Security Review (affaan-m) vs Security Review (Sentry)
Two different Claude skills are both called Security Review. Security Review (affaan-m) and Security Review (Sentry) install under the same name and do different jobs, which is exactly how the wrong one ends up running.
Security Review
affaan-m/ecc
Helps developers implement secure features by listing concrete checks and recommended patterns for authentication, input handling, secret management, API endpoints, and payment or sensitive flows. Unlike similarly named tools that scan code or produce vulnerability audits, this one focuses on design-time guidance and implementation checklists — it does not run automated SAST, assign severity scores, or perform penetration-style audits of diffs.
1 scenario in the bank answer to it
Security Review
Sentry
Hunts only for exploitable security holes — injection, XSS, broken auth, weak crypto — and deliberately stays quiet unless it can point at attacker-controlled input reaching a vulnerable pattern. It reports high-confidence findings only, so a clean run is not proof of safety.
2 scenarios in the bank answer to it
What is the difference between Security Review (affaan-m) and Security Review (Sentry)?
- Security Review (affaan-m)
- Helps developers implement secure features by listing concrete checks and recommended patterns for authentication, input handling, secret management, API endpoints, and payment or sensitive flows. Unlike similarly named tools that scan code or produce vulnerability audits, this one focuses on design-time guidance and implementation checklists — it does not run automated SAST, assign severity scores, or perform penetration-style audits of diffs.
- Security Review (Sentry)
- Hunts only for exploitable security holes — injection, XSS, broken auth, weak crypto — and deliberately stays quiet unless it can point at attacker-controlled input reaching a vulnerable pattern. It reports high-confidence findings only, so a clean run is not proof of safety.
Should I use Security Review (affaan-m) or Security Review (Sentry)?
The clearest answer is a situation each one is unambiguously right for. Both of these are drawn from the game's question bank.
Reach for Security Review (affaan-m) when
I'm about to design a new login + payment flow and want a clear, practical list of secure patterns, do/avoid rules, and concrete checks I should follow as I build the feature so we don't bake in mistakes. I don't want someone to comb the whole repo for every weakness, produce a full cross-system compliance report, or only review a single outstanding change.
Winner: security-review-affaan-m gives the practical, design-time guidance this person needs — concrete patterns and checks for authentication, input handling, secret management, endpoints and sensitive flows to follow while writing the feature. What it does that the others do not is focus on implementation guidance up front rather than producing vulnerability scan results, a prioritized compliance audit, or a narrow review of a pending change. Most tempting wrong answer: security-review-getsentry — it finds and labels code-level problems, so it looks useful, but its output is about surfacing and scoring findings from existing source code rather than giving the developer a checklist of patterns and design-time rules to follow. (Other traps: security-reviewer-jeffallan would overdeliver a prioritized, compliance-style audit across code, infra and deps — useful but the wrong scope and heavier than needed; security-review-waybarrios only examines the specific unmerged change and focuses on high-confidence exploit paths, so it won't provide the broad, feature-level implementation guidance the author wants.)
Reach for Security Review (Sentry) when
Ship is Friday. You want to know whether anything in this quarter of work is genuinely exploitable, and you do not want to wade through naming opinions to find out.
This is the only one that hunts exclusively for exploitable holes and stays quiet otherwise — it reports a finding when it can trace attacker-controlled input to a vulnerable pattern. The broad reviewers all include security, but they hand it to you mixed in with the style nits you just said you did not want.
What they have in common
Both are filed under Security, the axis along which they collide. That shared ground is what makes an agent pick between them on description alone — and what makes it pick wrong.
Nearby comparisons
- Security Review (affaan-m) vs Security Review (waybarrios)
- Dependency Updater vs Security Review (affaan-m)
- Secure Error Handling vs Security Review (affaan-m)
- Security Review (affaan-m) vs Security Reviewer
- Security Review (affaan-m) vs Semgrep Rule Creator
- Security Review (affaan-m) vs What Leaked About You
Reading the difference is not the same as spotting it at speed. That is the game.
Today's session