security-reviewer (jeffallan)

Performs end-to-end security examinations of code, infrastructure, dependencies and secrets and compiles a prioritized audit report that assigns severity to each finding and lists concrete remediation steps. Unlike tools that only add inline comments, check authentication patterns, or scan a branch diff, this one is aimed at producing a compliance-aware, prioritized audit document rather than a quick pre-merge or single-file review.

A situation it fits

An auditor is coming and wants one document that grades the whole system — app code, servers, third-party libraries, leaked secrets — with a severity on every issue and a fix for each, ranked worst-first.
security-reviewer (jeffallan). security-reviewer-jeffallan produces the end-to-end, severity-ranked audit document spanning code, infrastructure, dependencies and secrets. security-review-owasp and security-review-waybarrios only look at a diff or branch for exploits; security-review-affaan-m is build-time guidance, not an audit. The tell is a ranked document across the whole system.

Skills it gets confused with

These share a family with security-reviewer (jeffallan), which is another way of saying they are the ones you might reach for by mistake.

Knowing what security-reviewer (jeffallan) does is the easy half. Telling it apart from the others under time pressure is the game.

Today's session

security-reviewer (jeffallan) is part of jeffallan/claude-skills. Licence: MIT. The description above was written for this game, not taken from the skill.

← All skills