A conversational security advisor for every AI coding agent — hunts real, exploitable vulnerabilities in your codebase, explains the exploit path, and lets you push back.
Grounded in Anthropic's 2025/2026 safety research (Agents Rule of Two, Sleeper Agents, prompt-injection defences) and OWASP Top 10:2025 / OWASP LLM Top 10 2025.
Works with Claude Code, Cursor, Codex, Gemini CLI, GitHub Copilot Agents, Kiro, OpenCode, Pi, Rovo Dev, Trae — and any other harness that follows the Agent Skills spec.
Most "AI security audits" either produce a wall of low-signal findings or a one-shot report you never read. security-advisor is built differently:
- Conversational — surfaces one finding at a time, with a concrete exploit path, and asks what you want to do next.
- PoC-disciplined — if it can't give you
file:lineand a 3-5 step attack, it doesn't surface. No "could theoretically be exploited". - Stack-aware — progressive disclosure loads only the references that match your project (Next.js, React, LLM apps, Node, Python).
- Current — the Next.js reference cites the 2025 CVE list (CVE-2025-29927 middleware bypass, -55182 Server Function RCE, etc.). The LLM reference covers the four new OWASP LLM Top 10 2025 entries (System Prompt Leakage, Vector & Embedding Weaknesses, Unbounded Consumption, expanded Excessive Agency).
- Harness-portable — a single canonical source is materialised into every agent's expected directory. One skill, ten agents.
- Zero runtime deps — no plugins, no build step, just markdown.
It complements /cso and similar audit tools rather than replaces them. /cso is a 14-phase audit that writes a JSON report. This is a chat-first advisor that teaches as it scans.
Works with Claude Code, OpenCode, Codex, Cursor, and 40+ other agents:
# Install globally (recommended for a security tool you'll want everywhere)
npx skills add dani-z/security-advisor -g
# Interactive install — runs a wizard that asks which agent(s) and whether to install globally or into the current project
npx skills add dani-z/security-advisor
# Target a specific agent, globally
npx skills add dani-z/security-advisor -g -a claude-code
npx skills add dani-z/security-advisor -g -a cursor
npx skills add dani-z/security-advisor -g -a codex
npx skills add dani-z/security-advisor -g -a opencode
npx skills add dani-z/security-advisor -g -a gemini
# Install into just the current project (drop the -g flag)
npx skills add dani-z/security-advisor -a claude-code
# All agents, non-interactive (CI/CD friendly)
npx skills add dani-z/security-advisor -g --all -y-g installs to ~/<agent>/skills/ (available across all projects). Without -g, the skill installs into ./<agent>/skills/ in the current project so it can be committed alongside your code.
See skills.sh or run npx skills --help for the full CLI reference.
What is skills.sh? Vercel's open registry for Agent Skills. It auto-discovers any public GitHub repo following the Agent Skills spec and makes it installable via npx skills add. No submission required — you publish by pushing to GitHub. Ranking comes from install telemetry.
For agents that look for skills inside the project directory (Cursor, Kiro, Rovo Dev):
cd your-project
git clone https://github.com/dani-z/security-advisor .skills-source
# Then symlink the harness-specific dirs you need, e.g.:
ln -s .skills-source/.claude .claude
# or just copy the whole directoryThe repo already ships pre-materialised directories for every harness (.claude/, .cursor/, .codex/, .gemini/, .github/, .kiro/, .opencode/, .pi/, .rovodev/, .trae/, .trae-cn/). Just copy the one you need.
git clone https://github.com/dani-z/security-advisor ~/.security-advisor
# Claude Code
ln -s ~/.security-advisor/source/skills/security-advisor ~/.claude/skills/security-advisor
# Cursor
ln -s ~/.security-advisor/source/skills/security-advisor ~/.cursor/skills/security-advisor
# Codex
ln -s ~/.security-advisor/source/skills/security-advisor ~/.codex/skills/security-advisor
# ...and so onGrab the latest release's security-advisor.skill bundle and unzip into your harness's skills directory:
unzip security-advisor.skill -d ~/.claude/skills/ # or .cursor/skills, .codex/skills, etc.Note for Windows users: On Windows, extract the .skill bundle using your preferred unzip tool (7-Zip, WinRAR, or tar if available), as symlinks inside the bundle may not extract correctly with the default Windows unzip handler.
