What problem does it solve?
This Skill helps teams detect, explain, and prioritize security weaknesses before they become production incidents. It combines automated scanning with manual review so vulnerabilities, exposed secrets, risky dependencies, and insecure configurations are caught early.
Core Features & Use Cases
- Automated Security Scanning: Runs checks for secrets, static analysis findings, and dependency vulnerabilities across common development stacks.
- Manual Security Review: Evaluates authentication, authorization, input handling, error handling, headers, and other high-risk code paths.
- Threat and Compliance Analysis: Maps issues to OWASP Top 10, CWE Top 25, STRIDE, and SLSA so findings are actionable for engineering and audit workflows.
- Use Case: A team preparing a release can use this Skill to perform a final security sweep, generate a vulnerability report, and receive prioritized remediation guidance.
Quick Start
Use this skill to review the repository for security issues, identify the most important risks, and give clear remediation steps in priority order.