security-review is agent-read markdown (skill) from firzus/agent-skills: Perform source-only security audits of codebases, APIs, services, and applications. Use for security questions, focused vulnerability reviews, or explicitly requested full audits..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Audit security boundaries in source
Find vulnerabilities with a concrete trust-boundary failure and give owners evidence and a narrow fix. Delegate every audit to a subagent; the parent verifies findings and owns the report. This skill does not establish runtime behavior or authorize fixes, external probes, publication, or deployment.
## 1. Set the boundary
Read the request, instructions, repository state, architecture, and relevant controls. Identify the reviewed revision, paths, assets, lower-trust principals, and intended security boundaries. Include local changes only when requested. Keep a named concern focused; expand to a codebase-wide audit only when explicitly requested or report artifacts are required. Do not assume controls in unseen deployment infrastructure.
**Done:** scope and evidence limits are explicit; ask before a consequential expansion.
## 2. Delegate and investigate
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (3822 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
firzus/agent-skills · 3 stars · license MIT · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_yuwpwxc5ncnfpm73
GET https://markdownregistry.com/api/v1/resolve?ref=firzus/agent-skills/security-review
GET https://markdownregistry.com/api/v1/blob/714e6a351fdd2018bb24a3e856f400b7cee6a6c0f678e1df09f7519e76a7a670
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
firzus/agent-skills · skills/engineering/code-review/SKILL.md · Review a scoped diff against requirements, project standards, and correctness using independent read-only reviewers…
firzus/agent-skills · skills/engineering/deep-research/SKILL.md · Investigate a question across sources with delegated research, adversarial verification, and a reusable evidence…
firzus/agent-skills · skills/engineering/gamification/SKILL.md · Gamification design for products, apps, and game meta-layers: design an engagement, habit, or retention system; choose…
firzus/agent-skills · skills/engineering/implement/SKILL.md · Deliver prepared work with test-first verification, current documentation, and a verified handoff.
firzus/agent-skills · skills/engineering/interview/SKILL.md · Prepare approved Linear work briefs through a continuous interview, with progressive framing for large goals.
firzus/agent-skills · skills/engineering/prototype/SKILL.md · Resolve a bounded design or feasibility question through an observable experiment. Use for authorized interface, logic…
firzus/agent-skills · skills/engineering/setup-codex/SKILL.md · Configure a reviewed Codex Operating Policy through model_instructions_file and offer low model verbosity with separate…
affaan-m/ecc · .agents/skills/security-review/SKILL.md · Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or…
affaan-m/ecc · .kiro/skills/security-review/SKILL.md · Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or…
affaan-m/ecc · docs/es/skills/security-review/SKILL.md · Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o…
microsoft/power-platform-skills · plugins/power-pages/skills/security-review/SKILL.md · Runs a guided, end-to-end security review of a Power Pages site and consolidates every finding into one HTML report…