Security Review Skill

SkillSecurity

Security review via Codex MCP. Use when: OWASP Top 10 audit, dependency vulnerability check, security-sensitive changes. Not for: code review (use codex-code-review), test review (use test-review). Output: security findings + audit report.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Security Review Skill skill

What this skill tells your AI

The instructions your AI receives, as published by sd0xdev/sd0x-harness in skills/security-review/SKILL.md and read by ahel’s review.

Trigger

  • Keywords: security review, OWASP, vulnerability, dep-audit, npm audit, dependency security

When NOT to Use

  • General code review (use codex-code-review)
  • Functional testing (use test-review)
  • Performance issues (not security-related)

Commands

CommandPurposeWhen
/codex-securityOWASP Top 10 auditSecurity-sensitive code
/dep-auditDependency security auditPeriodic / PR

Workflow: /codex-security

Determine scope → Collect changes → Codex OWASP review → Findings + Gate → Loop if Must fix

Step 1: Determine Scope

Parse --scope from arguments, default to src/.

Step 2: Collect Change Metadata

Metadata, not content: the first dispatch carries the changed-file list and diff stats, and Codex reads the diffs itself from the sandbox (@rules/codex-invocation.md § Required in every first-dispatch prompt). A truncated | head -1500 excerpt was the old shape, and it decided for the reviewer which 1500 lines of a security review mattered.

  1. CHANGED_FILES: git diff --name-only HEAD -- <scope>git ls-files --others --exclude-standard -- <scope>
  2. DIFF_STAT: git diff --stat HEAD -- <scope>
  3. SCOPE: the resolved scope argument, plus the security-relevant paths a Glob("**/*{auth,login,password,token,secret,key,credential}*") surfaces — named as places to look, never pasted

Step 3: Codex Security Review

First review: dispatch per @skills/codex-code-review/references/codex-transport.md § Start with the OWASP prompt. See references/codex-prompt-security.md.

Save the returned threadId.

Loop review: dispatch per @skills/codex-code-review/references/codex-transport.md § Resume with the re-review template. See references/codex-prompt-security.md.

Step 4: Consolidate Output

Organize results into findings summary table + detailed findings + gate.

OWASP Top 10:2025

The version is part of the identifier: SSRF is no longer A10 (it sits inside A01), and A02–A06 renumbered, so a finding labelled with a 2021 code says something different to whoever reads it.

CodeCategoryCheck Focus
A01Broken Access CtrlIDOR, permission bypass, CORS, SSRF
A02MisconfigurationDebug mode, default passwords
A03Supply Chain FailuresVulnerable deps, unverified build sources
A04Crypto FailuresSensitive data encryption, weak crypto
A05InjectionSQL/NoSQL/Cmd Injection, XSS
A06Insecure DesignRate Limiting, business logic
A07Auth FailuresBrute force, session, weak passwords
A08Integrity FailuresDeserialization, CI/CD
A09Logging & AlertingSensitive data in logs, auditing, alerts
A10Exceptional ConditionsError paths that fail open or leak

Review Loop

⚠️ @CLAUDE.md auto-loop: fix → re-review → ... → ✅ PASS ⚠️

⛔ Must fix → fix P0 issues → /codex-security --continue <threadId> → repeat until ✅ Mergeable.

Max 3 rounds. Still failing → report blocker.

Verification

  • Each issue tagged with severity (P0/P1/P2)
  • Gate is explicit (✅ Mergeable / ⛔ Must fix)
  • Fix recommendations are specific and actionable
  • Includes verification test method
  • Codex independently researched auth/input/sensitive code

References

  • OWASP prompt: references/codex-prompt-security.md
  • Examples: references/examples.md
  • Standards: @rules/security.md

Examples

Input: /codex-security --scope src/controller/
Action: OWASP Top 10 check → output issues + Gate

Input: /dep-audit --level high
Action: npm audit → filter high/critical → output report

Signals

GitHub stars
188
Forks
24
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
security-review-sd0xdev
Source
github.com/sd0xdev/sd0x-harness