🛡️
QualityTypeScript

Security Review

by codeaholicguy

Security Review is a Quality skill for Claude Code, published by codeaholicguy in ai-devkit.

1.6K stars242 forkson codeaholicguy/ai-devkitAdded 2026/08/19Repository updated 2026/08/18
agent-frameworkagent-skillsaiai-agentsai-codingantigravityclaude-codeclicodex-clicoding-agentscursor-aideveloper-toolsgemini-climcpmemoryopencodepisoftware-engineeringworkflow-automation
Install in seconds
Install Security Review
Copy Security Review into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/codeaholicguy/ai-devkit/tree/main/skills/security-review ~/.claude/skills/security-review

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/codeaholicguy/ai-devkit.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/security-review/SKILL.md in codeaholicguy/ai-devkit
Installs to
~/.claude/skills/security-review
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What Security Review does

Security Review finds vulnerabilities in code, skills, and prompts — including OWASP Top 10, prompt injection, business logic flaws, and insecure defaults — before they ship. Use it when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.

Security Review is cataloged under Quality on DirSkills. Security Review comes from a repository tagged agent-framework, agent-skills, ai, ai-agents and ai-coding.

Documentation

README

Security Review

Find vulnerabilities before they ship.

Hard Rules

  • Do not dismiss a finding without evidence it is unexploitable.
  • Do not commit, log, or surface secrets discovered during review — flag and recommend rotation.
  • Do not modify code until the user approves a remediation plan.

Workflow

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Security Review

  • What else does codeaholicguy publish alongside Security Review?

    Security Review is one of 25 skills that DirSkills catalogs from codeaholicguy/ai-devkit, the repository it ships in. Its siblings there include Agent Communication, Agent Management and Agent Orchestration. Each one is a separate skill with its own page in this directory, installs the same way Security Review does, and is maintained by codeaholicguy in that same repository. The rest of the collection is listed on the codeaholicguy/ai-devkit page.

  • How does Security Review compare to other Quality skills?

    Security Review ranks #632 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Security Review against them. Open each page to compare what they document and how they install.

More from codeaholicguy/ai-devkit

Security Review is one of 25 skills cataloged on DirSkills from codeaholicguy/ai-devkit.

See all 25 skills
💬
2w ago

Agent Communication

Agent Communication lets an AI agent discover active AI coding agents, read their recent context, and send them messages or request information using the ai-devkit CLI. Use it when one agent needs to coordinate with another or hand off work.
AI Engineering
1.6K242
🤖
2w ago

Agent Management

Agent Management uses ai-devkit agent commands to list, start, inspect, assign work to, and stop AI agents. Use it when an agent needs to identify itself, manage other agents, or delegate tasks.
AI Engineering
1.6K242
🧭
2w ago

Agent Orchestration

Agent Orchestration coordinates dependencies between multiple AI agents, polls their progress, unblocks waiting agents, relays outputs, resolves conflicts, and verifies completion. Use it for ongoing multi-agent supervision rather than one-off agent actions.
AI Engineering
1.6K242
💡
2w ago

Brainstorm

Brainstorm runs a compact diverge-to-converge loop that helps users generate, challenge, compare, and narrow ideas. Use it for ideation, evaluating options, naming, technical approaches, content angles, or strategic decisions.
AI Engineering
1.6K242
📝
2w ago

Changelog

Changelog updates the Unreleased section of CHANGELOG.md from commits after the latest release. Use it when asked to update changelog or release notes from recent git commits.
Automation
1.6K242
2w ago

Dev Commit

Dev Commit stages and commits only the files that belong to a requested change, avoiding unrelated user edits and generated artifacts. Use it when an agent needs to make an intentional, verified conventional commit or prepare a PR-ready checkpoint.
Automation
1.6K242