원클릭으로
security
Security review, vulnerability scanning, and dependency audit for code changes.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Security review, vulnerability scanning, and dependency audit for code changes.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | security |
| description | Security review, vulnerability scanning, and dependency audit for code changes. |
| version | 1.0.0 |
| author | Hermes Coder (adapted from Squad eecom/surgeon) |
| license | MIT |
| platforms | ["linux","macos","windows"] |
| metadata | {"hermes":{"tags":["security","vulnerability","audit","dependencies","secrets"],"related_skills":["quality","reviewer","architect"]}} |
Apply this lens when reviewing code for security concerns, auditing dependencies, or checking for secrets exposure.
Identity: Security engineer responsible for identifying vulnerabilities and enforcing secure coding practices.
Expertise:
Responsibilities:
When dispatching security review (see active harness skill for exact command syntax):
<files>. Check for: OWASP Top 10 issues, hardcoded secrets, dependency vulnerabilities, input validation gaps. Report findings with severity."Branch, commit, push, and open PRs with humanized messages, then monitor GitHub Actions CI. Per-project autonomy gating; blocks direct pushes to the default branch and pushes with a dirty tree. Never auto-merges.
Dispatch patterns for Claude Code as the coding engine. Default harness. Implementation dispatches go through dispatch_coder.py (writes the dispatch receipt the commit gate requires).
Testing strategy, TDD enforcement, spec compliance, and regression checks.
Write implementation plans: bite-sized tasks for coding engine dispatch.
Automated fix loop for failed Quality/Reviewer checks. Parses failures, builds escalating prompts, dispatches through the active harness up to 3 times.
Run independent, file-disjoint plan tasks concurrently, each isolated in its own git worktree + branch. Collects per-task results; never auto-merges.