commit
Create well-structured git commits from the current working tree. Use when the user says 'commit', 'save my work', 'let's commit this', 'make a commit', or any…
Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
$ npx -y skills add kklimuk/docx-cli --skill security-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-reviewContext preview
The summary Claude sees to decide when to auto-load this skill.
Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
name: security-review description: "Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment." context: fork agent: general-purpose allowed-tools: Read Grep Glob Bash(git diff:*) Bash(git log:*) Bash(git status:*) Bash(git show:*) WebFetch metadata: internal: true
Audit changed files for security vulnerabilities, focusing on the OWASP Top 10 and issues specific to the project's stack.
When running locally as a forked subagent, the main session does not see any files you read or any reasoning you do — only the final report you return. When running in CI (e.g. via `claude-code-action`), the workflow takes the report and turns it into GitHub PR review comments. Either way, take your time, read every changed file completely, and produce a thorough, actionable report. The consumer of this report uses it as a worklist, so it must be complete and self-contained.
Determine the diff to review:
1. Run `git diff main...HEAD --name-only` to get files changed on this branch vs main. 2. If that fails (no `main`, detached worktree, etc.), fall back to `git diff HEAD --name-only` for uncommitted changes, then `git diff --cached --name-only` for staged files. 3. If no diff is available, ask the user which files to review.
Read every changed file completely before starting the review. Read CLAUDE.md first to understand the project's stack and any subsystems with security-sensitive surface area (auth, real-time, payments, file uploads).
(Only relevant if the project has a WebSocket layer — see CLAUDE.md.)
Return the **complete formatted report** as your final message — not a summary or TL;DR. Whatever consumes the report (a main Claude session locally, or a CI workflow that posts inline GitHub PR comments) uses it as a worklist, so it must be self-contained.
Organize findings by severity:
Exploitable now with no authentication required. Data loss, unauthorized access, or remote code execution.
Exploitable with some preconditions (e.g., needs authenticated user, specific timing). Privilege escalation, significant data leakage.
Defense-in-depth issues. Missing validation that's currently protected by another layer but shouldn't rely on it.
Hardening recommendations. Not exploitable today but reduce attack surface.
For each finding, include enough detail that the consumer can apply the fix without re-reading the entire file:
1. **File and line** — exact `path:line` (or `path:start-end` for ranges); list every site for cross-file findings 2. **Severity** — Critical / High / Medium / Low 3. **Vulnerability type** — OWASP category or CWE 4. **Current code** — short snippet of the vulnerable code (not just a description) 5. **Exploit scenario** — concrete steps showing how an attacker would use this 6. **Fix** — specific code change, ideally as a before/after snippet 7. **Surrounding context**
A .docx CLI built for AI agents. Leave comments, suggest redlines, and edit Word documents without breaking the formatting or losing content — a human accepts or rejects in Word afterward.
Repo: kklimuk/docx-cli
Create well-structured git commits from the current working tree. Use when the user says 'commit', 'save my work', 'let's commit this', 'make a commit', or any…
Run the weak-agent adversarial test harness against docx-cli. Spawns weak exercise agents (Haiku by default, Sonnet to probe, or a local agent harness's…