Security Review — Security agent for Claude Code
This agent should be invoked when the user asks to review code for security vulnerabilities, check for secrets, audit authentication, review API security, check for injection flaws, or perform OWASP c.
How to install Security Review
Installs to ~/.claude/agents/utkudarilmaz-claude-code-setup-security-review.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/utkudarilmaz/claude-code-setup/HEAD/.claude/agents/security-review.md -o ~/.claude/agents/utkudarilmaz-claude-code-setup-security-review.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Review does
name: security-review description: "This agent should be invoked when the user asks to review code for security vulnerabilities, check for secrets, audit authentication, review API security, check for injection flaws, or perform OWASP compliance review. Covers 13 security areas including auth, input validation, data exposure, cryptography, and modern attack vectors." model: opus color: red
You are a Security-Focused Code Reviewer with deep expertise in application security, penetration
Alternatives in Security
- Security Code Reviewer — Use this agent when you need to review code for security vulnerabilities, input validation issues, or authenti 2.8k ★
- Security Compliance Reviewer — Use this agent when code changes involve authentication, authorization, logging, configuration, or security-se 104 ★
- Dotnet Security Reviewer — WHEN reviewing .NET code for security vulnerabilities, OWASP compliance, secrets exposure, or cryptographic mi 76 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
API Security Audit
API security audit specialist. Use PROACTIVELY for REST API security audits, authentication vulnerabilities, a
Production Security Auditor
Audits codebase for security vulnerabilities — OWASP Top 10 detection, secrets exposure, injection vectors, au
API Security Analyst
Invoked by api-review-orchestrator or directly to audit a REST/OpenAPI spec and related implementation files f
API Security
Delegates to this agent when the user asks about API security testing, REST API attacks, GraphQL exploitation,
Tp Audit Scanner
Use this when the user asks for a security / quality audit, pre-release sweep, or "scan this for issues". Find
Ecc Security Reviewer
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles u
Related Skills
Security Sweep
Comprehensive security scanner covering OWASP Top 10 (2025), Mobile Top 10 (2024), and LLM Top 10 (2025). Scan
Security Auditor
Audits code for OWASP-class vulnerabilities — injection, auth flaws, secret leaks, unsafe deserialization.
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat