Security Reviewer Heavy — Security agent for Claude Code
Security review for changes that touch security-sensitive areas — authentication, authorisation, session or token handling, cryptography, secrets, trust-boundary input parsing, or anything CLAUDE.md m.
How to install Security Reviewer Heavy
Installs to ~/.claude/agents/prototypo-codequalityexplorer-security-reviewer-heavy.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/prototypo/codequalityexplorer/HEAD/agents/security-reviewer-heavy.md -o ~/.claude/agents/prototypo-codequalityexplorer-security-reviewer-heavy.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Reviewer Heavy does
name: security-reviewer-heavy description: Security review for changes that touch security-sensitive areas — authentication, authorisation, session or token handling, cryptography, secrets, trust-boundary input parsing, or anything CLAUDE.md marks as security-critical. Same PASS/FAIL contract as the security-reviewer agent. Only use this agent when the project-manager's routing rules (in CLAUDE.md) select it; for everything else use the standard security-reviewer. model: opus tools: Read, Ba
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Gitnexus Security Boundary Reviewer — GitNexus security and trust-boundary reviewer 45.8k ★
- Review Security — Reviews code changes for security vulnerabilities including injection attacks, sensitive data exposure, insecu 432 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Proteus Security Verifier
Proteus second verifier for tickets touching auth, input parsing, secrets, file or network I/O, money, persona
Stamity Security
Reviews the security surface of a change set — authentication, authorization, cryptography, trust boundaries,
Hive Security Verifier
hivemind second verifier for tickets touching auth, input parsing, secrets, file or network I/O. Reviews a dif
Fleet Review Deep
Frontier reviewer for very hard reviews. Use only when the user names it, when the change crosses a security o
Craft Code Reviewer Deep
Deep code review on Opus 4.8 for high-stakes PRs — release branches, security-sensitive code, large architectu
Security Officer
OWASP + STRIDE pass over a change or surface. Fails closed — unresolved risk blocks ship. Spawn for anything t
Related Skills
Rogue Auth Access Control Skill
Expert authentication and authorization engineering: identity lifecycle, session/token handling, password/OTP
My Security Review
Run a personal agent-tooling security review - secrets, shell/hook command execution, untrusted input, plugin/
Change Heavy
Heavy-mode 6-stage pipeline for changes that meet the project's CLAUDE.md Heavy-rigor trigger — its named high