Skip to content

secrets-reviewer

Use this agent for a deeper semantic security review of a code diff AFTER a local secret scan has already cleared it — injection, missing authz, unsafe deserialization, path traversal, SSRF, weak crypto, and credentials that are structurally hardcoded rather than read from a secret store. It reviews only the changed lines and their blast radius and reports only high-confidence findings.

At a glance

Model inherits the session's
Tools Read Grep Glob Bash
Author navjyotnishant
Source agents/secrets-reviewer.md

Returns content — does not write files

Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.

When it runs

The local secret scan found no leaked keys; now a semantic security pass is wanted.

do a security review of this diff

/review-secrets runs the local scan first as a gate; only when it clears does it spawn this agent for the semantic pass on the cleared snapshot.

What it returns

  • Dimension verdict: PASS / WARN (hardening nits) / BLOCK (exploitable).
  • Each finding, most severe first: Severity (BLOCKER/WARNING/NIT), Location (file:line), What's wrong (one sentence), Attack scenario (actor/input → impact), Fix (concrete).

Spawned by

Derived, not declared

No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.

See the /pre-push-review pipeline for where this fits in the whole run.

Read agents/secrets-reviewer.md →