with one click
security-review
Security analysis checklist aligned with OWASP Top 10
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Security analysis checklist aligned with OWASP Top 10
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
| name | security-review |
| description | Security analysis checklist aligned with OWASP Top 10 |
| argument-hint | <scope-description> |
| user-invocable | true |
| allowed-tools | ["Read","Grep","Glob","Bash"] |
| Severity | Criteria |
|---|---|
| CRITICAL | Remotely exploitable, high impact, no auth required |
| HIGH | Exploitable with moderate effort, significant data exposure |
| MEDIUM | Requires specific conditions, limited impact |
| LOW | Informational, defense in depth improvement |
Demo pipeline state machine — 7-phase autonomous sequence with delegation context templates, phase transition logic, BLOCKED recovery strategies, and demo-state.json schema. Used exclusively by demo-conductor.
Cinematic narration style guide for demo-conductor — ANSI-coloured banner formats, live pipeline scoreboard, audience-facing language, phase summaries, and error narration patterns. Keeps the demo presentation-quality throughout.
Standardized completion and escalation protocol for subagent responses. Ensures the conductor can machine-parse every subagent return. Use when reporting completion status back to the orchestrator.
Cross-session learnings lifecycle — schema, storage, retrieval, and pruning of lessons learned during orchestrator sessions. Use when managing learnings via the /learn command.
Agent Teams assembly and task injection — selects appropriate team, validates prerequisites, estimates cost, injects tasks into the shared task list, and manages team lifecycle.
Token and cost tracking with model tier enforcement