Skip to content

/security-deep-review

Review class · gate

Advise only. Reads changes, reports findings, and never writes a file or commits. Shared rules: CONVENTIONS.md.

Runs the same mandatory secret-scanner gate first, then a Workflow-tool pipeline — parallel specialist finders sweep independent lenses (injection/authz, SSRF/deserialization/path-traversal, supply-chain, crypto/authn, cloud/infra), each finding is adversarially re-checked by independent verifiers (majority-refute kills it), then one synthesis pass produces a severity-ranked BLOCK/WARN/PASS report. Diff-scoped by default; --full sweeps the whole repo. Deliberately invoked, not part of the default pre-push fleet.

At a glance

Run it /security-deep-review
Class review · gate
Version 0.1.0
Author navjyotnishant
Cost typically 5 finder calls + up to 15 verifier calls (commonly 15–30 total agent calls for a mid-size diff)
Needs gitleaks or trufflehog or detect-secrets
Source skills/security-deep-review/SKILL.md

What it needs, and what happens without it

Every tool is detected at runtime — none is installed for you.

Tool Without it
gitleaks or trufflehog or detect-secrets BLOCK with install instructions — the gate cannot be skipped

The pipeline

/security-deep-review pipeline

Agents it spawns

  • security-finder — Use this agent as one of several parallel lens-scoped finders in the security-deep-review Workflow pipeline —…
  • security-verifier — Use this agent as an independent adversarial verifier in the security-deep-review Workflow pipeline — given…

The procedure

The executable steps live in the skill file itself and are deliberately not reproduced here: they are instructions to the model at runtime, not documentation.

Read security-deep-review/SKILL.md →