review-security-compliance

review-security-compliance is a skill for Claude Code, Codex from JAXTech-Labs/claude-code-template. It costs 0 tokens per session (133 once invoked), scanned A, original, no licence file.

A review checklist for examining software or systems for security and compliance concerns.

In plain words
What is it for?
It is for carrying out security and compliance checks on a project, using the review criteria defined by the source template.
Why use it?
It helps identify security weaknesses and compliance issues that may otherwise be missed during a general code review.

Skill for Claude CodeCodex

Which agent this was written for is unclear — body not stored (licence); the path alone says nothing.

Good fit It is for carrying out security and compliance checks on a project, using the review criteria defined by the source template.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/jaxtech-labs/claude-code-template/review-security-compliance
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add JAXTech-Labs/claude-code-template --skill review-security-compliance
Clone the repo
git clone --depth 1 https://github.com/JAXTech-Labs/claude-code-template

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for review-security-compliance

README.md
[![agentmods](https://agentmods.dev/badge/skills/jaxtech-labs/claude-code-template/review-security-compliance.svg)](https://agentmods.dev/skills/jaxtech-labs/claude-code-template/review-security-compliance)
Your own site
<a href="https://agentmods.dev/skills/jaxtech-labs/claude-code-template/review-security-compliance"><img src="https://agentmods.dev/badge/skills/jaxtech-labs/claude-code-template/review-security-compliance.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 133 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00133
Opus 5 $0.00000 $0.00067
Sonnet 5 $0.00000 $0.00027
Haiku 4.5 $0.00000 $0.00013

Measured 8d ago against content hash 361c139f7f45, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

review-security-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/review-security-compliance/SKILL.md · 23 lines

The source is not reproduced here

No licence file

A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.

Read it on GitHub

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 23 lines · 0 tokens per session scan A 361c139f7f45

Subscribe to this mod's changes

review-security-compliance is a skill published in the GitHub repository JAXTech-Labs/claude-code-template (2 stars, last pushed 5mo ago), with no licence file. It costs nothing until one of its globs matches a file; then it loads 133 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

orchardcore-dnc-registry

Skill for configuring national and local do-not-call registry checks in CrestApps Orchard Core including Azure Blob Storage for uploaded local lists. Covers import suppression, provider settings, E.164 normalization, CSV processing, registry extensions, and tenant-aware Azure storage. Use this skill when requests…

CrestApps/CrestApps.AgentSkills · 135 tokens

orchardcore-audit-trail

Skill for configuring audit trail in Orchard Core. Covers audit event recording, AuditTrailPart for content tracking, event filtering and sorting, audit settings configuration, custom audit event providers, and audit trail feature setup. Use this skill when requests mention Orchard Core Audit Trail, Configure Audit…

CrestApps/CrestApps.AgentSkills · 189 tokens

cratis-chronicle-compliance

Model personal data in Chronicle with [PII] and [Subject], and erase it through crypto-shredding with IPIIManager. Use when an event or read model carries data about a natural person, when a subject must be identified for erasure, when a right-to-erasure request must be executed, or when redacting a stored event. Do…

Cratis/AI · 97 tokens

dotnet-analyzer-security-deps

Scan .NET projects for security vulnerabilities (OWASP Top 10), NuGet dependency health, CVE exploits, license compliance, and version conflicts using Roslyn and NuGet.org API. Use when the user asks to scan for security vulnerabilities, check for CVE, analyze dependency health, check license compliance, scan NuGet…

CartapenaBark/DotNetAnalyzer · 227 tokens

specification-writing

A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.

wanshuiyin/Auto-claude-code-research-in-sleep · 49 tokens

regulatory-research-fallback

Fallback workflow for regulatory research when web extraction tools fail on government PDFs.

HKUDS/OpenSpace · 20 tokens