Security Reviewer

Multi-language security review for web apps, APIs, and CLIs. Use whenever code is added or modified — new endpoints, auth/RBAC changes, template or DOM rendering, outbound HTTP, dependency updates, IaC/config changes, or end-of-feature reviews. Covers Python, JavaScript, TypeScript, Go, Rust, Java/Kotlin, Ruby, C#/.NET, plus shared OWASP Top 10 and ASVS L1 logic. Triggers on phrases like "security review", "review this for security", "audit this code", "is this safe", "AppSec check", "threat-model this change", "supply chain risk", "before I merge", or whenever a senior engineer would pause to ask "what could go wrong here". Pairs with the `security-reviewer` subagent and the session-start / pre-bash / post-edit hooks shipped alongside it.

security-phoenix-demo c9f9fa6 25 files · 157.9 KB Updated

File contents

security-phoenix-demo/security-skills-claude-code/tree/main/skills/Security Assessment/Security-automated-claude-skills commit c9f9fa6f04

Frequently asked questions

npx skillmds@latest add security-phoenix-demo/security-reviewer