code-review-security-first

Automate security-first PR reviews with ELIR-aligned checklist outputs.

2|Updated Apr 11, 2025
One-click install
npx skills add https://github.com/abhimehro/personal-config --skill code-review-security-first
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: code-review-security-first
Source: https://github.com/abhimehro/personal-config/tree/main/.cursor/skills/code-review-security-first
Command: npx skills add https://github.com/abhimehro/personal-config --skill code-review-security-first

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Reviews PRs with a security-first mindset across multiple repositories, providing a consistent, auditable checklist-driven process.

Core Features & Use Cases

  • Checklist-driven reviews that surface security risks first and require human verification for AI-assisted changes.
  • ELIR-aligned output ensuring explicit uncertainty and traceability across personal-config, email-security-pipeline, and ctrld-sync PRs.
  • Flexible mode selection with exactly one primary mode (Security, Performance, or Aesthetics) to tailor reviews.

Quick Start

Review a PR with Security as the primary mode and generate an auditable, checklist-driven report.

Frequently Asked Questions about code-review-security-first

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security-first code reviews for pull requests across multiple repositories?

Automate security-first code reviews by applying a checklist-driven process to pull requests across multiple codebases. This surfaces security risks first and enforces human verification for AI-assisted or agent-generated changes.

What is the best way to enforce human verification for AI-assisted pull requests?

Enforce human verification for AI-assisted pull requests by using a security-first review checklist. It enforces deterministic, templated outputs that require explicit human verification for non-human authored code changes.

How do I generate auditable checklist-driven outputs for pull request reviews?

Generate auditable pull request review outputs by capturing findings in a deterministic, templated format. This ELIR-aligned output ensures explicit uncertainty and traceability across your codebases.

Can I select different primary review modes like performance or aesthetics for my pull requests?

Yes, you can select exactly one primary review mode, such as Security, Performance, or Aesthetics. This tailors the checklist-driven review process to focus on your specific priority for the pull request.

Why should I use a security-first approach instead of a general code review checklist?

A security-first approach prioritizes vulnerability detection before other concerns, ensuring high-risk issues are addressed immediately. It provides consistent, auditable, ELIR-aligned traceability that general checklists lack.

Does the code review checklist work with agent-generated code changes?

Yes, the code review checklist is specifically designed for agent-generated code changes. It applies an ELIR-aligned review process that surfaces security concerns first and mandates human verification.