Security Review — Security skill for Claude Code
Review code for security vulnerabilities (OWASP Top 10).
How to install Security Review
Installs to ~/.claude/skills/shakacode-claude-code-commands-skills-agents-security-review/SKILL.md
mkdir -p ~/.claude/skills/shakacode-claude-code-commands-skills-agents-security-review && curl -fsSL https://raw.githubusercontent.com/shakacode/claude-code-commands-skills-agents/HEAD/commands/security-review.md -o ~/.claude/skills/shakacode-claude-code-commands-skills-agents-security-review/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Review does
description: Review code for security vulnerabilities (OWASP Top 10)
Review the specified code for security vulnerabilities.
Instructions
**Identify the target**: The user will specify a file, directory, or feature to review. If not specified, ask what to review.
**Read the code** and analyze against these categories:
Injection (SQLi, XSS, Command Injection)
- User input used in SQL queries without parameterization
- User input rendered in HTML without escaping
- User in
Alternatives in Security
- Security Best Practices — Review code for language-specific security vulnerabilities 14.6k ★
- Deepsec — Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents 7.8k ★
- Claude Code Security Review — An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities 3.9k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat
Security Sweep
Comprehensive security scanner covering OWASP Top 10 (2025), Mobile Top 10 (2024), and LLM Top 10 (2025). Scan
Security Audit Stride
Chạy checklist bảo mật OWASP Top 10 + STRIDE trước bước review cuối của Tech Lead trong WF-REVIEW-CRIT (luôn c
Owasp Security
OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026) with code review checklists, secure patterns, and
CodeWarden
CodeWarden is an autonomous code review agent that watches every pull request on GitHub. It pairs deterministi
Security Audit
Audit de securite complet d'une web app (OWASP Top 10, CWE/CVE, headers, auth, paywall, infra). Genere un rapp
Related Agents
Production Security Auditor
Audits codebase for security vulnerabilities — OWASP Top 10 detection, secrets exposure, injection vectors, au
Dnp Security Auditor
🔐 .NET security audit — OWASP Top 10 for APIs, secrets exposure, auth configuration, dependency vulnerabiliti
Security Sentinel
Deep security review focused on OWASP Top 10, injection, auth/authz, data exposure, and dependency vulnerabili