security-review

Audit trust boundaries, data flows, and secrets handling to produce a structured security review report.

2|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/chicongst/agent-skills-installer --skill security-review-chicongst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/chicongst/agent-skills-installer/tree/main/skills/security-review
Command: npx skills add https://github.com/chicongst/agent-skills-installer --skill security-review-chicongst

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identify and analyze security risks, trust boundaries, secrets handling, and potential abuse cases to reduce the likelihood of breaches.

Core Features & Use Cases

  • Threat modeling and vulnerability discovery across untrusted data entry points, authentication paths, and data flows.
  • Comprehensive risk assessment with prioritized remediation guidance and security hardening recommendations.
  • Structured reporting using standardized templates to enable actionable security reviews for developers and security teams.

Quick Start

Start by running a thorough security review of your target application using the provided Threat Model, Findings, and Hardening templates.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security review on my application's data flows and trust boundaries?

Perform a security review by auditing trust boundaries, data flows, and secrets handling across the target application to identify injections and authentication vulnerabilities. This process produces a structured security review report with threat model summaries and prioritized remediation.

What is threat modeling and how does it help identify security vulnerabilities?

Threat modeling discovers vulnerabilities across untrusted data entry points and authentication paths to reduce the likelihood of breaches. It maps potential abuse cases and data flows, providing a structured summary that enables actionable security reviews for developers and security teams.

How do I assess API security and authentication risks in my codebase?

Assess API security and authentication risks by auditing trust boundaries, authorization paths, and untrusted data entry points across the target application. The security review scopes injections, data protection, and API vulnerabilities, yielding concrete findings with severity ratings and hardening recommendations.

Can I generate a structured security report with prioritized remediation guidance?

Yes, you can generate a structured security review report using standardized templates that include a threat model summary, findings with severity, and hardening recommendations. This provides comprehensive risk assessment with prioritized remediation guidance for developers and security teams.

Does this security audit check for secrets handling and data protection issues?

Yes, the security audit explicitly checks secrets handling and data protection by analyzing data flows across the target application. It identifies potential abuse cases and documents concrete findings with severity ratings to reduce the likelihood of breaches.

What's the best way to harden application security against injections and unauthorized access?

Harden application security by conducting a comprehensive risk assessment that scopes injections, authentication, authorization, and API vulnerabilities. The resulting structured report provides concrete hardening recommendations and prioritized remediation guidance to mitigate identified threats.