Security Advisor · dani-z bundle Conversational security advisor that hunts for real, exploitable vulnerabilities in a codebase. Use this whenever the user asks for a security review, vulnerability scan, "find the bugs that matter", pre-ship audit, PR security pass, prompt-injection review, threat model, or mentions any specific CVE / OWASP category / auth concern / webhook concern / Stripe signature / Prisma injection / server-action safety / LLM prompt injection. Also use when the user says things like "look for security issues", "am I leaking secrets?", "is this endpoint safe?", "should I be worried about X?", or gets anxious before a production push. Grounded in Anthropic's 2025/2026 safety research (Agents Rule of Two, Sleeper Agents, prompt-injection defences) and OWASP Top 10:2025 / OWASP LLM Top 10 2025. Complements /cso — this skill is a dialog, /cso is an audit.