Install Reviewer — Security agent for Claude Code
Security review BEFORE anything is installed or connected — a package, app, MCP server, plugin, skill, extension, script from the internet, or a change to Claude settings or autostart.
How to install Install Reviewer
Installs to ~/.claude/agents/skrripa-install-checkpoint-install-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Skrripa/install-checkpoint/HEAD/agents/install-reviewer.md -o ~/.claude/agents/skrripa-install-checkpoint-install-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Install Reviewer does
name: install-reviewer description: Security review BEFORE anything is installed or connected — a package, app, MCP server, plugin, skill, extension, script from the internet, or a change to Claude settings or autostart. Use it whenever Install Checkpoint pauses a command, or when the user asks "is this safe to install?". Reads and researches only; never installs. Saves a verdict (OK / CAUTION / BLOCK) that the checkpoint shows to the human. tools: Read, Grep, Glob, Bash, WebFetch, WebSearch
Alternatives in Security
- Config Auditor — Security header and server configuration auditor 812 ★
- API Expert — Use this agent for Output.ai API server design, Express middleware configuration, workflow execution endpoints 434 ★
- Audit Verifier — Adversarially verifies one candidate finding from /bug-audit — tries to REFUTE it by reading the code and, whe 335 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Dependency Vetter
Supply-chain security audit of a third-party package (npm today) at ONE exact resolved version, run BEFORE it
Docs Keeper
Documentation custodian for ralphctl. Use when code lands that may have outdated CLAUDE.md or anything under .
Light Security ClaudeSettingsAudit
Audit Claude Code config files (settings.json, settings.local.json, .mcp.json) for unsafe or malicious content
My Security Reviewer
Fresh-context security reviewer for agent tooling - skills, subagents, commands, hooks, shell/sync scripts, do
Ehs AI Safety
AI, agent and chatbot security specialist for the Ethical Hacker Squad. Reviews the instruction/data boundary,
Security Officer
OWASP + STRIDE pass over a change or surface. Fails closed — unresolved risk blocks ship. Spawn for anything t
Related Skills
Replyreviewer
Generate point-by-point LaTeX reviewer response letters and apply track-change markup directly in the paper us
Twin Sparrow Apps
Use installed Codex app connectors for Twin Sparrow-focused work. Trigger when the user asks to use Codex Apps
Task Decomposer
Force a plan-and-confirm step before any multi-file or multi-step change. Invoke whenever the user requests a