Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
91
88%
Does it follow best practices?
Impact
97%
1.11xAverage score across 3 eval scenarios
High
Do not use without reviewing
False positive avoidance in Django codebase
Raw SQL injection flagged
100%
100%
mark_safe XSS flagged
100%
100%
User-URL SSRF flagged
100%
100%
Settings-based URL not flagged
57%
100%
Env var not flagged
70%
10%
Settings path not flagged
100%
100%
Path traversal with report_type flagged
100%
100%
Correct output format
14%
100%
Finding fields present
57%
100%
Always-flag patterns and severity classification
eval flagged as Critical
100%
100%
child_process.exec flagged
100%
100%
Hardcoded STRIPE_SECRET_KEY flagged
100%
100%
Hardcoded webhook secret flagged
100%
100%
dangerouslySetInnerHTML flagged
100%
100%
React JSX interpolation not flagged
100%
100%
Severity classification correct
100%
100%
VULN-NNN format used
85%
100%
Summary section present
71%
100%
Confidence-based reporting and weak crypto context
MD5 for passwords flagged
100%
100%
random for session token flagged
100%
100%
MD5 for file checksum not flagged
33%
100%
Path traversal flagged
100%
100%
Env-var base URL not flagged as SSRF
100%
100%
IDP token URL noted or flagged
100%
100%
Needs Verification section present
60%
100%
Correct output format
28%
100%
Fix suggestions included
100%
100%
170f233
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.