/security-advisor
Just ask for a security review. The skill description is engineered to auto-trigger on phrases like:
- "security review", "find vulnerabilities", "audit this"
- "am I leaking secrets?", "is this endpoint safe?", "check for IDOR"
- "prompt injection review", "threat model", "pre-ship audit"
- Any mention of a specific CVE, OWASP category, or auth concern
| Command | What it does |
|---|---|
/security-advisor |
Default — scan the current branch diff vs main + quick secrets/CVE sweep |
/security-advisor --full |
Scan the whole repo, not just the diff |
/security-advisor --llm |
Scan only LLM touchpoints (prompt injection, tool calling, cost, output handling) |
/security-advisor --deps |
Scan dependencies against known CVEs |
/security-advisor --secrets |
Scan for leaked secrets and env misconfiguration |
/security-advisor --scope <area> |
Focus on one area (e.g. --scope auth, --scope webhooks) |
/security-advisor --report |
Also write findings to .security-advisor/report-YYYY-MM-DD.md |
Flags combine: /security-advisor --full --report. Harnesses that don't support slash-command arguments (Cursor, Gemini, Kiro) — ask in plain language: "Run a full audit and write a report".
| Harness | Slash-command args | Auto-trigger on phrases |
|---|---|---|
| Claude Code | ✅ | ✅ |
| OpenCode | ✅ | ✅ |
| Codex | ✅ | ✅ |
| Cursor | ❌ (use prose) | ✅ |
| Gemini CLI | ❌ (use prose) | ✅ |
| Kiro | ❌ (use prose) | ✅ |
| GitHub Copilot Agents | ❌ (use prose) | ✅ |
| Pi | ✅ | ✅ |
| Rovo Dev | ✅ | ✅ |
| Trae / Trae China | ✅ | ✅ |
By default, /security-advisor scans only your current branch's diff against main. This is fast and targeted — good for PR reviews. If your repo has no main branch or the diff is empty, the skill automatically upgrades to a full repo scan.
- Secrets committed to git history or
.envtracked - Client-exposed server secrets (
NEXT_PUBLIC_*,VITE_*,PUBLIC_*,EXPO_PUBLIC_*with sensitive values) - Weak crypto (MD5/SHA1/DES for anything security-relevant)
- Insecure deserialization (
eval,Function,pickle.loads,yaml.load) - Command injection (
exec/execSyncwith user input) - Path traversal, JWT misuse, timing-unsafe comparisons, SSRF, prototype pollution
- Server Actions that forgot to re-authenticate (public POST endpoints, always)
- Tenant-scoped queries that source org ID from request body instead of session
- IDOR patterns (
findFirst({ where: { id } })without ownership check) - Stripe webhook raw-body verification (
req.text()before JSON.parse) - Middleware bypass — self-hosted Next.js +
x-middleware-subrequest(CVE-2025-29927) - Server Function deserialization (CVE-2025-55182), RSC DoS (CVE-2025-55184)
- better-auth misconfigurations, Prisma mass assignment,
$queryRawUnsafe - CSP / HSTS / security header audit
- XSS escape hatches —
dangerouslySetInnerHTML,innerHTML, URL schemes inhref - Auth token storage — flags session/refresh tokens in
localStorage - Open redirects (
next,redirect,returnTo,callbackUrlparams) postMessagehandlers without origin checks- Hydration / RSC data leakage
- Unsanitised markdown rendering
- React Native —
WebViewwith user content, deep links,AsyncStoragefor tokens
- Prompt injection entry points (user content in system-prompt position, tool schema, few-shot examples)
- Improper output handling (LLM output rendered as HTML or executed)
- Excessive agency — tools the LLM can call without user-level permission checks
