security-review
Security review
security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence.
Install Security review
Install this skill with the skills CLI
npx skills add getsentry/skills --skill security-reviewOr, for Claude Code, add Sentry's plugin marketplace
claude plugin marketplace add getsentry/skillsThen install the sentry-skills plugin, which holds all 28 skills
claude plugin install sentry-skills@sentry-skillsRestart Claude Code after installing the plugin. Sentry's README says its skills were written for Sentry employees, so some carry Sentry conventions.
Or paste this into your coding agent: Install the agent skill security-review from github.com/getsentry/skills.
A skill can include scripts that run on your computer, so read its source first.
What Security review does
security-review is an agent skill from Sentry that reviews code for security holes an attacker could actually use. Its main rule is to report only high-confidence findings: a vulnerable pattern plus input that an attacker controls. Medium-confidence issues are marked as needing verification, and theoretical or best-practice issues are not reported at all. The agent reports only on the code it was given but researches the whole codebase first.
The security-review skill spends much of its length on avoiding false positives. Values from settings, environment variables, config files and constants count as server-controlled, not attacker-controlled. Auto-escaping in Django, React and Vue templates and parameterized ORM queries are treated as safe unless bypassed, for example through dangerouslySetInnerHTML, v-html, mark_safe or raw SQL built with string interpolation.
The skill loads topic guides by context: authorization and injection for API routes, XSS and CSRF for templates, SSRF for outgoing requests, and others for crypto, file uploads, deserialization and supply chain. It has language guides for Python, JavaScript, Go, Rust and Java, and infrastructure guides for Docker, Kubernetes, Terraform, CI and cloud IAM. Findings carry a severity from critical to low.
When to use Security review
- You want a security review of a pull request without a flood of false alarms.
- You are about to ship a new API endpoint and want access control and injection checked.
- You want a second look at code that handles file uploads, tokens or outgoing requests.
- You need an OWASP-style review for Python, JavaScript, Go, Rust or Java code.
When to pick something else
- GitHub Actions workflow files: use gha-security-review from the same repository.
Which agents Security review works in
Sentry documents Security review for Claude Code, Cursor, Cline, GitHub Copilot. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.
The SKILL.md lists Claude Code tool names in allowed-tools (Read, Grep, Glob, Bash, Task). Other agents ignore that line and use their own file and shell tools.
Security review license
Security review is published under CC-BY-SA-4.0. The repository is Apache-2.0, but the security-review folder has its own LICENSE: its reference material is adapted from the OWASP Cheat Sheet Series and stays under CC-BY-SA-4.0. You may copy and adapt it, even commercially, if you credit the source and share any changed version under the same license.
Questions people ask
Can I copy Sentry's security-review skill into my own project?
Yes, with conditions. Its reference material is CC-BY-SA-4.0 because it is adapted from the OWASP Cheat Sheet Series. You may copy and change it, even in a commercial project, if you credit the source, link the license, say what you changed, and release any changed version under CC-BY-SA-4.0.
Does security-review report every possible vulnerability?
No, by design. It reports only high-confidence findings where attacker-controlled input reaches a vulnerable pattern, marks medium-confidence ones as needing verification, and drops theoretical issues. That keeps reports short but can miss issues it could not confirm.
Related skills for security
- Differential review: differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.
- Firebase security rules auditor: firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON.
- Semgrep rule creator: semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.
- Supply chain risk auditor: supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.
More from Sentry
- Code review: code-review is Sentry's agent skill for reviewing pull requests by Sentry's engineering practices: runtime errors, performance, side effects, compatibility, security, design, tests and the tone of feedback.
- GitHub Actions security review: gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.
- Iterate on PR: iterate-pr is Sentry's agent skill that keeps working on a GitHub pull request until CI passes and high and medium priority review comments are fixed, using bundled scripts and the gh CLI.