Reviewing Security

Deep nine-axis pre-release security audit for high-risk features. Invoke this skill when the user says "security review", "security audit", "review for security", "is this secure", or "before we ship" — especially when code touches authentication, authorization, PII handling, payment flows, or file uploads. SCOPE: Injection, Authentication, Authorization, Sensitive Data Exposure, Misconfiguration, Secrets Leakage, Input Validation, and Dependency CVEs. NOTE: SSRF findings — delegate to ssrf-review skill for deeper analysis. NOTE: CSRF findings — delegate to csrf-review skill for deeper analysis. Do NOT use this skill for routine post-generation review — that is auto-code-review's job. Use this skill only for explicit pre-release audits of security-critical features.

xuanjgcarryyou Updated

File contents

xuanjgcarryyou/claude-skill/tree/main/.claude/skills/reviewing-security commit 57f0dd99cb

Frequently asked questions

npx skillmds@latest add xuanjgcarryyou/reviewing-security