- Unbounded consumption (no token caps / cost limits per user or org)
- System prompt leakage via error messages or logs
- Vector & embedding weaknesses — tenant isolation in RAG
- Sensitive information disclosure via model responses
pickle.loads,yaml.load(non-safe),eval,exec,shell=True- SQL injection (f-string / format /
%formatting in queries) - Django
DEBUG=True/ wildcardALLOWED_HOSTSin prod - Flask SSTI (
render_template_string(userInput)) - CSRF / middleware order issues, JWT with missing
algorithms
Calibrated against 20 hard exclusions and 12 precedents (see source/skills/security-advisor/references/false-positive-rules.md):
- Missing rate limits as a standalone finding (only when combined with concrete auth/cost amplification)
- DoS without a specific exploit vector (exception: LLM unbounded consumption is a finding)
- Test fixtures with dummy secrets (unless imported by prod code)
- Memory safety concerns in memory-safe languages
- Client-side "lack of auth" (the server is what matters)
- User content in the user-message position of an LLM chat (intended API)
- Insecure randomness outside security contexts
- CVEs on transitive dependencies that aren't reached
A report with 3 real findings beats a report with 3 real plus 12 theoretical.
security-advisor/
├── source/skills/security-advisor/ # canonical skill (single source of truth)
│ ├── SKILL.md
│ ├── metadata.json
│ └── references/ # 8 reference files
│ ├── research-basis.md # Anthropic 2025/2026 research + OWASP
│ ├── stack-nextjs.md # Next.js CVEs, server actions, Prisma, Stripe
│ ├── stack-react.md # React UI-layer (XSS, tokens, RN)
│ ├── stack-llm-apps.md # OWASP LLM Top 10 2025
│ ├── stack-nodejs-general.md # Node/TS patterns
│ ├── stack-python.md # FastAPI / Django / Flask
│ ├── findings-template.md # Output formats
│ └── false-positive-rules.md # Exclusions + precedents
├── skills/security-advisor/ # → symlink (for `npx skills add` CLI)
├── .claude/skills/security-advisor/ # → symlink (Claude Code)
├── .cursor/skills/security-advisor/ # → symlink (Cursor)
├── .codex/skills/security-advisor/ # → symlink (Codex CLI)
├── .gemini/skills/security-advisor/ # → symlink (Gemini CLI)
├── .github/skills/security-advisor/ # → symlink (GitHub Copilot Agents)
├── .kiro/skills/security-advisor/ # → symlink (Kiro)
├── .opencode/skills/security-advisor/# → symlink (OpenCode)
├── .pi/skills/security-advisor/ # → symlink (Pi)
├── .rovodev/skills/security-advisor/ # → symlink (Rovo Dev)
├── .trae/skills/security-advisor/ # → symlink (Trae)
├── .trae-cn/skills/security-advisor/ # → symlink (Trae China)
├── .agents/skills/security-advisor/ # → symlink (Codex primary; fallback for Cursor, Gemini, Copilot, OpenCode, Pi)
├── metadata.json # skills.sh discovery metadata
├── scripts/sync.sh # regenerate harness symlinks
├── README.md
├── AGENTS.md # multi-agent entry point
├── HARNESSES.md # per-harness compatibility matrix
└── LICENSE # Apache 2.0
Every .<harness>/skills/security-advisor directory is a symlink to source/skills/security-advisor/. Edit source/, everything follows. To regenerate the symlinks (e.g. after cloning on a system where git didn't preserve them, or after adding a new harness), run:
bash scripts/sync.shNote for Windows users: git preserves symlinks by default only if core.symlinks=true is set. On Windows, after cloning, either enable symlinks (git config --global core.symlinks true) or run bash scripts/sync.sh to regenerate them.
