CodeWarden — Security skill for Claude Code
CodeWarden is an autonomous code review agent that watches every pull request on GitHub.
How to install CodeWarden
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open princekushwah2611/CodeWarden and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What CodeWarden does
CodeWarden is an autonomous code review agent that watches every pull request on GitHub. It pairs deterministic static analysis (Semgrep with OWASP Top 10 rulesets) with Claude's reasoning to find real vulnerabilities, rank them by severity, and explain both the risk and the fix. A RAG pipeline on ChromaDB indexes your team's own engineering guidel
Alternatives in Security
- Token Scan — Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP l 3.8k ★
- Node9 Proxy — The Execution Security Layer for the Agentic Era 209 ★
- Vibeship Scanner — a free vulnerability and security scanner for vibe coders, with 2000+ rulesets, and copy pasteable Master AI F 120 ★
README
🛡️ CodeWarden
**An agentic AI reviewer that watches every pull request for security risk and standards drift.**
CodeWarden is an autonomous code review agent that integrates directly with GitHub to review pull requests in real time. It performs multi-layered static security scans (Semgrep + OWASP Top 10), pairs findings with an LLM reasoning engine (Claude), and enforces team-specific coding standards using a Retrieval-Augmented Generation (RAG) pipeline powered by ChromaDB.
🌟 Key Capabilities
**Security Scanner Agent**
- Combines deterministic AST/SAST scanning (Semgrep OWASP Top 10 rulesets) with LLM deep reasoning.
- Categorizes issues with precise severity (
critical,high,medium,low) and explains why the vulnerability is risky and how to remediate it. - In-code suppression support via
// codewarden-ignorecomments.
**RAG Standards Agent**
- Ingests and vectorizes your team's internal engineering guidelines, conventions, and style guides.
- Dynamically retrieves standard chunks matching changed files in PR diffs.
- Enforces team conventions without generic or noisy lint warnings.
**Intelligent Aggregation Layer**
- Merges findings from both agents, eliminates duplicates, and ranks them by severity.
- Posts line-specific GitHub comments and a formatted review summary with clear emojis and action recommendations (
approve,comment, orrequest-changes).
**Interactive Developer Dashboard**
- Dark-mode-first developer UI built with React 19, Tailwind CSS v4, and Recharts.
- Overview metrics: Total PRs, Critical issues caught, Average response time, and Team health score.
- Detailed repository settings, standards document management, and review inspection with syntax-highlighted diffs and inline finding markers.
🏗️ Architecture
┌────────────────────┐
│ GitHub Repo │
│ (PR opened/synced) │
Related Skills
Claudrunner
Autonomous AI coding agent: finds bugs and security holes, fixes your Jira, Trello, GitHub Issues or Linear ti
Reviewer Gap Audit
You are the compact global omission auditor for a decomposed pull-request review. Primary specialists already
Don Cheli Sdd
Don Cheli — SDD Framework. The most comprehensive Specification-Driven Development framework for AI agents. 88
Security Playbook
Security skill pack for AI coding agents — behavioral guardrails, OWASP code/LLM rules, static analysis guidan
Install Audit
Audit a fresh install — plugin, declared dependencies, and what the human still has to do — before there is an
LaptopAI Agent
Fully local, privacy-first autonomous AI agent for laptop management — LangGraph reasoning loop, Ollama local
Related Agents
Semgrep Triager
Classifies semgrep scan findings as true or false positives by reading source context. Use when triaging stati
SEO Matomo
Matomo Reporting API analyst. Fetches organic traffic, top landing pages, device / country breakdowns, and ref
LLM AI Hunter
LLM and Agentic AI vulnerability specialist. Covers OWASP LLM Top 10 v2025 (LLM01-LLM10) and OWASP Agentic AI