원클릭으로
secure-code-review
Repeatable process for an application security code review that produces prioritized findings and fix guidance.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Repeatable process for an application security code review that produces prioritized findings and fix guidance.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Triage a dependency CVE using local repo evidence and remediation guidance.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Review workflow for AI/LLM output usage to prevent over-trust, injection, and unsafe automation.
| name | secure-code-review |
| description | Repeatable process for an application security code review that produces prioritized findings and fix guidance. |
Use this skill when asked to review code for security, produce findings, or prepare guidance for remediation.
If this repo includes prompt files under /prompts, the following are commonly relevant:
secure-code-review.prompt.mdscan-for-insecure-apis.prompt.mdvalidate-input-handling.prompt.mdreview-auth-flows.prompt.md