

    313 GitHub stars~1.6k tokensUpdated 20 days ago
    Auto-check passed
  • Bootstrap Issue Config

    warpdotdev/oz-for-oss

    Bootstrap the issue triage configuration for a repository by analyzing existing issues, labels, and contributors to generate .github/issue-triage/config.json and .github/STAKEHOLDERS.

    313 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Update Triage

    warpdotdev/oz-for-oss

    Update the repo-local triage-issue-local companion skill using signals from recently triaged issues (maintainer re-labels, re-opens, follow-up comments).

    313 GitHub stars~1k tokensUpdated 20 days ago
    Auto-check passed
  • Implement Issue

    warpdotdev/oz-for-oss

    Implement a GitHub issue in this repository by applying the shared implement-specs workflow with Oz-specific issue, spec-context, and summary-file handling.

    313 GitHub stars~2k tokensUpdated 20 days ago
    Auto-check passed
  • Review Spec

    warpdotdev/oz-for-oss

    Review a spec/plan pull request diff and write structured feedback to review.json for the workflow to publish.

    313 GitHub stars~1.9k tokensUpdated 20 days ago
    Auto-check passed

Questions about Security Review PR

What does Security Review PR do?

Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold…. Security Review PR is an agent skill from warpdotdev/oz-for-oss.json produced by the base PR review.

When should I use Security Review PR?

Security Review PR fits situations like: tasks that involve Pull requests; tasks that involve Security review; tasks that involve Secrets management.

How do I install Security Review PR in Claude Code?

Run `npx skills add warpdotdev/oz-for-oss --skill security-review-pr -a claude-code`. Or copy the skill folder (.agents/skills/security-review-pr in warpdotdev/oz-for-oss) into .claude/skills/security-review-pr in your project. Claude Code loads it when a task matches its description.

How do I install Security Review PR in Codex?

Run `npx skills add warpdotdev/oz-for-oss --skill security-review-pr -a codex`. Or copy the skill folder (.agents/skills/security-review-pr in warpdotdev/oz-for-oss) into .agents/skills/security-review-pr in your project. Codex loads it when a task matches its description.

Can I use Security Review PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add warpdotdev/oz-for-oss --skill security-review-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review-pr, .gemini/skills/security-review-pr, .github/skills/security-review-pr and .opencode/skills/security-review-pr in your project.

What does Security Review PR need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Review PR is instructions for the agent only.

Does Security Review PR access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Review PR safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Review PR use?

Security Review PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review PR use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review PR?

Skills that share tags, products or a category with Security Review PR: Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars), Code Review Web (rampstackco/claude-skills, 935 stars), Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars) and Security Audit (aAAaqwq/AGI-Super-Team, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review PR?

warpdotdev (a GitHub organization) maintains it in warpdotdev/oz-for-oss, which has 313 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 17, 2026.

Source: warpdotdev/oz-for-oss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.