Skip to main content

security-review-deep

Scanner-grounded security audit, distinct from the built-in /security-review: runs the right scanners (semgrep, osv-scanner, trivy, gitleaks, bandit), queries live CVEs via MCP, walks a 24-category threat-model checklist, and produces a triaged report. Trigger on "deep security review", "full security audit", "check for CVEs", "scan my dependencies", or proactively after changes touching auth, crypto, deserialization, or dependency upgrades. Routine file/network I/O does NOT trigger; offer it in a sentence instead.

Jump to install

Source facts

Repository
charliecpeterson/agent-config
Last source activity
July 18, 2026 at 21:05
Detected SKILL.md language
English
Stars
0
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.