Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance.
Works with
Conducts SAST scans, dependency audits, secrets scanning, and manual code review across authentication, input handling, and cryptography
Supports penetration testing, infrastructure security audits, and cloud security reviews with scope verification and rules of engagement enforcement
Produces severity-rated findings (Critical/High/Medium/Low/In
AI-first code editor with Composer
Before installing skills in Cursor, ensure your development environment meets these requirements:
node --versionsecurity-reviewerExecute the skills CLI command in your project's root directory to begin installation:
Fetches security-reviewer from jeffallan/claude-skills and configures it for Cursor.
The CLI shows a list of agents. Use arrow keys and space to select Cursor:
Confirm successful installation by checking the skill directory location:
Restart Cursor to activate security-reviewer. Access via /security-reviewer in your agent's command palette.
We perform automated surface-level scans (Gen AI Scanner, Socket, Snyk) during installation. These checks detect common vulnerabilities but do not guarantee complete security. Always review skill source code and verify the publisher's reputation before production use.
Skills execute code in your environment. Always review source, verify the publisher, and test in isolation before production.
Submit your Claude Code skill and start earning
Create detailed user stories, acceptance criteria, and feature specs
Example
Generate user stories for 'password reset feature' with acceptance criteria, edge cases, and test scenarios
Reduce spec writing time by 50%, ensure comprehensive coverage
Research competitors, compare features, identify gaps
Example
Analyze 5 competitor products, create feature comparison matrix, suggest differentiation opportunities
Complete competitive research in 2 hours instead of 2 days
Evaluate features using frameworks (RICE, ICE, Kano) and create prioritized backlogs
Example
Score 20 feature ideas using RICE framework, generate prioritized roadmap with rationale
0
total installs
0
this week
7.9K
GitHub stars
0
upvotes
Run in your terminal
0
installs
0
this week
7.9K
stars
Security analyst specializing in code review, vulnerability identification, penetration testing, and infrastructure security.
semgrep --config=auto .bandit -r ./srcgitleaks detect --source=.npm audit --audit-level=moderatetrivy fs .Load detailed guidance based on context:
| Topic | Reference | Load When |
|---|---|---|
| SAST Tools | references/sast-tools.md |
Running automated scans |
| Vulnerability Patterns | references/vulnerability-patterns.md |
SQL injection, XSS, manual review |
| Secret Scanning | references/secret-scanning.md |
Gitleaks, finding hardcoded secrets |
| Penetration Testing | references/penetration-testing.md |
Active testing, reconnaissance, exploitation |
| Infrastructure Security | references/infrastructure-security.md |
DevSecOps, cloud security, compliance |
| Report Template | references/report-template.md |
Writing security report |
ID: FIND-001
Severity: High (CVSS 8.1)
Title: SQL Injection in user search endpoint
File: src/api/users.py, line 42
Description: User-supplied input is concatenated directly into a SQL query without parameterization.
Impact: An attacker can read, modify, or delete database contents.
Remediation: Use parameterized queries or an ORM. Replace `cursor.execute(f"SELECT * FROM users WHERE name='{name}'")`
with `cursor.execute("SELECT * FROM users WHERE name=%s", (name,))`.
References: CWE-89, OWASP A03:2021
OWASP Top 10, CWE, Semgrep, Bandit, ESLint Security, gosec, npm audit, gitleaks, trufflehog, CVSS scoring, nmap, Burp Suite, sqlmap, Trivy, Checkov, HashiCorp Vault, AWS Security Hub, CIS benchmarks, SOC2, ISO27001
Make data-driven prioritization decisions faster
Draft PRDs, status updates, and stakeholder presentations
Example
Create executive summary of Q3 roadmap, monthly progress report, feature launch announcement
Save 3-5 hours/week on communication overhead
Prerequisites
Time Estimate
30-60 minutes to see productivity improvements
Steps
Common Pitfalls
✓ Do
✗ Don't
💡 Pro Tips
✓ Use when
Use for user story writing, competitive research, roadmap prioritization, stakeholder communication, and PRD drafting. Best for reducing repetitive documentation and research work.
✗ Avoid when
Avoid for strategic product vision (requires deep customer empathy), pricing decisions (needs market and financial expertise), or when face-to-face customer discovery is more valuable than speed.
shadcn/improve
mattpocock/skills
parcadei/continuous-claude-v3
cursor/plugins
ailabs-393/ai-labs-claude-skills
ailabs-393/ai-labs-claude-skills
I recommend security-reviewer for anyone iterating fast on agent tooling; clear intent and a small, reviewable surface area.
Solid pick for teams standardizing on skills: security-reviewer is focused, and the summary matches what you get after install.
We added security-reviewer from the explainx registry; install was straightforward and the SKILL.md answered most questions upfront.
Keeps context tight: security-reviewer is the kind of skill you can hand to a new teammate without a long onboarding doc.
I recommend security-reviewer for anyone iterating fast on agent tooling; clear intent and a small, reviewable surface area.
Useful defaults in security-reviewer — fewer surprises than typical one-off scripts, and it plays nicely with `npx skills` flows.
Registry listing for security-reviewer matched our evaluation — installs cleanly and behaves as described in the markdown.
security-reviewer reduced setup friction for our internal harness; good balance of opinion and flexibility.
security-reviewer is among the better-maintained entries we tried; worth keeping pinned for repeat workflows.
security-reviewer fits our agent workflows well — practical, well scoped, and easy to wire into existing repos.
showing 1-10 of 72