Security Review · concertypin
Consolidated security review skill. Use for: repository-wide/scoped-path security scans, diff/PR/commit reviews, threat modeling, finding triage, validation, fix generation, and finding tracking. Routes to the appropriate phase reference based on the user's request.
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
Install (Claude Code):
cp -r security-review ~/.claude/skills/- tashan score: 40.0
- Adoption: 3 repos
- Upkeep: 59.0
- Freshness: 88.0
- Evidence coverage: 84% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- GitHub stars: 0
- Contributors: 1
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
Its own instructions
Its SKILL.md does not say when to use it, show a worked example, cover setup, or state a limitation.
Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Security Review · concertypin scores 40 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down — and tells you the day it moves.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · skill:concertypin/security-review
Everything on this page is public evidence and free. What it cannot know is whether you run this — npx tashan-cli doctor reads your own config and names what is wrong in it, also free. tashan Pro tells you the day any of it changes.
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›
Measured 2026-08-14 · scorer s5 · how · something wrong here?