security-review

security-review is a skill for Claude Code, Codex from jsuvic/agent-profile. It costs 27 tokens per session (186 once invoked), scanned A, original, Apache-2.0.

A security-focused review of code changes for ways attackers could exploit them, expose secrets, misuse permissions, inject data, bypass login controls, or leak information.

In plain words
What is it for?
Use it to review trust boundaries, secret handling, permissions, input injection, authentication, authorization, dependencies, and data leakage without running scanners or contacting external systems.
Why use it?
It helps identify security defects and risks introduced by a change before they become incidents.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents).

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/jsuvic/agent-profile/security-review
Any agent
npx skills add jsuvic/agent-profile --skill security-review
Clone the repo
git clone --depth 1 https://github.com/jsuvic/agent-profile

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/jsuvic/agent-profile/security-review.svg)](https://agentmods.dev/skills/jsuvic/agent-profile/security-review)
Your own site
<a href="https://agentmods.dev/skills/jsuvic/agent-profile/security-review"><img src="https://agentmods.dev/badge/skills/jsuvic/agent-profile/security-review.svg" alt="Measured on agentmods" height="20"></a>
Per session 27 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 186 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00027 $0.00186
Opus 5 $0.00014 $0.00093
Sonnet 5 $0.00005 $0.00037
Haiku 4.5 $0.00003 $0.00019

Measured 6d ago against content hash e31a5b93c093, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

security-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

fixtures/advanced-review-enabled/expected/.agents/skills/security-review/SKILL.md · 29 lines

What it actually says

Security Review

Focus

  • Exploit paths and trust-boundary violations.
  • Secret exposure, unsafe permissions, and data leakage.
  • Injection and authentication or authorization failures.
  • Supply-chain and dependency risk introduced by the change.

Output Discipline

  • Lead with prioritized findings and concrete evidence.
  • Cite the affected file, symbol, or contract when available.
  • Distinguish confirmed defects from risks or missing evidence.
  • Do not edit or rewrite the change unless the user asks.

Safety

  • Review only; do not run scanners, install tools, or broaden permissions.
  • Do not upload source code or read or print secrets.
  • Do not contact production systems or external services.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 29 lines · 27 tokens per session scan A e31a5b93c093

Subscribe to this mod's changes

security-review is a skill published in the GitHub repository jsuvic/agent-profile (3 stars, last pushed 3d ago), licensed Apache-2.0. It adds 27 tokens to every session and 186 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

tastemaker

Generate genuinely beautiful, on-brand UI instead of generic "AI slop" — use whenever the user asks to build, design, style, or improve a UI, landing page, dashboard, app screen, or component, whenever a PRD/spec needs a design pass before implementation, whenever the user pastes reference images/Pinterest/Dribbble…

codeswithroh/tastemaker · 202 tokens

fde

Keeps the engagement record for client work. Use when they name a client or stakeholder. Use when they debrief a meeting or paste notes. Use when they ask what was agreed. Use when they run a POC, change the client's codebase, prove it on their staging, go live, or need evals before a model acts. Use when they prep a…

suboss87/FDEOps · 125 tokens

kubernetes-skill

Prevent Kubernetes hallucinations by diagnosing and fixing failure modes: insecure workload defaults, resource starvation, network exposure, privilege sprawl, fragile rollouts, and API drift. Use when generating, reviewing, refactoring, or migrating manifests, Helm charts, Kustomize overlays, cluster policies, and…

LukasNiessen/kubernetes-skill · 89 tokens

image-to-psd

将一张或多张图片转换为经过严格质量校验的分层 PSD;可独立运行,也可使用 image2editable 的 Host、Local 或本地服务 Agent。输出修复背景、独立透明视觉组件和可编辑 Photoshop 文字图层。仅支持图片输入,不用于 PDF 或 PPTX。.

DSY-Xueai/image2editable · 75 tokens

img2mo-learn

Learn reusable 2D motion-generation knowledge from user-specified action resources with /img2mo-learn . Use when the user provides videos, extracted frame sequences, spritesheets, Spine assets, generated outputs, failed attempts, or reference motion folders and wants to summarize animation timing, pose beats, style…

WU-HAOTIAN34/2dimg2motion · 104 tokens

img2mo-std

Standardize a 2D animation baseline image with /img2mo-std xxx.png/pos. Use when preparing a character, creature, prop, or weapon baseline before motion generation, especially if the source image is too large, tightly cropped, lacks transparent action margin, has a white background, or later walk/attack/idle frames…

WU-HAOTIAN34/2dimg2motion · 87 tokens