원클릭으로
security-review
Review a domain, file, or the full repository for OWASP-oriented security issues using the shared security checklist.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Review a domain, file, or the full repository for OWASP-oriented security issues using the shared security checklist.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | security-review |
| description | Review a domain, file, or the full repository for OWASP-oriented security issues using the shared security checklist. |
| metadata | {"short-description":"OWASP security audit"} |
self-review (security-sensitive surfaces: auth, tokens, sensitive fields, file upload, credentials)/sync-guidelines if drift; otherwise /review-pr)/security-review recursively, do not invoke /plan-feature from insideAGENTS.md and docs/ai/shared/skills/security-review.md for the full procedure.docs/ai/shared/security-checklist.md and docs/ai/shared/project-dna.md as the shared security rule sources.Drift Candidates, and whether Sync Required is true or false (Phase 2).Scope, Effect Answer, Sources Loaded, Findings (open only), Coverage (OK/SKIP), Drift Candidates, Verdict: N/A (audit-only scope), Next Actions, Completion State, Sync Required (Phase 3). Effect Answer is mandatory — see docs/ai/shared/review-protocol.md §3 for the contract and Guard H context.For cross-tool review prompts, use the Cross-Tool Review Prompt Template
section in docs/ai/shared/skills/security-review.md; do not duplicate it here.
Inspect drift between code, shared workflow references, and Claude, Codex, or Antigravity harness assets after architecture or workflow changes.
This skill should be used when the user asks to "sync guidelines", "document inspection", "check skill updates", "update project-dna", "sync patterns", "verify code-document consistency", or after architecture changes to verify Skills/AGENTS.md/CLAUDE.md match the actual code.
Guide a feature from requirements interview through architecture analysis, security check, and task decomposition.
This skill should be used when the user asks to "plan feature", "design feature", or wants to plan and design a new feature before implementation.
Audit a domain or the full repository for architecture compliance using the shared architecture checklist and repository rules.
Review a pull request or local diff against the repository's shared Review Protocol (correctness, regression, stability, contract, architecture, security, governance).