security-reviewer

Automate security audits with SAST, dependency checks, and secrets scanning.

14|Updated Feb 5, 2026
One-click install
npx skills add https://github.com/alexander-danilenko/ai-skills --skill security-reviewer-alexander-danilenko
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-reviewer
Source: https://github.com/alexander-danilenko/ai-skills/tree/main/skills/security-reviewer
Command: npx skills add https://github.com/alexander-danilenko/ai-skills --skill security-reviewer-alexander-danilenko

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security audits are often tedious and inconsistent; this Skill provides structured, repeatable security reviews of code, configuration, and infrastructure to identify vulnerabilities and misconfigurations.

Core Features & Use Cases

  • SAST scanning and dependency checks for codebases to surface vulnerabilities early.
  • Secrets detection, access control review, and infrastructure hardening within DevSecOps pipelines.
  • Generate actionable security reports with risk ratings and remediation guidance for stakeholders.

Quick Start

Provide the project repository and security scope to generate a comprehensive security review report.

Frequently Asked Questions about security-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a SAST scan and secrets detection for my codebase?

To automate a SAST scan and secrets detection, provide your project repository and security scope to trigger an automated security review. The Skill scans codebases to surface vulnerabilities early and identify hidden secrets within your DevSecOps workflows.

How do I run a security review on my CI/CD pipeline and cloud configurations?

You can run a security review on CI/CD pipelines and cloud configurations by providing the relevant configuration contexts as input. The Skill applies infrastructure hardening checks and access control reviews to identify misconfigurations in your DevSecOps pipelines.

What is the best way to generate a security report with severity ratings and remediation guidance?

The best way to generate a security report with severity ratings is to use an automated security audit on your repository files. The Skill outputs a structured security report detailing risk ratings and actionable remediation guidance for stakeholders.

Does this security review process work for infrastructure hardening and dependency checks?

Yes, this security review process works for both infrastructure hardening and dependency checks. It evaluates cloud configurations and scans project dependencies to surface vulnerabilities early within your existing DevSecOps workflows.

What access do I need to provide for an automated security audit of my repository?

For an automated security audit, you need to provide access to your repository files and configuration contexts. This access allows the Skill to perform comprehensive SAST scanning, secrets detection, and infrastructure reviews.

Can I use this for penetration testing and access control review in DevSecOps?

Yes, you can use this for access control review and penetration testing contexts within DevSecOps. The Skill automates security audits by identifying vulnerabilities and misconfigurations across code, configuration, and infrastructure layers.