SkillsLib.ai

AppSec Code Review: Vulnerability Assessment

Uncover Hidden Vulnerabilities Through Threat-Driven Code Review

0.0(0 reviews)
100+ downloads
Updated Oct 2026

What You Can Do

You can systematically analyze application code to identify security vulnerabilities using threat-driven patterns based on OWASP standards and industry best practices. The skill evaluates code across multiple attack vectors—authentication, data protection, injection attacks, cryptography, and business logic flaws—producing a prioritized report with severity scores and remediation guidance for each finding.

Features

Threat-driven analysis

Applies OWASP Top 10 and CWE patterns to identify real-world attack vectors in your code

Multi-layer vulnerability detection

Scans for auth bypass, crypto weaknesses, injection flaws, sensitive data exposure, and logic errors in a single pass

Severity classification

Assigns CVSS-style scores and business impact ratings so you prioritize high-risk findings first

Actionable remediation

Provides code examples and step-by-step fixes for each vulnerability, not just flagging problems

False-positive filtering

Uses contextual security analysis to eliminate noise, focusing only on genuine exploitable flaws

Compliance mapping

Links each finding to OWASP, CWE, and PCI-DSS standards for audit trails and policy alignment

Security report generation

Produces a formatted report with executive summary, detailed findings, and remediation roadmap

Custom threat model support

Adapts review to your architecture, tech stack, and business-specific risk profiles

Example Output

Example 1: SQL Injection Vulnerability

Finding: Unparameterized SQL query in authentication endpoint

code
// ❌ Vulnerable
const query = `SELECT * FROM users WHERE email = '${email}'`;

// ✅ Fixed
const query = 'SELECT * FROM users WHERE email = $1';
db.query(query, [email]);

Severity: Critical (CVSS 9.8) | CWE-89 | OWASP A1

Example 2: Weak Cryptography

Finding: MD5 hash used for password storage
Impact: Attacker can crack passwords using precomputed rainbow tables
Fix: Replace with bcrypt or Argon2 with appropriate salt cost
Severity: High (CVSS 7.5)

Example 3: Sensitive Data Exposure

Finding: API response includes unmasked credit card numbers and SSN
Risk: PCI-DSS violation, regulatory fines, customer breach notification
Remediation: Mask PII in API responses; encrypt in transit with TLS 1.3+
Severity: High (CVSS 8.2)

What's Included

  • SKILL.md: Full threat-driven code review framework with decision trees and heuristics
  • OWASP Top 10 Checklist: Structured vulnerability patterns for each category
  • Threat Model Template: Worksheet to define your application's attack surface
  • Vulnerability Scoring Matrix: CVSS calculation and risk prioritization guide
  • Remediation Code Snippets Library: Common fixes for injection, auth, crypto, and data exposure
  • Security Report Template: Executive summary, findings table, remediation roadmap
  • CWE/OWASP/PCI-DSS Cross-Reference: Map findings to compliance frameworks

Who It's For

  • Security engineers conducting code reviews and penetration testing
  • DevOps and platform engineers integrating security into CI/CD pipelines
  • Software architects designing secure systems and threat modeling
  • Compliance officers managing OWASP, PCI-DSS, and SOC 2 requirements
  • Developers performing peer review and security-focused code audits

Best For

  • Pre-deployment security code audits before production releases
  • Vulnerability assessment ahead of compliance reviews and audits
  • Security training and threat-awareness education for development teams
  • Third-party and vendor code evaluation during procurement
  • Legacy code refactoring to meet modern security standards

You might also like

Smart Contract Security Analysis & Code Review
$20
Smart Contract Security Analysis & Code Review

Analyze Solidity and other smart contract code for security vulnerabilities, gas inefficiencies, and best practice violations. Get detailed reports with risk scoring, remediation suggestions, and optimization recommendations. Whether you're auditing before deployment or reviewing third-party contracts, this skill identifies critical issues faster than manual review.

Database Performance Tuning Analyzer
$45
Database Performance Tuning Analyzer

You can systematically diagnose database performance bottlenecks by sharing your schema, slow query logs, and execution plans with Claude. It identifies root causes—missing indexes, inefficient joins, lock contention—and provides prioritized recommendations with ready-to-implement SQL. Skip the manual log analysis and get tuning strategies tailored to your workload.

Process Optimization & Troubleshooting
$30
Process Optimization & Troubleshooting

This skill provides a structured approach to analyzing process problems, identifying root causes, and recommending capacity optimizations. You'll get clear bottleneck identification, data-driven recommendations, and a framework to validate whether your solutions actually work. Perfect for diagnosing why workflows are slow and finding the leverage points that matter most.

Database Performance Tuning Analyst
$30
Database Performance Tuning Analyst

Use Claude to systematically analyze your database queries, execution plans, and schema to identify performance bottlenecks. The skill generates actionable optimization recommendations with SQL rewrites, index strategies, and configuration tuning. You'll receive detailed before-and-after performance analysis to validate improvements and prioritize work by impact.

Mobile Feature Architecture & Implementation
$40
Mobile Feature Architecture & Implementation

You'll design and implement mobile features with architectural rigor, cross-platform considerations, and edge-case handling built-in. This skill generates complete system designs, platform-specific implementation strategies, performance optimization approaches, and testing frameworks. The output is production-ready guidance spanning iOS and Android with security, offline resilience, and deployment strategies included.

Injectable Formulation Development Assistant
$40
Injectable Formulation Development Assistant

Design and optimize injectable formulations by analyzing your active pharmaceutical ingredient (API), selecting compatible excipients, and predicting stability outcomes. You'll receive systematic workflows that guide you through API characterization, formulation architecture, and risk mitigation—enabling faster development cycles and regulatory-ready documentation.

Injectable Formulation Development & Troubleshooting
$40
Injectable Formulation Development & Troubleshooting

You'll develop systematic approaches to injectable formulation design, from API selection through sterilization strategy. Claude helps you troubleshoot failed batches by analyzing root causes, recommends regulatory pathways (505(b)(2), ANDA, NDA), and provides science-backed solutions for stability, compatibility, and manufacturability challenges.

ROS Control Architecture & Debugging
$30
ROS Control Architecture & Debugging

You can architect multi-node ROS control systems from scratch, including node design patterns, communication flows, and real-time constraints. You'll debug complex node interactions using publisher/subscriber analysis, service call tracing, and action server diagnostics. You can optimize motion controllers through PID tuning, trajectory planning validation, and performance profiling to achieve precise, responsive robotic behavior.

$40.00