Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✓→✗ | ▼ Worse | 27% | 0% |
| case-05 | ✓→✗ | ▼ Worse | 121% | 0% |
| case-12 | ✓→✗ | ▼ Worse | -56% | 0% |
| case-10 | ✓→✓ | = Same ✓ | 0% | 0% |
| case-04 | ✓→✓ | = Same ✓ | -29% | 0% |
Use this skill after code changes that touch input handling, auth, APIs, data access, uploads, payments, or external integrations.
Use this skill when security is the main question:
Do not use this as the default owner for ordinary maintainability review. If security is only one item in a general PR review, code-reviewer can flag it, but explicit security-audit wording should route here.
security-best-practices for language/framework-specific guidance.code-reviewer for combined correctness + security review.Other measured skills in the registry, with their headline benchmark lift.