security-review

Identify and remediate OWASP-aligned security vulnerabilities in codebases.

1|Updated Jan 22, 2026
One-click install
npx skills add https://github.com/MLGBJDLW/vellum --skill security-review-mlgbjdlw
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/MLGBJDLW/vellum/tree/main/packages/core/src/skill/builtin/security-review
Command: npx skills add https://github.com/MLGBJDLW/vellum --skill security-review-mlgbjdlw

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security audit guidelines covering OWASP Top 10 vulnerabilities, secure coding practices, authentication patterns, and code review checklists

Core Features & Use Cases

  • Guided security reviews with actionable checklists aligned to OWASP, CWE, and NIST.
  • Standardized patterns for authentication, authorization, secrets management, and input validation.
  • Use Case: Teams running regular security audits or integrating automated checks into CI/CD pipelines.

Quick Start

Run the OWASP Top 10 checklist against a project to identify and remediate high-risk vulnerabilities.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OWASP Top 10 security audit on my codebase?

Use a guided security review checklist aligned with OWASP Top 10 guidelines to identify and remediate common vulnerabilities across your web and backend applications during code reviews.

What is included in a secure coding checklist for authentication and secrets management?

A secure coding checklist provides standardized patterns for authentication, authorization, secrets management, and input validation to ensure consistent threat modeling and vulnerability remediation.

Can I use this security review process for both web and backend applications?

Yes, the security audit applies to code reviews, authentication patterns, and secure coding checks across both web and backend applications to remediate common vulnerabilities.

Does this security audit support integration into CI/CD pipelines?

Yes, teams running regular security audits can use these reproducible audit checklists to integrate automated checks into CI/CD pipelines for consistent vulnerability identification.

What's the best way to identify common security vulnerabilities during code reviews?

Apply structured review workflows and reproducible audit checklists aligned to OWASP, CWE, and NIST guidelines during code reviews to accurately identify and remediate common security vulnerabilities.

Why use structured threat modeling for security audits?

Structured threat modeling and reproducible audit checklists satisfy structured review workflows, ensuring consistent security posture and thorough remediation of common codebase vulnerabilities.