Security Compliance Reviewer — Security agent for Claude Code
Use this agent when code changes involve authentication, authorization, logging, configuration, or security-sensitive operations.
How to install Security Compliance Reviewer
Installs to ~/.claude/agents/microsoft-agent365-samples-security-compliance-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/microsoft/Agent365-Samples/HEAD/.claude/agents/security-compliance-reviewer.md -o ~/.claude/agents/microsoft-agent365-samples-security-compliance-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Compliance Reviewer does
name: security-compliance-reviewer description: "Use this agent when code changes involve authentication, authorization, logging, configuration, or security-sensitive operations. This agent should be proactively invoked after completing work on: (1) authentication or token handling code, (2) logging or observability implementations, (3) configuration file changes (appsettings.json, .env, pyproject.toml), (4) MCP server connection logic, (5) user input processing, (6) environment variable usa
Alternatives in Security
- JS Error Handler Auditor — Use this agent when you need to audit a JavaScript codebase for unhandled errors in top-level async operations 6.1k ★
- Security Code Reviewer — Use this agent when you need to review code for security vulnerabilities, input validation issues, or authenti 2.8k ★
- Convention Auditor — Audits codebase for convention violations including naming, logging, configuration, imports, and error handlin 160 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Security Analyst
Security vulnerability analyst for authentication, authorization, secrets, input validation. Use proactively w
Security Agent.Agent
Use when a change touches permissions, authentication, dependencies, configuration, release surfaces, sensitiv
Paranoid Auditor
Use this agent proactively after completing any significant work (integration code, architecture, deployment c
Be Auth
Authentication and authorization work — guards, tokens, SSO/external login handoffs, policies, and access pred
Ecc Security Reviewer
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles u
Eval Security
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles u
Related Skills
Rogue Auth Access Control Skill
Expert authentication and authorization engineering: identity lifecycle, session/token handling, password/OTP
Content Shipped
Proactively detect and log shipped content when user mentions publishing, launching, or completing work. Track
Arcjet Py
Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data r