security-review

Audits Go API, Convex data layer, web app, and cloud infrastructure for security risks and actionable mitigations.

3|Updated Feb 7, 2026
One-click install
npx skills add https://github.com/Develonaut/bnto --skill security-review-develonaut
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/Develonaut/bnto/tree/main/.claude/skills/security-review
Command: npx skills add https://github.com/Develonaut/bnto --skill security-review-develonaut

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security and compliance gaps across code, cloud services, and deployment surfaces by providing a structured audit that surfaces actionable mitigations.

Core Features & Use Cases

  • Secret & credential scanning across the repository, CI/CD configurations, and infrastructure.
  • Go API, Convex data layer, and web app risk assessment with attack surface mapping, access control checks, and data exposure review.
  • Production-ready remediation guidance, prioritized action lists, and governance alignment.

Quick Start

Audit the repository and infrastructure using the security checklist and generate a prioritized remediation plan.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my Go API and Convex data layer for security risks?

Secret scanning for security involves checking the repository, CI/CD configurations, and infrastructure for exposed credentials. This security review process enforces checks across deployment surfaces to identify and mitigate credential leakage risks.

Can I assess infrastructure security across Railway and Cloudflare R2?

Security review for open-source readiness involves auditing the codebase and cloud services to identify compliance gaps. It produces a prioritized remediation plan and governance alignment to ensure production-ready security posture before release.

What is the best way to generate a prioritized security remediation plan?

The best way to generate a prioritized security remediation plan is to audit the codebase and infrastructure using a security checklist. This surfaces actionable mitigations for dependency risks, access control, and data exposure.

Does this security audit check for input validation and error disclosure?

This security audit does check for input validation and error disclosure. It enforces comprehensive checks across the Go API, web app, and infrastructure to identify risks and produce actionable findings for these specific vulnerabilities.