
Secure Code Reviewer
Identify security vulnerabilities in code changes before production deployment
What You Can Do
This skill reviews code changes with security-focused analysis, flagging injection attacks (SQL, command, template), hardcoded secrets, improper error handling, weak cryptography, and access control issues. It provides context-aware risk assessment, severity ratings, and actionable remediation strategies—complementing automated tools with human-level reasoning about business impact and secure coding patterns.
Features
Identifies SQL injection, command injection, template injection, and expression language injection vulnerabilities
Flags hardcoded credentials, unencrypted sensitive data, excessive logging, and PII handling violations
Detects weak algorithms, improper key management, timing attack risks, and unsafe random number generation
Reviews privilege escalation risks, broken access control, session management flaws, and token handling
Catches stack trace leakage, information disclosure through error messages, and improper exception handling
Identifies unsafe deserialization, dynamic code execution, and eval() usage risks
Ranks findings by severity, exploitability, and business impact with clear remediation guidance
Maps issues to OWASP Top 10, CWE, and relevant security standards
Example Output
Example 1: SQL Injection Detection
- ⚠️ HIGH SEVERITY - SQL Injection Risk
Line 42: SELECT * FROM users WHERE id = ' + userId + '
Risk: User input directly concatenated into SQL query
Remediation: Use parameterized queries or prepared statements
Example: connection.query('SELECT * FROM users WHERE id = ?', [userId])
Example 2: Hardcoded Secret Detection
- 🔴 CRITICAL - Exposed Credentials
Line 15: const apiKey = 'sk-1234567890abcdef'
Risk: API key stored in source code, visible in git history
Remediation: Move to environment variables or secrets manager
Example: const apiKey = process.env.API_KEY
Example 3: Weak Cryptography
- ⚠️ MEDIUM SEVERITY - Cryptographic Weakness
Line 87: const hash = md5(password)
Risk: MD5 is cryptographically broken for password hashing
Remediation: Use bcrypt, Argon2, or scrypt for password storage
What's Included
- secure-code-reviewer.md: Core instruction file with threat modeling framework and vulnerability taxonomy
- Security Checklist: OWASP Top 10 mapping and common vulnerability patterns by language
- Risk Assessment Template: Severity scoring matrix and business impact evaluation guide
- Remediation Reference: Secure coding examples for common vulnerabilities (SQL, injection, auth, crypto)
- Code Review Workflow: Step-by-step process for reviewing diffs, PRs, and components
Who It's For
- Security Engineers — Conducting code reviews and vulnerability assessments
- Software Developers — Learning secure coding practices and self-reviewing work
- DevSecOps Engineers — Integrating security checkpoints into CI/CD pipelines
- Technical Leads — Establishing code security standards for teams
- Compliance Officers — Ensuring adherence to security standards (OWASP, CWE, GDPR)
Best For
- Pull request and merge request security reviews before deployment
- Analyzing code changes in authentication, authorization, and data handling
- Evaluating third-party library integrations for security risks
- Security-focused code audits of critical or sensitive components
- Developer training and secure coding pattern education
- Post-incident analysis of reported security vulnerabilities






