All skills
jeffallan avatar

/security-reviewer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/security-reviewer

This session only. Nothing lands on disk.

referencesinfrastructure-security.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Infrastructure Security

DevSecOps Integration

CI/CD Security Pipeline

# GitHub Actions - Security scanning
name: Security Pipeline
on: [push, pull_request]
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: returntocorp/semgrep-action@v1
      - uses: gitleaks/gitleaks-action@v2
      - uses: aquasecurity/trivy-action@master
        with:
          scan-type: 'fs'
          severity: 'CRITICAL,HIGH'

Infrastructure as Code Security

# Terraform/CloudFormation scanning
checkov -d terraform/ --framework terraform
tfsec terraform/
terrascan scan -d terraform/

# Kubernetes manifest scanning
kubesec scan deployment.yaml

Cloud Security Controls

AWS Security Hardening

# Enable security services
aws guardduty create-detector --enable
aws securityhub enable-security-hub
aws cloudtrail create-trail --name security-trail --s3-bucket-name logs

# Check S3 bucket security
aws s3api list-buckets --query "Buckets[].Name" | \
  xargs -I {} aws s3api get-bucket-acl --bucket {}

# IAM password policy
aws iam update-account-password-policy \
  --minimum-password-length 14 \
  --require-symbols --require-numbers \
  --require-uppercase-characters --require-lowercase-characters

Azure Security

# Enable Security Center
az security auto-provisioning-setting update --name default --auto-provision on

# Enable disk encryption
az vm encryption enable --resource-group myRG --name myVM --disk-encryption-keyvault myKV

GCP Security

# Enable Security Command Center
gcloud services enable securitycenter.googleapis.com

# Enable VPC Flow Logs
gcloud compute networks subnets update SUBNET --enable-flow-logs

Container Security

Secure Dockerfile

FROM node:18-alpine
RUN addgroup -g 1001 -S nodejs && adduser -S nodejs -u 1001
WORKDIR /app
COPY --chown=nodejs:nodejs package*.json ./
RUN npm ci --only=production
USER nodejs
EXPOSE 3000
HEALTHCHECK --interval=30s CMD node healthcheck.js
CMD ["node", "server.js"]

Kubernetes Security

# Pod Security Standards
apiVersion: v1
kind: Pod
metadata:
  name: secure-pod
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 1000
    fsGroup: 2000
    seccompProfile:
      type: RuntimeDefault
  containers:
  - name: app
    image: myapp:1.0
    securityContext:
      allowPrivilegeEscalation: false
      readOnlyRootFilesystem: true
      capabilities:
        drop: [ALL]
    resources:
      limits:
        memory: "128Mi"
        cpu: "500m"
---
# Network Policy - Default deny
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
spec:
  podSelector: {}
  policyTypes:
  - Ingress
  - Egress

Compliance Automation

CIS Benchmark Scanning

# Docker CIS benchmark
docker run --net host --pid host --cap-add audit_control \
  -v /var/lib:/var/lib -v /var/run/docker.sock:/var/run/docker.sock \
  docker/docker-bench-security

# Kubernetes CIS benchmark
kube-bench run --targets master,node

# Linux system hardening
lynis audit system --quick

Compliance as Code (InSpec)

# controls/baseline.rb
control 'ssh-hardening' do
  impact 1.0
  title 'SSH Security Configuration'

  describe sshd_config do
    its('Protocol') { should eq '2' }
    its('PermitRootLogin') { should eq 'no' }
    its('PasswordAuthentication') { should eq 'no' }
  end
end

control 'encryption-at-rest' do
  impact 1.0
  title 'S3 Encryption Enabled'

  describe aws_s3_bucket('my-bucket') do
    it { should have_default_encryption_enabled }
  end
end

Secrets Management

HashiCorp Vault

# Initialize and configure
vault operator init
vault secrets enable -path=secret kv-v2

# Store secrets
vault kv put secret/app/config api_key="secret123"

# Dynamic database credentials
vault secrets enable database
vault write database/config/postgresql \
  plugin_name=postgresql-database-plugin \
  allowed_roles="app" \
  connection_url="postgresql://{{username}}:{{password}}@localhost:5432/" \
  username="vault" password="vaultpass"

vault write database/roles/app \
  db_name=postgresql \
  creation_statements="CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}';" \
  default_ttl="1h" max_ttl="24h"

