SkillsLib.ai

AppSec Code Review: Vulnerability Assessment

Uncover Hidden Vulnerabilities Through Threat-Driven Code Review

0.0(0 reviews)
100+ downloads
Updated Sep 2026

What You Can Do

You can systematically analyze application code to identify security vulnerabilities using threat-driven patterns based on OWASP standards and industry best practices. The skill evaluates code across multiple attack vectors—authentication, data protection, injection attacks, cryptography, and business logic flaws—producing a prioritized report with severity scores and remediation guidance for each finding.

Features

Threat-driven analysis

Applies OWASP Top 10 and CWE patterns to identify real-world attack vectors in your code

Multi-layer vulnerability detection

Scans for auth bypass, crypto weaknesses, injection flaws, sensitive data exposure, and logic errors in a single pass

Severity classification

Assigns CVSS-style scores and business impact ratings so you prioritize high-risk findings first

Actionable remediation

Provides code examples and step-by-step fixes for each vulnerability, not just flagging problems

False-positive filtering

Uses contextual security analysis to eliminate noise, focusing only on genuine exploitable flaws

Compliance mapping

Links each finding to OWASP, CWE, and PCI-DSS standards for audit trails and policy alignment

Security report generation

Produces a formatted report with executive summary, detailed findings, and remediation roadmap

Custom threat model support

Adapts review to your architecture, tech stack, and business-specific risk profiles

Example Output

Example 1: SQL Injection Vulnerability

Finding: Unparameterized SQL query in authentication endpoint

code
// ❌ Vulnerable
const query = `SELECT * FROM users WHERE email = '${email}'`;

// ✅ Fixed
const query = 'SELECT * FROM users WHERE email = $1';
db.query(query, [email]);

Severity: Critical (CVSS 9.8) | CWE-89 | OWASP A1

Example 2: Weak Cryptography

Finding: MD5 hash used for password storage
Impact: Attacker can crack passwords using precomputed rainbow tables
Fix: Replace with bcrypt or Argon2 with appropriate salt cost
Severity: High (CVSS 7.5)

Example 3: Sensitive Data Exposure

Finding: API response includes unmasked credit card numbers and SSN
Risk: PCI-DSS violation, regulatory fines, customer breach notification
Remediation: Mask PII in API responses; encrypt in transit with TLS 1.3+
Severity: High (CVSS 8.2)

What's Included

  • SKILL.md: Full threat-driven code review framework with decision trees and heuristics
  • OWASP Top 10 Checklist: Structured vulnerability patterns for each category
  • Threat Model Template: Worksheet to define your application's attack surface
  • Vulnerability Scoring Matrix: CVSS calculation and risk prioritization guide
  • Remediation Code Snippets Library: Common fixes for injection, auth, crypto, and data exposure
  • Security Report Template: Executive summary, findings table, remediation roadmap
  • CWE/OWASP/PCI-DSS Cross-Reference: Map findings to compliance frameworks

Who It's For

  • Security engineers conducting code reviews and penetration testing
  • DevOps and platform engineers integrating security into CI/CD pipelines
  • Software architects designing secure systems and threat modeling
  • Compliance officers managing OWASP, PCI-DSS, and SOC 2 requirements
  • Developers performing peer review and security-focused code audits

Best For

  • Pre-deployment security code audits before production releases
  • Vulnerability assessment ahead of compliance reviews and audits
  • Security training and threat-awareness education for development teams
  • Third-party and vendor code evaluation during procurement
  • Legacy code refactoring to meet modern security standards

You might also like

Database Performance Tuning Analyzer
$45
Database Performance Tuning Analyzer

You can systematically diagnose database performance bottlenecks by sharing your schema, slow query logs, and execution plans with Claude. It identifies root causes—missing indexes, inefficient joins, lock contention—and provides prioritized recommendations with ready-to-implement SQL. Skip the manual log analysis and get tuning strategies tailored to your workload.

Database Performance Tuning Analyst
$30
Database Performance Tuning Analyst

Use Claude to systematically analyze your database queries, execution plans, and schema to identify performance bottlenecks. The skill generates actionable optimization recommendations with SQL rewrites, index strategies, and configuration tuning. You'll receive detailed before-and-after performance analysis to validate improvements and prioritize work by impact.

IoT Firmware Analysis & Device Debugger
$40
IoT Firmware Analysis & Device Debugger

Rapidly analyze firmware logs and diagnose hardware issues that cause device failures, connectivity problems, and performance degradation. You'll identify root causes from stack traces, crash dumps, and sensor data, then generate specific optimization recommendations. This skill transforms raw device logs into actionable debugging plans that reduce time-to-resolution from hours to minutes.

Injectable Formulation Development & Troubleshooting
$40
Injectable Formulation Development & Troubleshooting

You'll develop systematic approaches to injectable formulation design, from API selection through sterilization strategy. Claude helps you troubleshoot failed batches by analyzing root causes, recommends regulatory pathways (505(b)(2), ANDA, NDA), and provides science-backed solutions for stability, compatibility, and manufacturability challenges.

Mobile Feature Architecture & Implementation
$40
Mobile Feature Architecture & Implementation

You'll design and implement mobile features with architectural rigor, cross-platform considerations, and edge-case handling built-in. This skill generates complete system designs, platform-specific implementation strategies, performance optimization approaches, and testing frameworks. The output is production-ready guidance spanning iOS and Android with security, offline resilience, and deployment strategies included.

Git Commit Message Writer
$45
CI/CD4.3(47)
Git Commit Message Writer

Claude analyzes your code diffs and generates standardized commit messages that follow the Conventional Commits specification. The skill automatically determines the correct commit type, scope, and description based on the changes you've made, ensuring your messages are parseable by automation tools while remaining human-readable for code reviewers.

Structured NLP Analysis and Annotation with Claude
$35
NLP3.3(6)
Structured NLP Analysis and Annotation with Claude

You can transform raw text into structured, labeled datasets for machine learning, analysis, and research. This skill performs named entity recognition, sentiment classification, part-of-speech tagging, and dependency parsing—generating consistent, validated annotations at scale. Use it to prepare corpora, extract entities, classify documents, or perform linguistic analysis without manual annotation.

ROS Control Architecture & Debugging
$30
ROS Control Architecture & Debugging

You can architect multi-node ROS control systems from scratch, including node design patterns, communication flows, and real-time constraints. You'll debug complex node interactions using publisher/subscriber analysis, service call tracing, and action server diagnostics. You can optimize motion controllers through PID tuning, trajectory planning validation, and performance profiling to achieve precise, responsive robotic behavior.

$40.00