Security Advisor — Security agent for Claude Code
Read-only security reviewer for auth, authz, payments, RLS, secrets, PII, and deletion.
How to install Security Advisor
Installs to ~/.claude/agents/jpcasa-real-skills-security-advisor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/jpcasa/real-skills/HEAD/agents/security-advisor.md -o ~/.claude/agents/jpcasa-real-skills-security-advisor.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Advisor does
name: security-advisor description: Read-only security reviewer for auth, authz, payments, RLS, secrets, PII, and deletion. Writes every finding in full prose and blocks shipping on exploitable or data-loss issues. The /do-shit orchestrator spawns it in the review stage when a path rule or the plan touches those areas. Never fixes, edits, pushes, or writes to trackers. tools: Read, Grep, Glob, Bash model: inherit stage: review
You review the change for security and data-safety risk. You
Alternatives in Security
- Knowledge Base Loader — Phase KB0 intake agent that converts staged, untrusted application documentation into a cited, security-orient 125 ★
- Audit Ecommerce — Audits product page SEO — Product/Offer/AggregateRating schema, pricing consistency, variant handling, breadcr 45 ★
- DB Supabase Expert — Supabase and PostgreSQL expert 34 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Security Triage
Independently evaluate a single security finding to decide whether it is a real, exploitable vulnerability or
Santa Reviewer
Use this agent for the Santa Method — an adversarial BREAKER + SIMPLIFIER + VERIFIER review that hunts REAL co
Web Pentester
Authorized offensive security testing of web applications you own or have written permission to test - finding
Evolve Authz Gap Scan
Authorization-gap adversary for the Evolve Loop (Evaluate archetype). The advisor INSERTS this phase after bui
Gilfoyle
Gilfoyle (Гілфойл, Silicon Valley) — security specialist for deep vulnerability audits — OWASP Top 10, auth/au
Advisor Freeberg
Runs the checksum language audit (primary deliverable) and assembles the final review document as a 3-section
Related Skills
Migration Audit
Safety review of pending Supabase / Postgres migrations: destructive ops, locking impact on large tables, miss
Change Heavy
Heavy-mode 6-stage pipeline for changes that meet the project's CLAUDE.md Heavy-rigor trigger — its named high
Claude Code Privacy Guard
🛡️ Claude Code plugin that blocks prompts containing secrets, API keys, and PII before they reach Claude.