security-reviewer

Installation
SKILL.md

security-reviewer (Codex Compatibility)

Use this skill after code changes that touch input handling, auth, APIs, data access, uploads, payments, or external integrations.

Routing Boundary

Use this skill when security is the main question:

  • OWASP/security audit/security review
  • secret leak, token exposure, unsafe logging
  • auth bypass, authorization gaps, session/token handling
  • injection, XSS, SSRF, unsafe file upload or command execution

Do not use this as the default owner for ordinary maintainability review. If security is only one item in a general PR review, code-reviewer can flag it, but explicit security-audit wording should route here.

Security Review Workflow

  1. Initial Scan
  • Locate auth, API endpoints, DB queries, file handling, and external calls.
  • Check for hardcoded secrets and unsafe config defaults.
Related skills
Installs
3
GitHub Stars
2.1K
First Seen
5 days ago