Agent skill

Security Review

by Zfinix in Zfinix/aster

Reviewing a diff or feature for exploitable vulnerabilities before it ships.

Apache-2.0Auto-check passedSecurity

Install Security Review

skills CLI
$ npx skills add Zfinix/aster --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Zfinix/aster security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/aster-skills/builtins/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
113
Token cost
~1.2k tokens
SKILL.md length
605 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reviewing a diff or feature for exploitable vulnerabilities before it ships.

  • Works in 8 steps: Injection. String-built SQL, shell… → Broken authorization. Endpoints and… → Unvalidated input reaching dangerous… → …
  • Asked to do a security review
  • SKILL.md covers What to hunt, in order of impact, Detection commands, How to work and Verification, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Review is an agent skill from Zfinix/aster. Reviewing a diff or feature for exploitable vulnerabilities before it ships. Use when asked to do a security review, when code touches auth, input handling, queries, files, URLs, crypto, or payments, and before merging changes that accept untrusted input.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The repository describes itself as: An open-source agent harness for software work. The licence is Apache-2.0.

When your agent uses it

  • Asked to do a security review
  • Code touches auth
  • Before merging changes that accept untrusted input

Example prompts

  • “/security-review”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Injection. String-built SQL, shell commands with interpolated input,
  2. Broken authorization. Endpoints and handlers that authenticate but never
  3. Unvalidated input reaching dangerous sinks. Path traversal
  4. Output escaping. User data rendered into HTML, markdown, shell output,
  5. Secrets and credentials. Hardcoded keys, tokens in URLs, secrets logged,
  6. Crypto and session. Weak hashes for passwords (anything unsalted or
  7. Web plumbing. Missing CSRF protection on state-changing routes, CORS
  8. AI/LLM integration. Provider API keys shipped to the client bundle,

What it can do on your machine

Read from SKILL.md and the folder at commit f77a5b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 1.2k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 605 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Zfinix/aster at commit f77a5b4, republished under its Apache-2.0 licence (© Zfinix). 605 words, ~1,204 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
Reviewing a diff or feature for exploitable vulnerabilities before it ships. Use when asked to do a security review, when code touches auth, input handling, queries, files, URLs, crypto, or payments, and before merging changes that accept untrusted input.

Security review

Review the diff as an attacker would. Only report issues introduced or exposed by the changed lines; pre-existing problems get one summary line at most, not findings.

What to hunt, in order of impact

  1. Injection. String-built SQL, shell commands with interpolated input, LDAP/ORM raw fragments, template injection. Parameterize or escape; name the exact concatenation site.
  2. Broken authorization. Endpoints and handlers that authenticate but never check ownership or role (user_id from the request instead of the session). IDOR: any resource fetched by an ID the client controls without an ownership check.
  3. Unvalidated input reaching dangerous sinks. Path traversal (PathBuf::join / path.join with user segments), open redirects, SSRF (user-supplied URLs fetched server-side), unsafe deserialization of untrusted bytes.
  4. Output escaping. User data rendered into HTML, markdown, shell output, logs, or SQL identifiers without escaping; innerHTML, dangerouslySetInnerHTML, unescaped template variables.
  5. Secrets and credentials. Hardcoded keys, tokens in URLs, secrets logged, credentials in error messages returned to clients.
  6. Crypto and session. Weak hashes for passwords (anything unsalted or non-argon2/bcrypt/scrypt), Math.random/naive RNG for tokens, missing expiry or signature checks, comparisons of secrets with == instead of constant-time.
  7. Web plumbing. Missing CSRF protection on state-changing routes, CORS widened to * with credentials, cookies without HttpOnly/Secure/ SameSite, permissive file-upload type checks.
  8. AI/LLM integration. Provider API keys shipped to the client bundle, no spend cap on model calls, untrusted content concatenated into prompts (prompt injection), model output rendered as HTML/markdown or passed to a tool without validation.

