/security-review
Comprehensive security code review workflow for a target repository, producing a markdown report with findings and recommendations.
$ npx -y skills add cosai-oasis/project-codeguard --skill security-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/security-review
Context preview
The summary Claude sees to decide when to auto-load this skill.
Comprehensive security code review workflow for a target repository, producing a markdown report with findings and recommendations.
SKILL.md
security-review.SKILL.mdname: security-review
description: Comprehensive security code review workflow for a target repository, producing a markdown report with findings and recommendations.
metadata:
short-description: Security code review report
framework: Project CodeGuard
codeguard-source: https://github.com/cosai-oasis/project-codeguard
Security Review
When to use
- Use for a full codebase security review with prioritized findings,
remediation guidance, and a formal report.
Inputs
- Target repository path (first argument after invocation).
- Example: `$security-review /path/to/repo`
- Security knowledge base source:
- Rules are sourced from [Project CodeGuard](https://github.com/cosai-oasis/project-codeguard),
an open-source, model-agnostic security framework by CoSAI/OASIS.
If the repo path is missing or unclear, ask the user for it before proceeding.
Workflow
1. Load the security knowledge base from Project CodeGuard
- First read the `Security_Code_Reviewer_Guidelines.md` file bundled with
this skill. Use its purpose and rule-loading strategy to guide the review.
- Load all core security rules from Project CodeGuard:
https://github.com/cosai-oasis/project-codeguard/tree/main/sources/rules/core
These are mandatory foundational rules that must be loaded for every review.
- Load relevant OWASP rules for the detected tech stack from:
https://github.com/cosai-oasis/project-codeguard/tree/main/sources/rules/owasp
Only load OWASP rules that match the target repository's technology stack.
2. Perform deep code analysis
- Review the repository line by line.
- Focus on: injection flaws, authn/authz, hardcoded secrets, crypto misuse,
SSRF, path traversal, RCE vectors, XSS/CSRF, unsafe deserialization, insecure defaults/configuration, and supply chain issues. 3. Produce the report in markdown.
Report requirements
- Executive Summary
- Total findings by severity (Critical/High/Medium/Low/Info)
- Top 5 most critical issues
- Overall security posture
- Detailed Findings (for each issue)
- Title, Severity, Rule Reference(s), Location, Code Snippet
- Description, Impact, Remediation (with examples), References
- Findings by Category
- Recommendations
- Immediate actions, short-term (1-3 months), long-term improvements,
tooling/process suggestions
- Appendix
- Files reviewed, rules applied/coverage, methodology notes
Output
- Save the report to:
- `./security_report/sec_review_<repo-name>_<YYYY-MM-DD_HH-mm-ss>.md`
- Use the target repo folder name for `<repo-name>` and replace spaces
with `-`.
- Write to the `security_report` folder in the current working directory.
Read more
name: security-review description: Comprehensive security code review workflow for a target repository, producing a markdown report with findings and recommendations. metadata: short-description: Security code review report framework: Project CodeGuard codeguard-source: https://github.com/cosai-oasis/project-codeguard
Security Review
When to use
- Use for a full codebase security review with prioritized findings,
remediation guidance, and a formal report.
Inputs
- Target repository path (first argument after invocation).
- Example: `$security-review /path/to/repo`
- Security knowledge base source:
- Rules are sourced from [Project CodeGuard](https://github.com/cosai-oasis/project-codeguard),
an open-source, model-agnostic security framework by CoSAI/OASIS.
If the repo path is missing or unclear, ask the user for it before proceeding.
Workflow
1. Load the security knowledge base from Project CodeGuard
- First read the `Security_Code_Reviewer_Guidelines.md` file bundled with
this skill. Use its purpose and rule-loading strategy to guide the review.
- Load all core security rules from Project CodeGuard:
https://github.com/cosai-oasis/project-codeguard/tree/main/sources/rules/core
These are mandatory foundational rules that must be loaded for every review.
- Load relevant OWASP rules for the detected tech stack from:
https://github.com/cosai-oasis/project-codeguard/tree/main/sources/rules/owasp
Only load OWASP rules that match the target repository's technology stack.
2. Perform deep code analysis
- Review the repository line by line.
- Focus on: injection flaws, authn/authz, hardcoded secrets, crypto misuse,
SSRF, path traversal, RCE vectors, XSS/CSRF, unsafe deserialization, insecure defaults/configuration, and supply chain issues. 3. Produce the report in markdown.
Report requirements
- Executive Summary
- Total findings by severity (Critical/High/Medium/Low/Info)
- Top 5 most critical issues
- Overall security posture
- Detailed Findings (for each issue)
- Title, Severity, Rule Reference(s), Location, Code Snippet
- Description, Impact, Remediation (with examples), References
- Findings by Category
- Recommendations
- Immediate actions, short-term (1-3 months), long-term improvements,
tooling/process suggestions
- Appendix
- Files reviewed, rules applied/coverage, methodology notes
Output
- Save the report to:
- `./security_report/sec_review_<repo-name>_<YYYY-MM-DD_HH-mm-ss>.md`
- Use the target repo folder name for `<repo-name>` and replace spaces
with `-`.
- Write to the `security_report` folder in the current working directory.
This repository is for the work of the Coalition for Secure AI (CoSAI). CoSAI is an OASIS Open Project and an open ecosystem of AI and security experts from industry-leading organizations.
Other skills on cosai-oasis-codeguard-security.
- /codeguard
A CodeGuard security skill that helps AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.
Open skill - /memory-safe-migration
Guide secure migration of code from memory-unsafe languages (C, C++, Assembly) to memory-safe languages (Rust, Go, Java, C#, Swift). Use when migrating or rewriting legacy C/C++ code, designing FFI boundaries between safe and unsafe code, writing new modules in existing C/C++
Open skill

