Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Configure CodeRabbit for security-focused code review with secret detection and vulnerability scanning. Use when setting up security review rules, configuring secret detection in PRs, or hardening CodeRabbit configuration for compliance requirements. Trigger with phrases like "coderabbit security", "coderabbit secrets", "secure coderabbit", "coderabbit vulnerability detection", "coderabbit security review".
.claude/skills/jeremylongshore-coderabbit-security-basics/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 31% | 0% |
| case-21 | ✗→✓ | ▲ Improved | 61% | 0% |
| case-22 | ✗→✓ | ▲ Improved | 71% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 91% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 31% | 0% |
Use documented CodeRabbit Security and tools while retaining independent scanners and human review. AI findings cannot prove absence of vulnerabilities.
references/official-docs.md and re-check any time-sensitive contract before execution.Treat Git-provider sessions, CodeRabbit web sessions, CLI credentials, and CodeRabbit API keys as separate credentials. Use only an already-approved session or secret-manager reference, never print a secret, and do not place credentials in .coderabbit.yaml, source files, logs, or deliverables.
Require security approval before disabling tools, excluding sensitive paths, or accepting high-risk findings. Keep analysis and drafts local until approval is explicit, and record who approved the action and its scope.
A threat-control matrix, patch, independent-gate inventory, fixture evidence, gaps, and escalation. Include source dates, unknowns, and the exact boundary between observed fact and recommendation.
| Condition | Response | |---|---| | Current contract is unclear or docs disagree | Stop mutation, cite both sources, and request owner resolution. | | Required access or approval is missing | Produce a draft and evidence plan only. | | Validation or pilot behavior differs from expectation | Restore the prior state and retain the failed evidence. | | Output contains secrets or private code | Stop, quarantine the artifact, redact it, and notify the data owner. |
Enable secret and IaC tools while keeping provider scanning.
Test SkillSpector with a synthetic unsafe MCP fixture.
references/official-docs.md.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-06 | pass→pass | 11,651 | 8,482 | -27% | 1 | 1 | 0% | 2,103 | 4,015 | +91% | 0 | 0 | — |
case-01 | fail→pass | 18,845 | 11,593 | -38% | 1 | 1 | 0% | 3,716 | 4,885 | +31% | 0 | 0 | — |
case-07 | fail→fail | 9,146 | 7,049 | -23% | 1 | 1 | 0% | 1,591 | 3,600 | +126% | 0 | 0 | — |
case-02 | pass→pass | 19,031 | 13,179 | -31% | 1 | 1 | 0% | 4,012 | 5,256 | +31% | 0 | 0 | — |
case-03 | pass→pass | 16,889 | 10,737 | -36% | 1 | 1 | 0% | 3,390 | 4,516 | +33% | 0 | 0 | — |
case-04 | pass→pass | 10,216 | 7,639 | -25% | 1 | 1 | 0% | 1,852 | 3,979 | +115% | 0 | 0 | — |
case-05 | pass→pass | 15,599 | 14,868 | -5% | 1 | 1 | 0% | 2,898 | 5,365 | +85% | 0 | 0 | — |
case-08 | fail→fail | 12,697 | 6,515 | -49% | 1 | 1 | 0% | 2,389 | 3,629 | +52% | 0 | 0 | — |
case-09 | pass→pass | 8,323 | 4,178 | -50% | 1 | 1 | 0% | 1,528 | 3,281 | +115% | 0 | 0 | — |
case-10 | pass→pass | 8,649 | 7,125 | -18% | 1 | 1 | 0% | 1,468 | 3,689 | +151% | 0 | 0 | — |
case-11 | pass→pass | 12,933 | 5,836 | -55% | 1 | 1 | 0% | 2,289 | 3,444 | +50% | 0 | 0 | — |
case-12 | pass→pass | 12,772 | 12,866 | +1% | 1 | 1 | 0% | 2,530 | 4,995 | +97% | 0 | 0 | — |
case-13 | pass→pass | 11,873 | 7,317 | -38% | 1 | 1 | 0% | 2,315 | 3,751 | +62% | 0 | 0 | — |
case-14 | pass→pass | 7,190 | 3,768 | -48% | 1 | 1 | 0% | 1,175 | 2,850 | +143% | 0 | 0 | — |
case-15 | pass→pass | 12,675 | 7,362 | -42% | 1 | 1 | 0% | 2,358 | 3,857 | +64% | 0 | 0 | — |
case-16 | pass→pass | 11,276 | 8,834 | -22% | 1 | 1 | 0% | 1,724 | 3,758 | +118% | 0 | 0 | — |
case-21 | fail→pass | 14,923 | 10,576 | -29% | 1 | 1 | 0% | 2,713 | 4,360 | +61% | 0 | 0 | — |
case-17 | pass→pass | 12,168 | 11,838 | -3% | 1 | 1 | 0% | 2,253 | 4,481 | +99% | 0 | 0 | — |
case-18 | pass→pass | 9,673 | 4,471 | -54% | 1 | 1 | 0% | 1,567 | 3,302 | +111% | 0 | 0 | — |
case-19 | pass→pass | 8,611 | 4,139 | -52% | 1 | 1 | 0% | 1,624 | 3,349 | +106% | 0 | 0 | — |
case-20 | pass→pass | 5,304 | 5,946 | +12% | 1 | 1 | 0% | 992 | 2,948 | +197% | 0 | 0 | — |
case-22 | fail→pass | 8,172 | 3,536 | -57% | 1 | 1 | 0% | 1,547 | 2,651 | +71% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.