Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review.
.claude/skills/foryourhealth111-pixel-security-reviewer/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✓→✗ | ▼ Worse | 27% | 0% |
| case-05 | ✓→✗ | ▼ Worse | 121% | 0% |
| case-12 | ✓→✗ | ▼ Worse | -56% | 0% |
| case-10 | ✓→✓ | = Same ✓ | 0% | 0% |
| case-04 | ✓→✓ | = Same ✓ | -29% | 0% |
Use this skill after code changes that touch input handling, auth, APIs, data access, uploads, payments, or external integrations.
Use this skill when security is the main question:
Do not use this as the default owner for ordinary maintainability review. If security is only one item in a general PR review, code-reviewer can flag it, but explicit security-audit wording should route here.
security-best-practices for language/framework-specific guidance.code-reviewer for combined correctness + security review.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-10 | pass→pass | 11,563 | 10,223 | -12% | 1 | 1 | 0% | 2,188 | 2,195 | +0% | 0 | 0 | — |
case-01 | fail→fail | 6,883 | 8,044 | +17% | 1 | 1 | 0% | 896 | 1,631 | +82% | 0 | 0 | — |
case-02 | fail→fail | 12,032 | 17,188 | +43% | 1 | 1 | 0% | 1,589 | 2,852 | +79% | 0 | 0 | — |
case-03 | pass→fail | 8,233 | 4,578 | -44% | 1 | 1 | 0% | 944 | 1,201 | +27% | 0 | 0 | — |
case-04 | pass→pass | 8,623 | 4,210 | -51% | 1 | 1 | 0% | 1,411 | 997 | -29% | 0 | 0 | — |
case-11 | pass→pass | 13,440 | 12,255 | -9% | 1 | 1 | 0% | 2,476 | 2,889 | +17% | 0 | 0 | — |
case-05 | pass→fail | 5,889 | 10,291 | +75% | 1 | 1 | 0% | 949 | 2,095 | +121% | 0 | 0 | — |
case-06 | pass→pass | 10,541 | 11,191 | +6% | 1 | 1 | 0% | 1,962 | 2,345 | +20% | 0 | 0 | — |
case-07 | pass→pass | 14,657 | 12,512 | -15% | 1 | 1 | 0% | 2,493 | 2,756 | +11% | 0 | 0 | — |
case-08 | pass→pass | 11,534 | 10,749 | -7% | 1 | 1 | 0% | 1,977 | 2,268 | +15% | 0 | 0 | — |
case-09 | fail→fail | 19,855 | 17,066 | -14% | 1 | 1 | 0% | 3,651 | 3,870 | +6% | 0 | 0 | — |
case-12 | pass→fail | 17,606 | 8,526 | -52% | 1 | 1 | 0% | 3,290 | 1,433 | -56% | 0 | 0 | — |
case-13 | pass→pass | 11,916 | 16,272 | +37% | 1 | 1 | 0% | 1,337 | 2,631 | +97% | 0 | 0 | — |
case-14 | pass→pass | 13,949 | 10,679 | -23% | 1 | 1 | 0% | 2,628 | 2,486 | -5% | 0 | 0 | — |
case-15 | pass→pass | 14,263 | 12,527 | -12% | 1 | 1 | 0% | 1,392 | 2,746 | +97% | 0 | 0 | — |
case-16 | pass→pass | 15,020 | 12,865 | -14% | 1 | 1 | 0% | 2,690 | 2,713 | +1% | 0 | 0 | — |
case-17 | pass→pass | 16,164 | 11,360 | -30% | 1 | 1 | 0% | 2,634 | 2,246 | -15% | 0 | 0 | — |
case-18 | pass→pass | 20,658 | 16,548 | -20% | 1 | 1 | 0% | 3,659 | 3,127 | -15% | 0 | 0 | — |
case-19 | pass→pass | 16,558 | 15,540 | -6% | 1 | 1 | 0% | 2,897 | 3,098 | +7% | 0 | 0 | — |
case-20 | pass→pass | 13,568 | 11,241 | -17% | 1 | 1 | 0% | 2,399 | 2,372 | -1% | 0 | 0 | — |
case-21 | pass→pass | 13,420 | 10,426 | -22% | 1 | 1 | 0% | 2,422 | 2,514 | +4% | 0 | 0 | — |
case-22 | pass→pass | 15,685 | 10,136 | -35% | 1 | 1 | 0% | 3,117 | 2,397 | -23% | 0 | 0 | — |
case-23 | pass→pass | 14,415 | 11,993 | -17% | 1 | 1 | 0% | 2,449 | 2,453 | +0% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of -50 percentage points is the difference between those two pass rates over the 23 comparable cases. 3 cases got worse with the skill loaded, and they are included in that figure.
Other measured skills in the registry, with their headline benchmark lift.