Skip to content
Automation
Skill

/security-review

Security vulnerability assessment identifying OWASP risks, injection vectors, authentication issues, and data exposure with severity classification.

From plugin
babysitter
1.8k200 skills3 agents21 commands1 MCP
Install
$ npx -y skills add a5c-ai/babysitter --skill security-review --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/security-review

Context preview

The summary Claude sees to decide when to auto-load this skill.

Security vulnerability assessment identifying OWASP risks, injection vectors, authentication issues, and data exposure with severity classification.

SKILL.md

security-review.SKILL.md
name: security-review
description: Security vulnerability assessment identifying OWASP risks, injection vectors, authentication issues, and data exposure with severity classification.
allowed-tools: Read, Bash, Grep, Glob, Agent, AskUserQuestion
graph:
  domains: [domain:software-engineering]
  skillAreas: [skill-area:agentic-loops, skill-area:orchestration-loop]
  workflows: [workflow:feature-development]
  topics: [topic:developer-experience]
  roles: [role:tech-lead, role:backend-engineer]
  • Before any code merge involving user-facing changes
  • As part of the /review-security command
  • Mandatory for high-stakes implementations

Process

1. Identify modified files with security relevance 2. Scan for common vulnerability patterns 3. Assess authentication and authorization changes 4. Check for data exposure risks 5. Evaluate dependency security 6. Classify severity and provide recommendations

Severity Levels

  • **Critical**: Immediate exploitation risk
  • **High**: Significant vulnerability requiring fix before merge
  • **Medium**: Vulnerability that should be addressed soon
  • **Low**: Minor security improvement opportunity

Key Rules

  • Security review failure halts implementation
  • All findings must include file paths and line numbers
  • Provide actionable remediation steps
  • Reference OWASP categories where applicable

Tool Use

Invoke via babysitter process: `methodologies/rpikit/rpikit-review`

Read more
Ships withbabysitter

Enforce obedience on agentic workforces. Manage extremely complex workflows through deterministic, hallucination-free self-orchestration.

Get the whole plugin

Other skills on babysitter.