All skills
jeffallan avatar

/security-reviewer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/security-reviewer

This session only. Nothing lands on disk.

referencesreport-template.md

≈938 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Report Template

Full Report Template

# Security Review Report

## Executive Summary

| Field | Value |
|-------|-------|
| **Application** | [Application Name] |
| **Review Date** | [YYYY-MM-DD] |
| **Reviewer** | [Name] |
| **Scope** | [Files/modules reviewed] |
| **Overall Risk Level** | [Critical/High/Medium/Low] |

### Key Findings
- X Critical vulnerabilities requiring immediate attention
- Y High-severity issues to address before deployment
- Z Medium/Low issues for future consideration

## Findings Summary

| Severity | Count | Status |
|----------|-------|--------|
| Critical | X | Requires immediate fix |
| High | X | Fix before deployment |
| Medium | X | Fix in next sprint |
| Low | X | Backlog |

## Detailed Findings

### [CRITICAL] SQL Injection in User Search

| Field | Value |
|-------|-------|
| **ID** | SEC-001 |
| **Location** | `src/api/users.ts:45` |
| **CWE** | CWE-89 |
| **CVSS** | 9.8 (Critical) |

**Description**
User input directly concatenated into SQL query without sanitization.

**Vulnerable Code**
```typescript
const query = `SELECT * FROM users WHERE name LIKE '%${searchTerm}%'`;

Proof of Concept

GET /api/users?search=' OR '1'='1

Impact

  • Full database access
  • Data exfiltration
  • Data modification/deletion
  • Potential RCE via SQL features

Remediation Use parameterized queries:

const query = 'SELECT * FROM users WHERE name LIKE $1';
db.query(query, [`%${searchTerm}%`]);

Effort: 1 hour Priority: Immediate


[HIGH] Weak Password Requirements

Field Value
ID SEC-002
Location src/auth/validation.ts:12
CWE CWE-521
CVSS 7.5 (High)

Description Password policy requires only 6 characters with no complexity requirements.

Current Policy

const isValid = password.length >= 6;

Impact

  • Susceptible to brute force attacks
  • Dictionary attack vulnerability

Remediation Implement stronger requirements:

const isValid =
  password.length >= 12 &&
  /[A-Z]/.test(password) &&
  /[a-z]/.test(password) &&
  /[0-9]/.test(password) &&
  /[^A-Za-z0-9]/.test(password);

Effort: 30 minutes Priority: Before deployment

Automated Scan Results

Dependency Vulnerabilities

Package Severity CVE Fix
lodash High CVE-2021-xxxx Upgrade to 4.17.21

SAST Findings

Tool Critical High Medium Low
Semgrep 1 3 5 8
npm audit 0 2 4 10

Recommendations

Immediate (This Sprint)

  1. Fix SQL injection vulnerability (SEC-001)
  2. Implement parameterized queries globally
  3. Update vulnerable dependencies

Short-term (Next Sprint)

  1. Strengthen password policy (SEC-002)
  2. Add input validation middleware
  3. Enable security headers

Long-term

  1. Implement SAST in CI/CD pipeline
  2. Schedule regular security reviews
  3. Security training for developers

Appendix

Tools Used

  • Semgrep v1.x
  • npm audit
  • Gitleaks v8.x
  • Manual code review

References

  • OWASP Top 10 2021
  • CWE Database
  • CVSS Calculator

## Severity Definitions

| Severity | CVSS Score | Response Time |
|----------|------------|---------------|
| Critical | 9.0 - 10.0 | Immediate |
| High | 7.0 - 8.9 | 24-48 hours |
| Medium | 4.0 - 6.9 | 1-2 weeks |
| Low | 0.1 - 3.9 | Next release |

## Quick Reference

| Section | Purpose |
|---------|---------|
| Executive Summary | Management overview |
| Findings Summary | Quick count by severity |
| Detailed Findings | Technical details |
| Scan Results | Automated tool output |
| Recommendations | Prioritized action items |

Source: SKILL.md on GitHub

2 alerts16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive framework for security auditing and penetration testing. It includes instructions for identifying vulnerabilities, scanning for secrets, and evaluating privilege escalation paths. While it contains commands for sensitive actions such as credential harvesting and local enumeration, these are documented within a professional audit context requiring explicit authorization and rules of engagement.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    5/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
What it can do
Reads files Runs commands
All 4 allowed tools
ReadGrepGlobBash
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.1",
  "domain": "security",
  "triggers": "security review, vulnerability scan, SAST, security audit, penetration test, code audit, security analysis, infrastructure security, DevSecOps, cloud security, compliance audit",
  "role": "specialist",
  "scope": "review",
  "output-format": "report",
  "related-skills": "secure-code-guardian, code-reviewer, devops-engineer, cloud-architect, kubernetes-specialist, api-designer, mcp-developer"
}
  • Security
  • DevOps
  • vulnerability-scanning
  • sast
  • code-audit
  • penetration-testing
  • secrets-scanning
  • compliance
  • infrastructure-security
  • cvss

README badge

README badge for jeffallan/claude-skills/security-reviewer

Identifies code, infrastructure, and dependency vulnerabilities through SAST scanning, manual review, and penetration testing, then produces severity-rated audit reports with remediation guidance. Covers secrets scanning, cloud security, compliance checks, and DevSecOps workflows using tools like Semgrep, Bandit, Gitleaks, and Trivy.

Generated from the current SKILL.md.

Does this skill perform active penetration testing or only static analysis?
It does both. The skill includes SAST scanning (semgrep, bandit), dependency audits, and secrets scanning, but also supports active penetration testing and reconnaissance. However, it requires written authorization and scope confirmation before any active testing.
What automated scanning tools does this skill use?
The skill runs semgrep, bandit, gitleaks, npm audit, and trivy. It treats automated tools as a starting point and requires manual review of auth, input handling, and crypto, since tools miss context-dependent vulnerabilities.
Does this skill generate compliance reports for SOC2 or ISO27001?
The skill produces structured vulnerability reports with severity ratings, findings with remediation guidance, and checklists. It references CIS benchmarks, SOC2, and ISO27001 in its knowledge base, but is designed primarily for vulnerability identification and audit support rather than compliance certification.
Can I use this skill to test production systems?
No. The skill explicitly requires written authorization and scope confirmation before active testing, and prohibits testing on production systems without explicit permission or causing service disruption or data loss.

Generated from the current SKILL.md. These answers refresh after source changes.