security-review-codebase
This skill should be used when the user asks to 'security review the codebase', 'audit the codebase for vulnerabilities', 'run a full security audit', 'run a deep, thorough, or hierarchical security review', or 'check the whole project for security issues' — any security review scoped to the entire checked-in codebase (not uncommitted changes, not general code quality). Runs a single-pass audit by default and scales to an optional hierarchical deep mode (per-component sub-reviews plus a cross-component data-flow pass) for large or complex codebases — per-component reviews run as sub-agents where available, sequentially otherwise.
Pinned to revision 13ce57a02c25, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/security-review-codebase/SKILL.md
- skills/security-review-codebase/references/hierarchical-mode.md
Every link opens the file at its source, pinned to the revision this page describes.