security-reviewer

Identify and report security vulnerabilities in code, configurations, and infrastructure.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/paulund/skills --skill security-reviewer-paulund
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-reviewer
Source: https://github.com/paulund/skills/tree/main/skills/security-reviewer
Command: npx skills add https://github.com/paulund/skills --skill security-reviewer-paulund

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews.

Core Features & Use Cases

  • Perform automated SAST scans, secret scanning, and infrastructure security checks across codebases and deployment configurations.
  • Provide actionable remediation guidance and risk scoring to support DevSecOps and security governance.
  • Use during code reviews and security assessments to identify vulnerabilities, misconfigurations, and compliance gaps in cloud environments.

Quick Start

Provide a comprehensive security assessment by running automated scans, manual review, and reporting within authorized scope.

Frequently Asked Questions about security-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a SAST scan and security audit on my codebase?

A SAST scan and security audit identifies vulnerabilities in code, configurations, and infrastructure. This Skill performs automated SAST, secret scanning, and manual review within a defined engagement scope to report security flaws.

What is the best way to review cloud infrastructure for security misconfigurations?

The best way to review cloud infrastructure for security misconfigurations is to analyze deployment configurations for compliance gaps. This Skill identifies cloud vulnerabilities and provides actionable remediation guidance and risk scoring to support DevSecOps governance.

Can I use this for penetration testing and finding vulnerabilities in configurations?

Yes, you can use this for penetration testing and finding vulnerabilities in configurations. It identifies and reports security vulnerabilities during audits, applying to penetration testing, code reviews, and infrastructure checks within authorized scope.

Does this security review process provide actionable remediation guidance?

Yes, the security review process provides actionable remediation guidance and risk scoring. It supports DevSecOps and security governance by delivering specific steps to fix identified vulnerabilities, misconfigurations, and compliance gaps in cloud environments.

When do I need to define an engagement scope for a security audit?

You need to define an engagement scope for a security audit before running automated scans, manual reviews, and reporting. Defining the scope ensures the vulnerability identification, secret scanning, and penetration testing actions remain authorized and targeted.