Review Security
SkillMonitoring & opsReview application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. Use for security reviews, threat-focused PR reviews, authentication or authorization changes, input handling, secrets, dependencies, and infrastructure permissions; do not use to exploit live systems or modify code unless separately requested.
Use Review Security in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Review Security and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Review Security skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by hashgraph-online/awesome-codex-plugins in plugins/Phelan164/codex-howto/skills/review-security/SKILL.md and read by ahel’s review.
Workflow
- Establish the review target, intended behavior, and relevant threat model.
- Identify assets, trust boundaries, actors, entry points, and sensitive operations.
- Trace attacker-controlled data to security-relevant sinks.
- Inspect authentication, authorization, tenant isolation, and privilege changes.
- Evaluate realistic exploitability and existing controls.
- Validate suspected findings safely with read-only analysis or sandboxed tests when authorized.
- Return prioritized findings with evidence, impact, prerequisites, and remediation direction.
Guardrails
- Work read-only by default.
- Do not access production systems, real customer data, or private credentials.
- Do not publish weaponized exploit details or active secrets.
- Avoid checklist-only findings without a reachable attack path.
- Distinguish a missing defense-in-depth measure from an exploitable vulnerability.
- Treat dependency scanner output as leads requiring context.
- Keep proof-of-concept activity scoped, reversible, and authorized.
Threat checklist
Read references/threat-checklist.md for changes involving identity, parsers, URLs, files, commands, serialization, secrets, data boundaries, CI, or cloud permissions.
Finding standard
Include:
- severity and confidence;
- affected asset and trust boundary;
- attacker prerequisites;
- source-to-sink or authorization path;
- impact;
- exact code location;
- safe reproduction guidance when appropriate;
- remediation and verification direction.
Acceptance criteria
- Findings describe realistic attack paths.
- Authorization and tenant boundaries are explicitly reviewed.
- Sensitive data handling is traced through logs and storage.
- False positives and assumptions are called out.
- No live exploitation or unauthorized write occurred.
- Residual risk and unreviewed surfaces are explicit.
Signals
- GitHub stars
- 1k
- Forks
- 316
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
review-security-hashgraph-online- Source
- github.com/hashgraph-online/awesome-codex-plugins
github.com/hashgraph-online/awesome-codex-plugins
Related picks
Skill · stbenjam
The pick for Dependenciesauditing-python-dependencies
Skill · jeremylongshore
The pick for Dependenciesgenerate-sandbox-policy
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infrasecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secrets