secrets-reviewer¶
Use this agent for a deeper semantic security review of a code diff AFTER a local secret scan has already cleared it — injection, missing authz, unsafe deserialization, path traversal, SSRF, weak crypto, and credentials that are structurally hardcoded rather than read from a secret store. It reviews only the changed lines and their blast radius and reports only high-confidence findings.
At a glance¶
| Model | inherits the session's |
| Tools | Read Grep Glob Bash |
| Author | navjyotnishant |
| Source | agents/secrets-reviewer.md |
Returns content — does not write files
Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.
When it runs¶
The local secret scan found no leaked keys; now a semantic security pass is wanted.
do a security review of this diff
/review-secrets runs the local scan first as a gate; only when it clears does it spawn this agent for the semantic pass on the cleared snapshot.
What it returns¶
- Dimension verdict:
PASS/WARN(hardening nits) /BLOCK(exploitable). - Each finding, most severe first: Severity (
BLOCKER/WARNING/NIT), Location (file:line), What's wrong (one sentence), Attack scenario (actor/input → impact), Fix (concrete).
Spawned by¶
Derived, not declared
No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.
See the /pre-push-review pipeline for where this fits in the whole run.