security-reviewer

Identify vulnerabilities in code, configurations, and infrastructure with prioritized remediation guidance.

Updated Feb 11, 2026
One-click install
npx skills add https://github.com/lamb92009/claude-skills --skill security-reviewer-lamb92009
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-reviewer
Source: https://github.com/lamb92009/claude-skills/tree/main/security-reviewer
Command: npx skills add https://github.com/lamb92009/claude-skills --skill security-reviewer-lamb92009

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Security audits, vulnerability identification, and infrastructure security reviews are essential to building and deploying trustworthy software. This skill provides a structured approach for assessing code, configurations, and cloud environments, enabling teams to uncover weaknesses and produce actionable remediation guidance.

Core Features & Use Cases

  • Scope & attack-surface mapping: Identify critical paths and potential entry points across code, dependencies, and infrastructure.
  • Automated scanning + manual review: Combine SAST, secret scanning, and configuration checks with expert analysis to validate findings.
  • Reporting & remediation: Document findings with severity, impact, and concrete fixes to drive resolution.

Quick Start

Identify and prioritize security findings for the target project by running automated scans and manual review to generate a prioritized security report.

Frequently Asked Questions about security-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify vulnerabilities in my codebase and cloud infrastructure?

Security reviews map your attack surface by identifying critical paths and potential entry points across code, dependencies, and cloud infrastructure. This process combines SAST, secret scanning, and configuration checks with expert analysis to validate findings and harden systems.

What is the best way to scan infrastructure configurations for security flaws?

The best way to scan infrastructure configurations is applying security reviews across cloud environments and CI pipelines. This combines automated configuration checks with expert manual analysis to detect flaws and deliver prioritized findings with concrete fixes.

How do I generate a prioritized security report with actionable remediation steps?

You generate a prioritized security report by running automated scans and manual review across your target project. This documents findings with severity, impact, and concrete fixes to drive resolution and produce actionable remediation guidance.

Can I use SAST and secret scanning together to harden my CI pipelines?

Yes, you can use SAST and secret scanning together to harden CI pipelines by applying security reviews across codebases and infrastructure. This detects flaws in code and configurations, producing prioritized findings to resolve vulnerabilities.

Does this security review approach work for mapping attack surfaces in cloud environments?

Yes, this security review approach works for mapping attack surfaces in cloud environments by identifying critical paths and potential entry points across code, dependencies, and infrastructure. It leverages infrastructure security practices to detect flaws and harden systems.