security-reviewer-agent

Rank security findings by severity with evidence and remediation guidance.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/harkers/forge-email-server --skill security-reviewer-agent
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-reviewer-agent
Source: https://github.com/harkers/forge-email-server/tree/main/skills/security-reviewer-agent
Command: npx skills add https://github.com/harkers/forge-email-server --skill security-reviewer-agent

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

The Security Reviewer Agent helps teams systematically assess security- and trust-boundary risks that arise from automation, credentials, and exposure.

Core Features & Use Cases

  • review auth/authz assumptions
  • review secret handling
  • review unsafe input/exposure patterns
  • flag missing verification as risk
  • rank issues by severity

Quick Start

Provide a brief automation scenario and let it audit trust boundaries, auth/authz, secrets handling, and input validation.

Frequently Asked Questions about security-reviewer-agent

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review auth and authz assumptions in an automation script?▼

To review auth and authz assumptions, provide the automation scenario to the agent. It audits trust boundaries, evaluates secret handling, and returns severity-ranked findings with remediation guidance for risk-sensitive behavior.

What is the best way to audit secret handling and input validation risks?▼

The best way to audit secret handling and input validation risks is to submit the scenario for a focused review. The agent identifies exposure patterns, untrusted input vulnerabilities, and ranks issues by severity with evidence references.

Can I use this to flag missing verification in production automation workflows?▼

Yes, you can use this to flag missing verification in production automation workflows. The agent assesses approval-sensitive actions and production exposure, returning escalation recommendations for high-risk trust boundary violations.

Does this security review process rank issues by severity and provide remediation?▼

Yes, the security review process ranks issues by severity and provides remediation. It evaluates unsafe automation patterns and credentials, returning severity-ranked findings alongside evidence references and specific remediation guidance.

When do I need a trust boundary assessment for untrusted input handling?▼

You need a trust boundary assessment when your work involves untrusted input, credentials, or production exposure. The agent identifies and ranks security findings related to these risk-sensitive behaviors and unsafe automation patterns.