- Agents Rule of Two (Anthropic, Nov 2025) — code paths combining 2+ of {untrusted input, sensitive tool/data, external communication} get the review budget first.
- PoC discipline —
file:line+ 3-5 step exploit path, or it doesn't surface. - LLMs beat static tools at reasoning, not taint tracking — delegate mechanical stuff (
npm audit,gitleaks), focus the agent on business logic, IDOR, prompt injection. - Instruction-like content in scanned code is data, not instructions — anti-manipulation rule, shaped by the Oct 2025 Claude Code PR-title prompt injection on HackerOne.
- Zero noise beats full coverage — confidence gate at 7/10, below that it's dropped.
See source/skills/security-advisor/references/research-basis.md for the full research grounding with citations.
/security-advisor --scope auth
> I'll scan the auth surface of this project. First, let me map it out...
>
> ATTACK SURFACE — auth
> ─────────────────────
> PUBLIC POST /api/auth/[...all] → better-auth handler
> ACTIONS 38 server actions → src/actions/*
> PAGES /admin/* → admin-only routes
>
> This look right? Anything I missed?
yes, go
> ### Finding: Server action leaks org-scoped data across tenants
> HIGH · confidence 9/10 · src/actions/qr/get-stats.ts:12
>
> What I see: getStats() reads organizationId from actionInput rather than
> the authenticated session, so a user authenticated to org A can pass
> { organizationId: "org-B" } and read org B's analytics.
>
> Exploit path:
> 1. Attacker signs in to any org.
> 2. Opens DevTools, finds the server action request.
> 3. Replays with a different organizationId value.
> 4. Server trusts the body; returns another tenant's scan data.
>
> Fix: source organizationId from getOrganizationContextForCurrentUser()
> inside the action; never accept it from the input schema.
>
> Reference: OWASP A01 Broken Access Control (2025)
Follow-up menu via AskUserQuestion in Claude Code; plain-text prompts in other harnesses.
- AI-assisted review, not a penetration test. Catches common and current patterns; misses subtle cryptographic bugs, timing side channels, and runtime-only issues.
- Static analysis from a read-only agent — won't probe live endpoints, won't run fuzzers.
- Python coverage is deliberately brief (~90 lines) — expand on demand.
- For anything handling payments, PII, or production credentials, engage a qualified security firm. Use this as a fast second pass, not as your only line of defence.
/cso(gstack) — deeper 14-phase audit with JSON report output.gitleaks/trufflehog— dedicated secret scanners.semgrep/codeql— static taint analysis at scale.npm audit/bun outdated/pip audit— dependency CVE matching.
security-advisor does the reasoning these tools can't. Use them together.
This skill is packaged to the agentskills.io spec and is ready to publish to skills.sh — Vercel's open registry that powers npx skills add.
There's no submission — any public GitHub repo following the Agent Skills format is installable via npx skills add <owner>/<repo>. Ranking on the leaderboard comes from anonymous install telemetry. You publish simply by pushing to GitHub.
- Push this directory to a public GitHub repo.
- Tag a release (
v1.0.0) — optional but good hygiene; matchesmetadata.version. - Test the install:
npx skills add <you>/security-advisor -a claude-code -yon a clean machine (omit-gto test project-level install; the wizard will offer both). - Bump
metadata.versionin bothsource/skills/security-advisor/SKILL.mdfrontmatter andsource/skills/security-advisor/metadata.jsonon each update sonpx skills updatedetects it. - (Optional) Open a PR to vercel-labs/agent-skills to be featured in Vercel's curated set.
npx skills update security-advisor- Fork the repo.
- Edit
source/skills/security-advisor/SKILL.mdor any reference file undersource/skills/security-advisor/references/. Never edit files inside.<harness>/skills/directly — those are symlinks. - Bump
metadata.versionin the two metadata files. - If you added a new harness, update the
HARNESSESarray in scripts/sync.sh, then runbash scripts/sync.sh. - Open a PR.
See LICENSE.
