Sdlc Security Reviewer — Security agent for Claude Code
Security review for production readiness.
How to install Sdlc Security Reviewer
Installs to ~/.claude/agents/denizokcu-claude-code-ai-development-workflow-sdlc-security-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/DenizOkcu/claude-code-ai-development-workflow/HEAD/.claude/agents/sdlc-security-reviewer.md -o ~/.claude/agents/denizokcu-claude-code-ai-development-workflow-sdlc-security-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Sdlc Security Reviewer does
name: sdlc-security-reviewer description: Security review for production readiness. Runs OWASP checks, threat modeling, dependency audit, and secret detection on changed code. Produces SECURITY.md with a verdict. Use during the parallel review phase of the SDLC workflow. model: claude-opus-4-6 tools:
- Read
- Write
- Bash
- Glob
- Grep
Security Reviewer Agent
**Mindset:** What can an attacker do with this code? Focus on real exploitable issues, not theoretical concerns.
**
Alternatives in Security
- Review Security — Reviews code changes for security vulnerabilities including injection attacks, sensitive data exposure, insecu 432 ★
- Vuln Hunter — Walks in-scope files item-by-item against the gated checklists and phase-triggered known-vectors, recording an 50 ★
- Audit Content — Evaluates E-E-A-T signals, readability, thin content detection, duplicate content, freshness, and AI citation 45 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Narwhal Content
Content quality & E-E-A-T specialist for the narwhal audit — depth, readability, experience/expertise/trust si
Pan Hardener
Security audit agent — OWASP Top 10 + STRIDE threat modeling across files changed in a phase. Read-only. Spawn
Agentille Security Reviewer
Reviews changed code for security issues — secret leaks, injection vectors, auth bypass, unsafe deserializatio
Skill Quarantine
Vets a third-party Claude Code skill/plugin (git URL or local path in the sandbox) for security red flags befo
Vuln Validator
Independently tries to refute candidate vulnerabilities and records a reasoned verdict for each. Must be a dif
Senior Security Engineer
Senior security engineer covering application security (OWASP-style threat modeling, secure coding, auth desig
Related Skills
Squad Review
Run only the reviewer agent against the current run's code and tests. Produces a PASS/FAIL verdict and routes
Skill Threat Modeling
Code-First Deep Risk Analysis Skill for Claude Code - 8-Phase Workflow with Security design review, STRIDE Thr
J Audit
Security threat model and vulnerability scan — STRIDE analysis, SAST patterns, and compliance mapping. Use whe