Borrowing it
Nothing to install: this file belongs to dinhnguyenngoc/spec-driven-claude-code. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/dinhnguyenngoc/spec-driven-claude-code/main/.claude/skills/security-review/SKILL.mdgit clone --depth 1 https://github.com/dinhnguyenngoc/spec-driven-claude-codeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dinhnguyenngoc/spec-driven-claude-code/security-review)<a href="https://agentmods.dev/skills/dinhnguyenngoc/spec-driven-claude-code/security-review"><img src="https://agentmods.dev/badge/skills/dinhnguyenngoc/spec-driven-claude-code/security-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/dinhnguyenngoc/spec-driven-claude-code/security-review"><img src="https://agentmods.dev/badge/skills/dinhnguyenngoc/spec-driven-claude-code/security-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Tool Misuse · line 67 Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.Fix: Override unsafe defaults with secure settings (verify=True, auth required, restrictive permissions). Review and harden all tool configurations.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.01590 |
| Opus 5 | $0.00007 | $0.00795 |
| Sonnet 5 | $0.00003 | $0.00318 |
| Haiku 4.5 | $0.00001 | $0.00159 |
Grade A, and why
security-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 202 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Review Skill
Purpose
Systematically scan the codebase for security vulnerabilities and produce a prioritized report.
Boundary vs
/scan: inside the/scanpipeline, do NOT run these tools manually — use the automation script.claude/scripts/scan-all.sh(percommands/scan.mdPhase 0). This skill is the manual / ad-hoc variant for quick audits outside the pipeline.
Checklist
🔴 Critical (Check First)
- Hardcoded secrets, API keys, passwords in source files
grep -rn --include="*.cs" --include="*.json" \ -E "(password|secret|apikey|api_key|connectionstring)\s*[:=]\s*['\"][^'\"]{8,}" src/ -
appsettings.jsonwith real secrets committedgit log --all --full-history -- "**/appsettings*.json" grep -rn "Password=" src/ - SQL injection via string concatenation (Dapper raw queries)
grep -rn --include="*.cs" "ExecuteAsync\|QueryAsync" src/ | grep -v "@" grep -rn --include="*.cs" '\$".*SELECT\|INSERT\|UPDATE\|DELETE' src/ - Insecure deserialization
grep -rn --include="*.cs" "JsonSerializer.Deserialize\|BinaryFormatter" src/
🟡 High Priority
- Missing
[Authorize]on protected endpointsgrep -rn --include="*.cs" "\[HttpGet\]\|\[HttpPost\]\|\[HttpPut\]\|\[HttpDelete\]" src/ | \ grep -v "\[Authorize\]" - Missing authorization checks (privilege escalation)
- Passwords stored without hashing
grep -rn --include="*.cs" "Password\s*=" src/ | grep -v "PasswordHash\|HashPassword" - JWT secrets too short or hardcoded
grep -rn --include="*.cs" --include="*.json" "Jwt.*Secret" src/ - No rate limiting on auth endpoints
grep -rn --include="*.cs" "\[HttpPost\].*login\|signin\|register" src/ - Missing FluentValidation on request DTOs
# Check if validators exist for Request classes find src/ -name "*Request.cs" -exec basename {} \; | \ while read f; do grep -l "${f%.*}Validator" src/ || echo "Missing: $f"; done
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 202 lines · 14 tokens per session scan A 2dba9f1cb970
security-review is a skill published in the GitHub repository dinhnguyenngoc/spec-driven-claude-code (20 stars, last pushed 10d ago), licensed MIT. It adds 14 tokens to every session and 1,590 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
specx-component-architecture
Design or review specx core scope boundaries in Python services. Use when deciding where code belongs across packaged scoped foundation bases, optional local foundation extensions, core/, capabilities, delivery, infrastructure, shared/, and ioc; when adding guardrails or splitting use cases, services, DTOs, schemas…
specx-tests
Add or refine tests for specx Python services. Use when creating unit tests for use cases/services, integration tests for FastAPI controllers or infrastructure adapters, e2e smoke tests, architecture import guardrails, DI override tests, pytest fixtures, or coverage and boundary checks.
specx-project-structure
Create or reshape a Python FastAPI service repo into the specx clean core/delivery architecture using packaged scoped foundation bases. Use when starting an API backend, adding the first src package, or establishing AGENTS.md, core/, optional local foundation/, delivery/, infrastructure, ioc/, migrations, and tests.
specx-add-core-use-case
Add or refactor a specx core scope use case. Use when implementing an externally meaningful application action under a core scope usecases package, adding same-file command/query inputs, result DTOs, coordinating services, opening a unit-of-work transaction, or moving behavior out of delivery or infrastructure into…
specx-add-infrastructure-adapter
Add technical infrastructure adapters for specx core scopes. Use when implementing SQLAlchemy repositories and Alembic-backed persistence, Redis stores, HTTP/network clients, file or queue adapters, unit-of-work implementations, gateway implementations for external APIs or SDKs such as OpenAI, or explicit diwire…
specx-diwire-composition
Wire dependency injection for a specx Python service with diwire. Use when adding ioc/container.py, explicit dependency registrations for capabilities, repositories, gateways, UoW managers, clients, settings, or factories, Injected[...] constructor fields, FastAPI app factory/lifecycle composition, test overrides, or…