code-review-security-first

Automate security-first PR reviews with ELIR-aligned checklist outputs.

2|Updated Apr 11, 2025
One-click install
npx skills add https://github.com/abhimehro/personal-config --skill code-review-security-first
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: code-review-security-first
Source: https://github.com/abhimehro/personal-config/tree/main/.cursor/skills/code-review-security-first
Command: npx skills add https://github.com/abhimehro/personal-config --skill code-review-security-first

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Reviews PRs with a security-first mindset across multiple repositories, providing a consistent, auditable checklist-driven process.

Core Features & Use Cases

  • Checklist-driven reviews that surface security risks first and require human verification for AI-assisted changes.
  • ELIR-aligned output ensuring explicit uncertainty and traceability across personal-config, email-security-pipeline, and ctrld-sync PRs.
  • Flexible mode selection with exactly one primary mode (Security, Performance, or Aesthetics) to tailor reviews.

Quick Start

Review a PR with Security as the primary mode and generate an auditable, checklist-driven report.

Frequently Asked Questions about code-review-security-first

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security-first code reviews for pull requests across multiple repositories?▼

Automate security-first code reviews by applying a checklist-driven process to pull requests across multiple codebases. This surfaces security risks first and enforces human verification for AI-assisted or agent-generated changes.

What is the best way to enforce human verification for AI-assisted pull requests?▼

Enforce human verification for AI-assisted pull requests by using a security-first review checklist. It enforces deterministic, templated outputs that require explicit human verification for non-human authored code changes.

How do I generate auditable checklist-driven outputs for pull request reviews?▼

Generate auditable pull request review outputs by capturing findings in a deterministic, templated format. This ELIR-aligned output ensures explicit uncertainty and traceability across your codebases.

Can I select different primary review modes like performance or aesthetics for my pull requests?▼

Yes, you can select exactly one primary review mode, such as Security, Performance, or Aesthetics. This tailors the checklist-driven review process to focus on your specific priority for the pull request.

Why should I use a security-first approach instead of a general code review checklist?▼

A security-first approach prioritizes vulnerability detection before other concerns, ensuring high-risk issues are addressed immediately. It provides consistent, auditable, ELIR-aligned traceability that general checklists lack.

Does the code review checklist work with agent-generated code changes?▼

Yes, the code review checklist is specifically designed for agent-generated code changes. It applies an ELIR-aligned review process that surfaces security concerns first and mandates human verification.