security-review

Review codebases and cloud infrastructure for OWASP Top 10 risks.

Updated Feb 20, 2026
One-click install
npx skills add https://github.com/saajunaid/junai --skill security-review-saajunaid
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/saajunaid/junai/tree/main/.github/skills/coding/security-review
Command: npx skills add https://github.com/saajunaid/junai --skill security-review-saajunaid

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security review workflow covering OWASP Top 10, code scanning, and cloud infrastructure.

Core Features & Use Cases

  • Comprehensive OWASP Top 10 checks across API endpoints, auth flows, and data handling.
  • Integrated phase-driven checks for cloud infrastructure, secrets management, and CI/CD security.
  • Actionable remediation guidance with evidence-rich reporting for developers and operators.

Quick Start

Run a comprehensive security review across code, dependencies, and cloud configurations.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OWASP Top 10 security review on my codebase?

To perform an OWASP Top 10 security review, you need to analyze API endpoints, authentication flows, and data handling patterns for vulnerabilities. This security review process applies comprehensive checks across languages and platforms to identify risks and generate evidence-rich remediation reports.

What is the best way to secure CI/CD pipelines and manage secrets in my infrastructure?

Securing CI/CD pipelines and managing secrets requires integrated phase-driven checks across your infrastructure configurations. A comprehensive security review identifies configuration vulnerabilities and provides actionable remediation guidance for developers and operators.

Can I use this security review for cloud infrastructure configurations across different platforms?

Yes, you can use this security review for cloud infrastructure across different platforms. It performs comprehensive checks for configuration hardening and vulnerabilities in cloud environments, applying its analysis broadly across languages and platforms without platform-specific limitations.

How does a comprehensive code and cloud security review work?

A comprehensive code and cloud security review works by performing phase-driven checks across codebases, dependencies, and cloud configurations. It scans API endpoints and CI/CD pipelines to identify OWASP Top 10 risks, outputting evidence-rich reports with specific remediation recommendations.

What does a security review check for in authentication and authorization flows?

A security review checks authentication and authorization flows for OWASP Top 10 vulnerabilities and insecure coding patterns. It evaluates these access control mechanisms to identify security risks, outputting actionable remediation guidance to harden your application.