security-reviewer

Scans code and systems for vulnerabilities and generates risk reports.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/Timmy6942025/bob-workspace --skill security-reviewer-timmy6942025
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-reviewer
Source: https://github.com/Timmy6942025/bob-workspace/tree/main/skills/pentest
Command: npx skills add https://github.com/Timmy6942025/bob-workspace --skill security-reviewer-timmy6942025

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams identify weaknesses during code reviews, SAST analyses, and DevSecOps workflows, reducing risk and enhancing compliance.

Core Features & Use Cases

  • Automated vulnerability detection through SAST, secret scanning, and dependency checks across applications and infrastructure.
  • Manual threat analysis and remediation guidance to prioritize fixes and verify improvements.
  • Use Case: Apply to a multi-repo project to produce a consolidated security report with prioritized remediation across services.

Quick Start

Run a security review on your repository by pointing the skill at the target codebase and generating a unified risk report.

Frequently Asked Questions about security-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit code and infrastructure for vulnerabilities across a multi-repo project?▼

To audit code and infrastructure for vulnerabilities across a multi-repo project, point the skill at the target codebase to generate a unified risk report with prioritized remediation across services.

What is the best way to integrate SAST scans and secret scanning into DevSecOps workflows?▼

Integrating SAST scans and secret scanning into DevSecOps workflows involves applying automated vulnerability detection across applications and infrastructure to identify weaknesses during code reviews.

How does manual threat analysis verify automated SAST scan results?▼

Manual threat analysis verifies automated SAST scan results by applying manual verification to validate findings, prioritize fixes, and provide structured reporting with remediation guidance.

Can I use this security review process for both cloud security and infrastructure security?▼

Yes, you can use this security review process for cloud security and infrastructure security, as it applies automated scans and manual threat analysis across software projects and infrastructure.

Does penetration testing require dependency checks to produce remediation guidance?▼

Penetration testing and remediation guidance benefit from dependency checks, as the skill enforces scope, automated scans, and manual verification to produce structured reporting for security reviews.