security-reviewer

Review codebases for vulnerabilities and generate structured security audit reports.

2|Updated Feb 5, 2026
One-click install
npx skills add https://github.com/damacus/agent-skills --skill security-reviewer-damacus
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-reviewer
Source: https://github.com/damacus/agent-skills/tree/main/skills/security-reviewer
Command: npx skills add https://github.com/damacus/agent-skills --skill security-reviewer-damacus

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews.

Core Features & Use Cases

  • SAST scanning and vulnerability assessment across codebases
  • Secrets detection, code quality review, and infrastructure security checks
  • Use Case: When preparing for a security release, generate a comprehensive audit report with findings and mitigations.

Quick Start

Provide a complete security assessment plan and report template for the current project.

Frequently Asked Questions about security-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a SAST scan to identify vulnerabilities in my codebase?

Perform a SAST scan by executing a security review of your codebase to identify vulnerabilities. The process analyzes source code for security flaws, detects exposed secrets, and produces structured reports with severity ratings and remediation guidance.

What is included in a structured code audit report for a security release?

A structured code audit report includes identified vulnerabilities, severity ratings, remediation guidance, and an audit trail. It covers secrets detection, code quality review, and infrastructure security checks to ensure comprehensive mitigations before deployment.

Can I use this to run infrastructure security checks for cloud security reviews?

Yes, you can use this to run infrastructure security checks for cloud security reviews. The assessment applies to DevSecOps practices and analyzes infrastructure configurations to produce structured reports with severity ratings and actionable remediation guidance.

What's the best way to generate remediation guidance for penetration testing findings?

Generate remediation guidance for penetration testing findings by conducting a security review of the codebase. The analysis produces a comprehensive audit report that maps identified vulnerabilities to severity ratings and provides actionable mitigation steps.

Does the security review require any specific dependencies or tools to start?

No specific dependencies are required to start the security review. You can invoke the assessment directly on your software projects to perform SAST runs, detect secrets, and analyze infrastructure security without external tool installations.