code-security-review

Identify and remediate security vulnerabilities with OWASP Top 10 and CWE mappings.

14|11|Updated Dec 1, 2025
One-click install
npx skills add https://github.com/DauQuangThanh/hanoi-rainbow --skill code-security-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: code-security-review
Source: https://github.com/DauQuangThanh/hanoi-rainbow/tree/main/skills/code-security-review
Command: npx skills add https://github.com/DauQuangThanh/hanoi-rainbow --skill code-security-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Performs comprehensive, rigorous security code reviews to identify vulnerabilities, assess risks, and deliver actionable remediation guidance aligned with OWASP Top 10, CWE mappings, and relevant compliance requirements.

Core Features & Use Cases

  • Threat modeling and risk assessment for applications
  • Structured code analysis across languages to surface authentication, authorization, and cryptography flaws
  • Detailed vulnerability classification with CWE/OWASP mappings, CVSS scoring, and exploit scenarios
  • Comprehensive security reports and remediation guidance, including evidence and code references
  • Compliance alignment templates for PCI-DSS, GDPR, HIPAA, and SOC 2

Quick Start

Analyze a sample repository by running the security-review workflow on your project and generate a remediation-ready report

Frequently Asked Questions about code-security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OWASP Top 10 security code review on my web app?

To perform an OWASP Top 10 security code review, this Skill analyzes your codebase to identify vulnerabilities, maps them to CWE references, and generates detailed remediation guidance with CVSS scoring and exploit scenarios.

Can I use this to check my codebase for PCI-DSS and GDPR compliance gaps?

Yes, you can check for compliance gaps by running the security review workflow, which aligns identified vulnerabilities and remediation guidance with regulatory requirements including PCI-DSS, GDPR, HIPAA, and SOC 2.

What is the best way to map CWE vulnerabilities and generate CVSS scores during a security audit?

The best way to map CWE vulnerabilities and generate CVSS scores is to use an automated security analysis workflow that classifies flaws, references CVEs, and provides structured threat modeling and risk assessment outputs.

How do I remediate authentication and cryptography flaws found during a code security analysis?

To remediate authentication and cryptography flaws, this Skill provides actionable remediation guidance, structured code analysis, and evidence references directly targeting the vulnerabilities discovered across your application services.

Does this security review workflow support pre-deployment checks for APIs and web services?

Yes, this security review workflow supports pre-deployment checks across web apps, APIs, and services by surfacing authorization flaws, assessing risks, and producing remediation-ready reports before release.

When do I need threat modeling and vulnerability classification for my software project?

You need threat modeling and vulnerability classification when preparing for security audits or pre-deployment checks, ensuring your codebase is assessed for exploit scenarios and mapped to OWASP Top 10 risks.