Topic · Security

Best security review skills for Claude Code, Codex and other agents.

Skills that review code and changes for security flaws before they ship.
skills
611
official
61

Security review skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Security review skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

shareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT9 days ago
2

General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

supabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT5 days ago
3

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0today
4

Runs an autonomous modify, verify, keep-or-discard loop against any metric, with subcommands for planning, debugging, fixing, security audits, shipping and more.

uditgoenka/autoresearch6.5k1 repo~2kAutomated safety check: PassMIT1 mo ago
5

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

jewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT4 mo ago
6

Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

usestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0today
7

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

vercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.08 days ago
8

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8931 repo~2.7kAutomated safety check: PassNo licence7 mo ago
9

Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

awesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT29 days ago
10

A skill your agent uses when doing ANY task involving Supabase.

curvenote/curvenote1695 repos~2.2kAutomated safety check: PassUnknown9 days ago
11

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.05 days ago
12

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

vercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.08 days ago
13

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

tanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassUnknown2 mo ago
14

Scaffold a well-designed agent loop with best-practice coaching and a cross-model review council.

ksimback/looper710—~2.7kAutomated safety check: NotesMIT1 mo ago
15

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknownyesterday
16

Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.

trailofbits/skills-curated5125 repos~2.2kAutomated safety check: NotesCC-BY-SA-4.02 mo ago
17

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
18

Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

kubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.06 days ago
19

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.05 days ago
20

A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my…

solana-foundation/solana-dev-skill571—~3.8kAutomated safety check: PassMIT4 days ago
21

Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

awarexone/Agentic-Bug-Hunter5.3k1 repo~2.4kAutomated safety check: PassMIT2 days ago
22

Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

HezaoHezao/poirot2505 repos~1.6kAutomated safety check: PassMIT2 mo ago
23
23.Security ReviewOfficial

Security code review for vulnerabilities. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.04 days ago
24

Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when…

TanStack/ai3.2k—~4.6kAutomated safety check: PassMITtoday
25

Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

luongnv89/claude-howto42k—~764Automated safety check: PassMIT7 days ago
26

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

lingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT2 mo ago
27

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

nyldn/claude-octopus4.2k1 repo~2.3kAutomated safety check: PassMITtoday
28

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

mono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMITtoday
29

Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

symfony/symfony31k—~2.9kAutomated safety check: PassMITtoday
30

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT2 days ago
31

Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

verdaccio/verdaccio18k—~853Automated safety check: PassMITtoday
32

Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

tech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.017 days ago
33

Verify that code changes do not introduce OAuth security vulnerabilities.

doorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMITyesterday
34

Security audit for web apps, especially AI-built ("vibe coded") ones.

benavlabs/vibe-check116—~1.1kAutomated safety check: NotesMIT18 days ago
35

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

zebbern/claude-code-guide4.6k—~4.2kAutomated safety check: PassMITtoday
36

Apply modern web development best practices for security, compatibility, and code quality.

midudev/100cosas.dev1143 repos~3kAutomated safety check: PassMIT9 days ago
37

Operates Flounder, an autonomous white-hat security auditor.

adshao/flounder517—~9.2kAutomated safety check: PassAGPL-3.0yesterday
38

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.05 days ago
39

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

gocronx-team/gocron808—~690Automated safety check: PassMIT4 days ago
40
40.Review SecurityOfficial

Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

pydantic/monty8.6k—~852Automated safety check: PassMITyesterday
41

Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

codexstar69/bug-hunter519—~5kAutomated safety check: PassMIT1 mo ago
42

Interact with Bitget Wallet API for crypto market data, token info, swap quotes, RWA (real-world asset) stock trading, and security audits.

bitget-wallet-ai-lab/bitget-wallet-skill245—~7.6kAutomated safety check: PassMIT4 mo ago
43

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.09 days ago
44

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

EpicenterHQ/epicenter4.8k—~896Automated safety check: PassUnknowntoday
45

Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output.

coderabbitai/skills188—~1.9kAutomated safety check: PassMITtoday
46

Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

Fangcun-AI/SkillWard143—~2.9kAutomated safety check: PassUnknown2 mo ago
47

Django access control and IDOR security review. An agent skill from getsentry/skills.

getsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.04 days ago
48

Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files.

HarnessMD/munder-difflin8.5k—~350Automated safety check: NotesMITtoday

Questions, answered from the data.

What is the best security review skill?

Code Review Checklist from shareAI-lab/learn-claude-code ranks first of the 611 security review skills listed here, with the highest score: its repository has 78k GitHub stars, 5 other GitHub owners carry a copy, its SKILL.md loads about 1.1k tokens and it passes the automated safety check with no findings. Next come Supabase Development and Debugging and Security Auditor.

Which security review skills are official?

61 of the 611 security review skills are official, published by the vendor's own GitHub organization: Supabase Development and Debugging, Deepsec Vulnerability Scanner, CodeQL Security Scan, Deepsec Documentation Guide, Openai Security Ownership Map and 56 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.