Detection commands

Run these over the changed files first; each hit is a candidate to trace by hand, not a finding on its own:

  • Secrets: (api[_-]?key|secret|token|password)\s*[:=]\s*["'][A-Za-z0-9]
  • Client-submitted prices or roles: price|amount|role|is_admin read from request body/params and used without server-side lookup.
  • Unverified JWTs: jwt\.decode\( without a matching verify; auth enforced only in middleware rather than in the handler.
  • Raw queries: queryRawUnsafe|raw\(|format!\(.*SELECT|\$\{.*(?:WHERE|INSERT|UPDATE).
  • Dangerous sinks: exec|eval|innerHTML|dangerouslySetInnerHTML|join\(.*user, user-supplied URLs passed to fetch/reqwest/http clients.
  • Never trust the client: every price, user ID, role, subscription status, and rate-limit counter must be validated server-side. If it only exists in the browser bundle or request body, an attacker controls it.
Show full SKILL.md (258 more words)Show less

How to work

  • Read the full function around each changed line, not just the hunk. A taint source above the diff or a sink below it is still your finding.
  • Trace untrusted input from its entry point (route, CLI arg, env, request body) to every sink it reaches.
  • For each candidate, try to write the concrete exploit input. If you cannot construct one, say so and downgrade the confidence, or drop it.
  • Frameworks matter: check whether the framework already escapes, parameterizes, or guards before flagging. A finding that the framework neutralizes is noise. Known framework guards (React auto-escaping, Prisma parameterization, RLS policies, webhook signature verification) suppress the finding entirely.

Verification

A finding is not done until the fix is confirmed:

  • After fixing, re-run the matching detection command; it must come back clean for that site.
  • For authz fixes, show the request that was rejected before and succeeds or fails correctly now (two users, one resource).
  • For secrets, rotation is part of the fix: a removed key that was committed is still burned. Say so explicitly.

Reporting

Lead with the count and worst severity. Each finding states:

  • What breaks, the exact input or state that triggers it, and the affected route/function with file:line.
  • Severity: critical (exploitable now, no auth), high (exploitable with an account), medium (needs a specific setup), low (defense-in-depth).
  • The fix in one line: parameterize here, add the ownership check there.

No padding findings. If the diff is clean, say so plainly; a clean bill from a real pass is worth more than a list of hypotheticals.

© Zfinix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/aster-skills/builtins/security-review of Zfinix/aster.

Open the folder on GitHubat commit f77a5b4

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skillZfinix/aster113—~1.2kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from Zfinix/aster

All 19 skills in this repo
  • Artifact Design

    Zfinix/aster

    Designing and building any user-facing surface: a web page, landing page, dashboard, report, HTML document, email, or a component inside an existing app.

    113 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Drive aster chat programmatically and manage sessions and memory: one-shot --print/--json answers, --messages-json for caller-owned history, --continue and --session persistence, --allow-edits…

    113 GitHub stars~591 tokensUpdated today
    Auto-check passed
  • Aster CLI

    Zfinix/aster

    Guidance for using the aster CLI to work in a codebase with an AI agent: chat and edit code, run AI code reviews, apply fixes, and manage sessions, memory, and skills.

    113 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aster Config

    Zfinix/aster

    Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

    113 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aster Fix Workflow

    Zfinix/aster

    Pipe aster review findings into aster fix to generate and apply patches safely, using review --json, fix --findings-json, dry-run inspection, --apply, and permission gating.

    113 GitHub stars~534 tokensUpdated today
    Auto-check passed
  • Aster Planning

    Zfinix/aster

    Create and execute structured plans for multi-step tasks. An agent skill from Zfinix/aster.

    113 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Security Review

What does Security Review do?

Reviewing a diff or feature for exploitable vulnerabilities before it ships. Security Review is an agent skill from Zfinix/aster. Reviewing a diff or feature for exploitable vulnerabilities before it ships.

When should I use Security Review?

Security Review fits situations like: asked to do a security review; code touches auth; before merging changes that accept untrusted input.

How do I install Security Review in Claude Code?

Run `npx skills add Zfinix/aster --skill security-review -a claude-code`. Or copy the skill folder (crates/aster-skills/builtins/security-review in Zfinix/aster) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add Zfinix/aster --skill security-review -a codex`. Or copy the skill folder (crates/aster-skills/builtins/security-review in Zfinix/aster) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Zfinix/aster --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Review is instructions for the agent only.

Does Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

Zfinix (a GitHub user) maintains it in Zfinix/aster, which has 113 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: Zfinix/aster on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.