Topic · Security
Best security review skills for Claude Code, Codex and other agents.
- skills
- 611
- official
- 61
Security review skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format. | shareAI-lab/ | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | 9 days ago |
| 2 | General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs. | supabase/ | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | 5 days ago |
| 3 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | today |
| 4 | Runs an autonomous modify, verify, keep-or-discard loop against any metric, with subcommands for planning, debugging, fixing, security audits, shipping and more. | uditgoenka/ | 6.5k | 1 repo | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 5 | A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. | jewbetcha/ | 116 | 17 repos | ~3.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 6 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation. | vercel-labs/ | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 8 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 9 | Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart… | awesome-skills/ | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | 29 days ago |
| 10 | 10.Supabase A skill your agent uses when doing ANY task involving Supabase. | curvenote/ | 169 | 5 repos | ~2.2k | Automated safety check: Pass | Unknown | 9 days ago |
| 11 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 12 | Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner. | vercel-labs/ | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 13 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 14 | 14.Looper Scaffold a well-designed agent loop with best-practice coaching and a cross-model review council. | ksimback/ | 710 | — | ~2.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 15 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 16 | Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. | trailofbits/ | 512 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 mo ago |
| 17 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 18 | Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK. | kubeshark/ | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 19 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 20 | 20.Solana Dev A skill your agent uses when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my… | solana-foundation/ | 571 | — | ~3.8k | Automated safety check: Pass | MIT | 4 days ago |
| 21 | Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review. | awarexone/ | 5.3k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 22 | Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot. | HezaoHezao/ | 250 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 23 | Security code review for vulnerabilities. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 4 days ago |
| 24 | 24.PR Sweep Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when… | TanStack/ | 3.2k | — | ~4.6k | Automated safety check: Pass | MIT | today |
| 25 | Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts. | luongnv89/ | 42k | — | ~764 | Automated safety check: Pass | MIT | 7 days ago |
| 26 | Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. | lingbol088-spec/ | 222 | — | ~1.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 27 | OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews | nyldn/ | 4.2k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | today |
| 28 | Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. | mono/ | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | today |
| 29 | Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening. | symfony/ | 31k | — | ~2.9k | Automated safety check: Pass | MIT | today |
| 30 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 31 | Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues. | verdaccio/ | 18k | — | ~853 | Automated safety check: Pass | MIT | today |
| 32 | Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team. | tech-leads-club/ | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | 17 days ago |
| 33 | Verify that code changes do not introduce OAuth security vulnerabilities. | doorkeeper-gem/ | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 34 | 34.Vibe Check Security audit for web apps, especially AI-built ("vibe coded") ones. | benavlabs/ | 116 | — | ~1.1k | Automated safety check: Notes | MIT | 18 days ago |
| 35 | 35.Audit Flow Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. | zebbern/ | 4.6k | — | ~4.2k | Automated safety check: Pass | MIT | today |
| 36 | Apply modern web development best practices for security, compatibility, and code quality. | midudev/ | 114 | 3 repos | ~3k | Automated safety check: Pass | MIT | 9 days ago |
| 37 | 37.Flounder Operates Flounder, an autonomous white-hat security auditor. | adshao/ | 517 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 38 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 39 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 808 | — | ~690 | Automated safety check: Pass | MIT | 4 days ago |
| 40 | Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses. | pydantic/ | 8.6k | — | ~852 | Automated safety check: Pass | MIT | yesterday |
| 41 | 41.Bug Hunter Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. | codexstar69/ | 519 | — | ~5k | Automated safety check: Pass | MIT | 1 mo ago |
| 42 | Interact with Bitget Wallet API for crypto market data, token info, swap quotes, RWA (real-world asset) stock trading, and security audits. | bitget-wallet-ai-lab/ | 245 | — | ~7.6k | Automated safety check: Pass | MIT | 4 mo ago |
| 43 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 9 days ago |
| 44 | Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. | EpicenterHQ/ | 4.8k | — | ~896 | Automated safety check: Pass | Unknown | today |
| 45 | 45.Code Review Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output. | coderabbitai/ | 188 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 46 | Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner. | Fangcun-AI/ | 143 | — | ~2.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 47 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | 4 days ago |
| 48 | Scans the working directory for ignored errors, hard-coded secrets, debt comments, dead exports and type gaps, and reports findings by severity without editing files. | HarnessMD/ | 8.5k | — | ~350 | Automated safety check: Notes | MIT | today |
Questions, answered from the data.
What is the best security review skill?
Code Review Checklist from shareAI-lab/learn-claude-code ranks first of the 611 security review skills listed here, with the highest score: its repository has 78k GitHub stars, 5 other GitHub owners carry a copy, its SKILL.md loads about 1.1k tokens and it passes the automated safety check with no findings. Next come Supabase Development and Debugging and Security Auditor.
Which security review skills are official?
61 of the 611 security review skills are official, published by the vendor's own GitHub organization: Supabase Development and Debugging, Deepsec Vulnerability Scanner, CodeQL Security Scan, Deepsec Documentation Guide, Openai Security Ownership Map and 56 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34