security-reviewer

Identify security vulnerabilities and generate structured audit reports with severity ratings.

Updated Mar 17, 2026
One-click install
npx skills add https://github.com/Blake-John/agent-config --skill security-reviewer-blake-john
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-reviewer
Source: https://github.com/Blake-John/agent-config/tree/main/.agents/skill_spec/security-reviewer
Command: npx skills add https://github.com/Blake-John/agent-config --skill security-reviewer-blake-john

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security reviews of codebases and infrastructure are time-consuming and error-prone; this skill identifies vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance.

Core Features & Use Cases

  • Identify vulnerabilities via SAST, secrets scanning, dependency audits, and infrastructure reviews
  • Generate vulnerability reports with severity ratings, remediation guidance, and compliance checklists
  • Integrate into DevSecOps pipelines and CI/CD processes for automated security governance
  • Use Case: When auditing a project, run automated scans and produce a prioritized remediation plan.

Quick Start

Initiate a security review on a repository and generate a prioritized remediation report with actionable steps.

Frequently Asked Questions about security-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify security vulnerabilities in my codebase and infrastructure?

Security audits identify vulnerabilities by running SAST, secrets scanning, dependency audits, and infrastructure reviews to generate structured reports with severity ratings and remediation guidance for your codebase.

How does SAST integrate into DevSecOps pipelines for automated security governance?

SAST integrates into DevSecOps pipelines by automating security scans within CI/CD processes, enabling continuous vulnerability detection and generating prioritized remediation plans to maintain compliance throughout development.

Do I need explicit authorization before running a security audit on a repository?

Yes, security audits require explicit scope definition and authorization before testing begins, ensuring that vulnerability scans and infrastructure reviews operate within approved boundaries and generate accurate compliance checklists.

What's the best way to generate a prioritized remediation plan from a dependency audit?

The best way to generate a prioritized remediation plan is conducting a dependency audit that applies CVSS-based severity scoring to identified vulnerabilities, producing detailed findings with exact locations and actionable remediation steps.

Can I use this security audit approach for cloud security reviews and compliance checklists?

Yes, security audit approaches support cloud security reviews by identifying infrastructure vulnerabilities and generating compliance checklists alongside structured audit reports, providing actionable remediation guidance tailored to cloud environments.

What limitations apply when scanning for secrets and vulnerabilities across large codebases?

Limitations include the requirement for explicit scope definition before testing, and while detailed findings with locations and CVSS severity scores are generated, remediation guidance depends on the defined authorization boundaries.