- Home
- Skills
- Code Quality & Review
- Security Code Review, Structured Findings by Severity
Works with the AI tools you already use
Security Code Review, Structured Findings by Severity
Runs a tested secret/vulnerability scan, then a structured security review. Findings grouped by file, severity-rated, ready to act on.
$9
Security Code Review, Structured Findings by Severity
Example session with this skill installed
Do a security review of this code before I merge it:
import os
import subprocess
api_key = "sk-abc123def456ghi789jklmnopqrstuv"
def run_command(user_input):
os.system("echo " + user_input)
subprocess.run(user_input, shell=True)
def unsafe_eval(data):
return eval(data)
def safe_function(x, y):
return x + y
- Read your context and instructions
- Compiled the security code review
Summary
4 Critical findings, 0 Warning, 0 Suggestion.
[CRITICAL] Hardcoded API secret key, line 4
Issue: An API secret key is hardcoded directly in source code.
Impact: Anyone with read access to this file or its version control history can extract and use this key.
Fix: Load it from an environment variable: api_key = os.environ["API_KEY"]
[CRITICAL] Command injection via os.system(), line 7
Issue: User-controlled input is concatenated directly into a shell command.
Impact: An attacker could inject arbitrary shell commands.
Fix: Use subprocess.run(["echo", user_input]) with a list of arguments instead of string concatenation.
[CRITICAL] Command injection via shell=True, line 8
Issue: User input is passed directly to a shell via shell=True.
Impact: Same as above, arbitrary command execution.
Fix: Pass the command as a list of arguments and drop shell=True.
[CRITICAL] Arbitrary code execution via eval(), line 11
Issue: eval() executes its input as Python code with no restriction.
Impact: If the input can be influenced by a user, this allows full code execution.
Fix: Replace with a safe parser for the actual data format needed, ast.literal_eval() for Python literals, or json.loads() for JSON.
No issues found in safe_function.
Most urgent: the hardcoded API key should be rotated immediately, not just removed from the current version. It's likely already exposed in version control history.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
A structured, security-focused code review skill that goes beyond a generic "looks fine to me" pass. It runs a deterministic scan for hardcoded secrets and dangerous function calls first, tested and verified to catch real planted issues, not just theoretically correct. Then it layers a full contextual review across ten security categories: injection, authentication, data exposure, access control, misconfiguration, insecure deserialization, vulnerable dependencies, SSRF, path traversal, and logging gaps. Every finding comes out grouped by file, severity-rated (Critical, Warning, Suggestion) using consistent definitions, with a concrete fix, not vague advice.
Built by someone with a real security background: Google Cybersecurity certified, with hands-on SIEM and threat-analysis experience. This is a review aid for everyday development, not a replacement for a licensed penetration tester on regulated or high-stakes systems.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 24 days ago
- Passed all security checks, Safe to install