code-review-security
OWASP-published review, SCA, secrets and threat-modelling skills — the most citable provenance available for security review vocabulary.
Install
$ /plugin marketplace add OWASP/secure-agent-playbookThen /plugin install code-security-skills@agent-security-playbook (and ai-security-skills@agent-security-playbook for the threat-modelling set).
Best for
Pre-merge security gates mapped to a standard a reviewer can cite, and threat modelling multi-agent systems against the OWASP Multi-Agentic guide and CSA MAESTRO layers.
Not ideal for
Vendoring into a product. The bundle is CC-BY-4.0 — a content licence, not a software licence — so check your obligations before redistributing the rules.
About this skill
Security-focused code review mapped to OWASP Top 10 and ASVS. Use when reviewing pull requests, auditing files or modules for vulnerabilities, or performing pre-merge security gate checks. Covers injection, auth, authorization, cryptography, data exposure, misconfiguration, and deserialization. The same plugin bundle adds sca-audit for dependency CVEs, secrets-scan for credential exposure, and multi-agentic-threat-model for threat modelling multi-agent systems against the CSA MAESTRO framework.
Score breakdown
Score breakdown
rubric 1.0Composite 0–100 score derived from 9 verifiable signals. See the rubric →
Related skills
Security audits run by a real security firm. CodeQL + Semgrep + audit workflows.
Kubernetes hardening by the book. NetworkPolicies, RBAC, OPA, service mesh.
Real exploits, no false positives. 96.15% exploit success across 50+ vuln types.