Review Security

SkillMonitoring & ops

Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. Use for security reviews, threat-focused PR reviews, authentication or authorization changes, input handling, secrets, dependencies, and infrastructure permissions; do not use to exploit live systems or modify code unless separately requested.

Use Review Security in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Review Security and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Review Security skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Review SecurityStart free

What this skill tells your AI

The instructions your AI receives, as published by hashgraph-online/awesome-codex-plugins in plugins/Phelan164/codex-howto/skills/review-security/SKILL.md and read by ahel’s review.

Workflow

  1. Establish the review target, intended behavior, and relevant threat model.
  2. Identify assets, trust boundaries, actors, entry points, and sensitive operations.
  3. Trace attacker-controlled data to security-relevant sinks.
  4. Inspect authentication, authorization, tenant isolation, and privilege changes.
  5. Evaluate realistic exploitability and existing controls.
  6. Validate suspected findings safely with read-only analysis or sandboxed tests when authorized.
  7. Return prioritized findings with evidence, impact, prerequisites, and remediation direction.

Guardrails

  • Work read-only by default.
  • Do not access production systems, real customer data, or private credentials.
  • Do not publish weaponized exploit details or active secrets.
  • Avoid checklist-only findings without a reachable attack path.
  • Distinguish a missing defense-in-depth measure from an exploitable vulnerability.
  • Treat dependency scanner output as leads requiring context.
  • Keep proof-of-concept activity scoped, reversible, and authorized.

Threat checklist

Read references/threat-checklist.md for changes involving identity, parsers, URLs, files, commands, serialization, secrets, data boundaries, CI, or cloud permissions.

Finding standard

Include:

  • severity and confidence;
  • affected asset and trust boundary;
  • attacker prerequisites;
  • source-to-sink or authorization path;
  • impact;
  • exact code location;
  • safe reproduction guidance when appropriate;
  • remediation and verification direction.

Acceptance criteria

  • Findings describe realistic attack paths.
  • Authorization and tenant boundaries are explicitly reviewed.
  • Sensitive data handling is traced through logs and storage.
  • False positives and assumptions are called out.
  • No live exploitation or unauthorized write occurred.
  • Residual risk and unreviewed surfaces are explicit.

Signals

GitHub stars
1k
Forks
316
Last commit
Oct 2026
Advanced
Item type
skill
Key
review-security-hashgraph-online
Source
github.com/hashgraph-online/awesome-codex-plugins