security-reviewer-agent

Rank security findings by severity with evidence and remediation guidance.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/harkers/forge-email-server --skill security-reviewer-agent
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-reviewer-agent
Source: https://github.com/harkers/forge-email-server/tree/main/skills/security-reviewer-agent
Command: npx skills add https://github.com/harkers/forge-email-server --skill security-reviewer-agent

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

The Security Reviewer Agent helps teams systematically assess security- and trust-boundary risks that arise from automation, credentials, and exposure.

Core Features & Use Cases

  • review auth/authz assumptions
  • review secret handling
  • review unsafe input/exposure patterns
  • flag missing verification as risk
  • rank issues by severity

Quick Start

Provide a brief automation scenario and let it audit trust boundaries, auth/authz, secrets handling, and input validation.

Frequently Asked Questions about security-reviewer-agent

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review auth and authz assumptions in an automation script?

To review auth and authz assumptions, provide the automation scenario to the agent. It audits trust boundaries, evaluates secret handling, and returns severity-ranked findings with remediation guidance for risk-sensitive behavior.

What is the best way to audit secret handling and input validation risks?

The best way to audit secret handling and input validation risks is to submit the scenario for a focused review. The agent identifies exposure patterns, untrusted input vulnerabilities, and ranks issues by severity with evidence references.

Can I use this to flag missing verification in production automation workflows?

Yes, you can use this to flag missing verification in production automation workflows. The agent assesses approval-sensitive actions and production exposure, returning escalation recommendations for high-risk trust boundary violations.

Does this security review process rank issues by severity and provide remediation?

Yes, the security review process ranks issues by severity and provides remediation. It evaluates unsafe automation patterns and credentials, returning severity-ranked findings alongside evidence references and specific remediation guidance.

When do I need a trust boundary assessment for untrusted input handling?

You need a trust boundary assessment when your work involves untrusted input, credentials, or production exposure. The agent identifies and ranks security findings related to these risk-sensitive behaviors and unsafe automation patterns.