security-reviewer
security reviewer
What it does
- Code review and SAST scanning
- Vulnerability scanning and dependency audits
- Secrets scanning and credential detection
- Penetration testing and reconnaissance
- Infrastructure and cloud security audits
- DevSecOps pipelines and compliance automation
- semgrep --config=auto .
Derived from the skill's own SKILL.md documentation · extracted 2026-07-23
security-reviewer FAQ
What does the security-reviewer skill do?
Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists. Code review and SAST scanning Vulnerability scanning and dependency audits
How do I install security-reviewer?
Run: npx -y skills add https://github.com/jeffallan/claude-skills --skill security-reviewer --agent claude-code — the source lives at github.com/jeffallan/claude-skills.
Maintain security-reviewer?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[security-reviewer on getagentictools](https://getagentictools.com/skills/jeffallan-claude-skills-security-reviewer?ref=badge) npx agentictools info skills/jeffallan-claude-skills-security-reviewer The second line is the CLI lookup for this page — handy in READMEs and docs.