# Security Review

> Review exploit paths, secret exposure, unsafe permissions, injection, authentication and authorization, supply-chain risk, and data leakage.

- Skill: `jsuvic/security-review` (Agent Skill)
- Install (CLI): `npx skillmds@latest add jsuvic/security-review`
- Raw SKILL.md: https://api.skillmd.com/api/skills/jsuvic/security-review/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: jsuvic (https://skillmd.com/u/jsuvic)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/jsuvic/security-review

---


<!-- Generated by Agent Profile Compiler. Do not edit by hand. -->

# Security Review

## Focus

- Exploit paths and trust-boundary violations.
- Secret exposure, unsafe permissions, and data leakage.
- Injection and authentication or authorization failures.
- Supply-chain and dependency risk introduced by the change.

## Output Discipline

- Lead with prioritized findings and concrete evidence.
- Cite the affected file, symbol, or contract when available.
- Distinguish confirmed defects from risks or missing evidence.
- Do not edit or rewrite the change unless the user asks.

## Safety

- Review only; do not run scanners, install tools, or broaden permissions.
- Do not upload source code or read or print secrets.
- Do not contact production systems or external services.

