code-security-audit
A reusable agent skill published by leonmelamud/claude-code-security-review.
How do I install this agent skill?
npx skills add https://github.com/leonmelamud/claude-code-security-review --skill code-security-auditIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill is an AI-powered security review tool that integrates with GitHub Actions and the Claude Code CLI. It performs automated audits of pull request diffs for vulnerabilities. The analysis found that the skill correctly handles secrets via environment variables and uses trusted APIs (GitHub, Anthropic). It incorporates security measures such as disallowing specific AI tools and using structured output filtering to reduce noise. While it has an attack surface for indirect prompt injection because it processes untrusted code diffs, it includes explicit warnings about this risk and is designed for use on trusted pull requests.
- Socketwarn
2 alerts: gptSecurity
- Snykwarn
Risk: MEDIUM · 2 issues
- Runlayerfail
20/48 files flagged
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/leonmelamud/claude-code-security-review/code-security-audit">View code-security-audit on skillZs</a>