Security Review

Security review knowledge delivered as parent-inline context (the form-factor counterpart to the security agent). Threat-models a code change, scores risk with CWE/CVE evidence, and returns a verdict. Use to review a diff or snippet for vulnerabilities when you want the security knowledge inline rather than dispatched to a subagent. Do NOT use for STRIDE attack-surface analysis of a system or architecture; use threat-modeling instead. Do NOT use to decide whether security review is warranted (use security-detection).

rjmurillo Updated

File contents

rjmurillo/ai-agents/tree/main/.claude/skills/security-review commit a5b203c229

Frequently asked questions

npx skillmds@latest add rjmurillo/security-review