security-review

Audit web applications and infrastructure for security vulnerabilities and compliance.

1|Updated Mar 26, 2026
One-click install
npx skills add https://github.com/jdiegosierra/enterprise-agent-plugins --skill security-review-jdiegosierra
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/jdiegosierra/enterprise-agent-plugins/tree/main/plugins/acme-engineering/src/skills/security-review
Command: npx skills add https://github.com/jdiegosierra/enterprise-agent-plugins --skill security-review-jdiegosierra

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps security analysts efficiently perform comprehensive security assessments by guiding through code reviews, vulnerability identifications, and infrastructure security checks.

Core Features & Use Cases

  • Automated & Manual Security Assessment: Performs automated scans with tools like SAST, secrets detection, and dependency checks, complemented by manual review guidance.
  • Vulnerability Identification & Prioritization: Classifies issues by severity, offers remediation guidance, and supports compliance assessments.
  • Use Case: Security teams can use this Skill to conduct pre-deployment security reviews, generate detailed vulnerability reports, and ensure compliance with security standards.

Quick Start

Load the detailed security assessment guidance, then initiate a scan of your project's codebase to identify potential vulnerabilities and misconfigurations.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a comprehensive security audit for web applications?

A comprehensive security audit combines automated SAST scans, secrets detection, and dependency checks with manual code review guidance to identify vulnerabilities. This process classifies issues by severity and provides remediation prioritization to reduce infrastructure risks.

What is the best way to prioritize vulnerabilities found during a code review?

Vulnerability prioritization involves classifying identified security issues by severity and offering targeted remediation guidance. This ensures security teams address the most critical infrastructure risks first while maintaining compliance with security standards.

Can I use automated tools for secrets detection and dependency checks before deployment?

Yes, automated security assessments perform secrets detection and dependency checks alongside SAST scans. These automated tools are complemented by manual inspection guidance to ensure thorough pre-deployment vulnerability detection and configuration review.

How do I generate detailed vulnerability reports for compliance checks?

Detailed vulnerability reports are generated by scanning your project's codebase to identify potential vulnerabilities and misconfigurations. The results map to compliance checks, providing security teams with documented evidence for security standard adherence.

Does infrastructure security review require manual inspection alongside automated scans?

Yes, infrastructure security review requires manual inspection alongside automated scans. Combining SAST, secrets detection, and dependency checks with manual code review guidance ensures comprehensive vulnerability analysis and accurate misconfiguration identification.