Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Security Code Review, Structured Findings by Severity

    1

    Runs a tested secret/vulnerability scan, then a structured security review. Findings grouped by file, severity-rated, ready to act on.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Security Code Review, Structured Findings by Severity

    Security Code Review, Structured Findings by Severity

    Example session with this skill installed

    Do a security review of this code before I merge it:

    import os
    import subprocess
    

    api_key = "sk-abc123def456ghi789jklmnopqrstuv"

    def run_command(user_input):
        os.system("echo " + user_input)
        subprocess.run(user_input, shell=True)
    
    def unsafe_eval(data):
        return eval(data)
    
    def safe_function(x, y):
        return x + y
    
    • Read your context and instructions
    • Compiled the security code review

    Summary

    4 Critical findings, 0 Warning, 0 Suggestion.

    [CRITICAL] Hardcoded API secret key, line 4

    Issue: An API secret key is hardcoded directly in source code.
    Impact: Anyone with read access to this file or its version control history can extract and use this key.
    Fix: Load it from an environment variable: api_key = os.environ["API_KEY"]

    [CRITICAL] Command injection via os.system(), line 7

    Issue: User-controlled input is concatenated directly into a shell command.
    Impact: An attacker could inject arbitrary shell commands.
    Fix: Use subprocess.run(["echo", user_input]) with a list of arguments instead of string concatenation.

    [CRITICAL] Command injection via shell=True, line 8

    Issue: User input is passed directly to a shell via shell=True.
    Impact: Same as above, arbitrary command execution.
    Fix: Pass the command as a list of arguments and drop shell=True.

    [CRITICAL] Arbitrary code execution via eval(), line 11

    Issue: eval() executes its input as Python code with no restriction.
    Impact: If the input can be influenced by a user, this allows full code execution.
    Fix: Replace with a safe parser for the actual data format needed, ast.literal_eval() for Python literals, or json.loads() for JSON.

    No issues found in safe_function.

    Most urgent: the hardcoded API key should be rotated immediately, not just removed from the current version. It's likely already exposed in version control history.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Catch hardcoded API keys and secrets before they're committed.Flag command injection and eval() risks in a pull request.Get severity-rated security findings grouped by file, ready to act on.Run a structured security pass before deploying to production.

    About this skill

    A structured, security-focused code review skill that goes beyond a generic "looks fine to me" pass. It runs a deterministic scan for hardcoded secrets and dangerous function calls first, tested and verified to catch real planted issues, not just theoretically correct. Then it layers a full contextual review across ten security categories: injection, authentication, data exposure, access control, misconfiguration, insecure deserialization, vulnerable dependencies, SSRF, path traversal, and logging gaps. Every finding comes out grouped by file, severity-rated (Critical, Warning, Suggestion) using consistent definitions, with a concrete fix, not vague advice.

    Built by someone with a real security background: Google Cybersecurity certified, with hands-on SIEM and threat-analysis experience. This is a review aid for everyday development, not a replacement for a licensed penetration tester on regulated or high-stakes systems.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 24 days ago

    • Passed all security checks, Safe to install

    Listed24 days ago

    What's inside

    Frequently Asked Questions