SkillsLib.ai

Secure Code Reviewer

Identify security vulnerabilities in code changes before production deployment

4.6(50 reviews)
500+ downloads
Updated Sep 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

This skill reviews code changes with security-focused analysis, flagging injection attacks (SQL, command, template), hardcoded secrets, improper error handling, weak cryptography, and access control issues. It provides context-aware risk assessment, severity ratings, and actionable remediation strategies—complementing automated tools with human-level reasoning about business impact and secure coding patterns.

Features

Injection Attack Detection

Identifies SQL injection, command injection, template injection, and expression language injection vulnerabilities

Data Exposure Analysis

Flags hardcoded credentials, unencrypted sensitive data, excessive logging, and PII handling violations

Cryptography Review

Detects weak algorithms, improper key management, timing attack risks, and unsafe random number generation

Authentication & Authorization Assessment

Reviews privilege escalation risks, broken access control, session management flaws, and token handling

Error Handling Security

Catches stack trace leakage, information disclosure through error messages, and improper exception handling

Deserialization & Code Execution Analysis

Identifies unsafe deserialization, dynamic code execution, and eval() usage risks

Risk Severity Scoring

Ranks findings by severity, exploitability, and business impact with clear remediation guidance

Compliance & Standard Reference

Maps issues to OWASP Top 10, CWE, and relevant security standards

Example Output

Example 1: SQL Injection Detection

code
- ⚠️ HIGH SEVERITY - SQL Injection Risk
Line 42: SELECT * FROM users WHERE id = ' + userId + '
Risk: User input directly concatenated into SQL query
Remediation: Use parameterized queries or prepared statements
Example: connection.query('SELECT * FROM users WHERE id = ?', [userId])

Example 2: Hardcoded Secret Detection

code
- 🔴 CRITICAL - Exposed Credentials
Line 15: const apiKey = 'sk-1234567890abcdef'
Risk: API key stored in source code, visible in git history
Remediation: Move to environment variables or secrets manager
Example: const apiKey = process.env.API_KEY

Example 3: Weak Cryptography

code
- ⚠️ MEDIUM SEVERITY - Cryptographic Weakness
Line 87: const hash = md5(password)
Risk: MD5 is cryptographically broken for password hashing
Remediation: Use bcrypt, Argon2, or scrypt for password storage

What's Included

  • secure-code-reviewer.md: Core instruction file with threat modeling framework and vulnerability taxonomy
  • Security Checklist: OWASP Top 10 mapping and common vulnerability patterns by language
  • Risk Assessment Template: Severity scoring matrix and business impact evaluation guide
  • Remediation Reference: Secure coding examples for common vulnerabilities (SQL, injection, auth, crypto)
  • Code Review Workflow: Step-by-step process for reviewing diffs, PRs, and components

Who It's For

  • Security Engineers — Conducting code reviews and vulnerability assessments
  • Software Developers — Learning secure coding practices and self-reviewing work
  • DevSecOps Engineers — Integrating security checkpoints into CI/CD pipelines
  • Technical Leads — Establishing code security standards for teams
  • Compliance Officers — Ensuring adherence to security standards (OWASP, CWE, GDPR)

Best For

  • Pull request and merge request security reviews before deployment
  • Analyzing code changes in authentication, authorization, and data handling
  • Evaluating third-party library integrations for security risks
  • Security-focused code audits of critical or sensitive components
  • Developer training and secure coding pattern education
  • Post-incident analysis of reported security vulnerabilities

You might also like

Site Monitoring Compliance & Deviation Auditor
$45
Site Monitoring Compliance & Deviation Auditor

This skill enables you to automatically audit your websites against compliance standards and detect deviations from expected baselines. You can track regulatory requirements, identify policy violations, and generate compliance reports with actionable remediation steps. Monitor multiple sites simultaneously and maintain detailed audit trails for compliance documentation.

Chemical Process Safety Analyzer
$40
Chemical Process Safety Analyzer

Analyze chemical processes systematically to identify hazards, assess risks, and generate safety recommendations. You can perform HAZOP analyses, evaluate compliance with industry standards, conduct root-cause analysis of incidents, and develop emergency response procedures. The skill guides you through structured safety reviews that reduce the likelihood of accidents and regulatory violations.

Injectable Formulation Development & Troubleshooting
$40
Injectable Formulation Development & Troubleshooting

You'll develop systematic approaches to injectable formulation design, from API selection through sterilization strategy. Claude helps you troubleshoot failed batches by analyzing root causes, recommends regulatory pathways (505(b)(2), ANDA, NDA), and provides science-backed solutions for stability, compatibility, and manufacturability challenges.

$50
Integration Architecture Assessor

This skill helps you systematically assess integration needs across your systems, design architecture patterns that scale with your organization, and identify technical and operational risks before implementation. You'll receive architecture recommendations aligned to your business constraints, clear integration roadmaps, and risk mitigation strategies that reduce deployment surprises. Get structured decision records suitable for architecture review boards and engineering teams.

Chemical Process Hazard Analysis and Control Design
$30
Chemical Process Hazard Analysis and Control Design

You can conduct comprehensive hazard analyses for chemical processes using industry-standard methodologies like HAZOP and LOPA. The skill helps you assess risks quantitatively, identify control gaps, design engineered safeguards, and generate formal documentation for regulatory compliance and process safety management.

Git Commit Message Writer
$45
CI/CD4.3(47)
Git Commit Message Writer

Claude analyzes your code diffs and generates standardized commit messages that follow the Conventional Commits specification. The skill automatically determines the correct commit type, scope, and description based on the changes you've made, ensuring your messages are parseable by automation tools while remaining human-readable for code reviewers.

Structured NLP Analysis and Annotation with Claude
$35
NLP3.3(6)
Structured NLP Analysis and Annotation with Claude

You can transform raw text into structured, labeled datasets for machine learning, analysis, and research. This skill performs named entity recognition, sentiment classification, part-of-speech tagging, and dependency parsing—generating consistent, validated annotations at scale. Use it to prepare corpora, extract entities, classify documents, or perform linguistic analysis without manual annotation.

IoT Firmware Analysis & Device Debugger
$40
IoT Firmware Analysis & Device Debugger

Rapidly analyze firmware logs and diagnose hardware issues that cause device failures, connectivity problems, and performance degradation. You'll identify root causes from stack traces, crash dumps, and sensor data, then generate specific optimization recommendations. This skill transforms raw device logs into actionable debugging plans that reduce time-to-resolution from hours to minutes.

$40.00