Kubernetes Secrets with External Secrets Operator

apiVersion: external-secrets.io/v1beta1
kind: SecretStore
metadata:
  name: vault-backend
spec:
  provider:
    vault:
      server: "https://vault.example.com"
      path: "secret"
      auth:
        kubernetes:
          role: "app-role"
---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
  name: app-secrets
spec:
  refreshInterval: 1h
  secretStoreRef:
    name: vault-backend
  target:
    name: app-secrets
  data:
  - secretKey: api_key
    remoteRef:
      key: secret/app/config
      property: api_key

Security Monitoring

SIEM Log Shipping (Filebeat)

filebeat.inputs:
- type: log
  paths:
    - /var/log/auth.log
    - /var/log/nginx/*.log
  fields:
    environment: production

output.elasticsearch:
  hosts: ["elasticsearch:9200"]
  index: "security-logs-%{+yyyy.MM.dd}"

Quick Reference

Area Tool Purpose
Cloud Security Prowler, ScoutSuite AWS/Azure/GCP audit
Container Trivy, Clair Image scanning
IaC Checkov, tfsec Terraform/CloudFormation
Secrets Vault, Sealed Secrets Secret management
Compliance InSpec, OpenSCAP CIS benchmarks
Monitoring ELK, Splunk SIEM
Framework Focus Key Controls
SOC 2 Security controls Access, encryption, monitoring
ISO 27001 ISMS Policy, risk, audit
PCI DSS Payment security Network segmentation, encryption
HIPAA Healthcare Encryption, access logs
GDPR Data privacy Consent, retention, DLP

Source: SKILL.md on GitHub

2 alerts16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive framework for security auditing and penetration testing. It includes instructions for identifying vulnerabilities, scanning for secrets, and evaluating privilege escalation paths. While it contains commands for sensitive actions such as credential harvesting and local enumeration, these are documented within a professional audit context requiring explicit authorization and rules of engagement.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    5/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files Runs commands
All 4 allowed tools
ReadGrepGlobBash
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.1",
  "domain": "security",
  "triggers": "security review, vulnerability scan, SAST, security audit, penetration test, code audit, security analysis, infrastructure security, DevSecOps, cloud security, compliance audit",
  "role": "specialist",
  "scope": "review",
  "output-format": "report",
  "related-skills": "secure-code-guardian, code-reviewer, devops-engineer, cloud-architect, kubernetes-specialist, api-designer, mcp-developer"
}
  • Security
  • DevOps
  • vulnerability-scanning
  • sast
  • code-audit
  • penetration-testing
  • secrets-scanning
  • compliance
  • infrastructure-security
  • cvss

README badge

README badge for jeffallan/claude-skills/security-reviewer

Identifies code, infrastructure, and dependency vulnerabilities through SAST scanning, manual review, and penetration testing, then produces severity-rated audit reports with remediation guidance. Covers secrets scanning, cloud security, compliance checks, and DevSecOps workflows using tools like Semgrep, Bandit, Gitleaks, and Trivy.

Generated from the current SKILL.md.

Does this skill perform active penetration testing or only static analysis?
It does both. The skill includes SAST scanning (semgrep, bandit), dependency audits, and secrets scanning, but also supports active penetration testing and reconnaissance. However, it requires written authorization and scope confirmation before any active testing.
What automated scanning tools does this skill use?
The skill runs semgrep, bandit, gitleaks, npm audit, and trivy. It treats automated tools as a starting point and requires manual review of auth, input handling, and crypto, since tools miss context-dependent vulnerabilities.
Does this skill generate compliance reports for SOC2 or ISO27001?
The skill produces structured vulnerability reports with severity ratings, findings with remediation guidance, and checklists. It references CIS benchmarks, SOC2, and ISO27001 in its knowledge base, but is designed primarily for vulnerability identification and audit support rather than compliance certification.
Can I use this skill to test production systems?
No. The skill explicitly requires written authorization and scope confirmation before active testing, and prohibits testing on production systems without explicit permission or causing service disruption or data loss.

Generated from the current SKILL.md. These answers refresh after source changes.