‹ The Index

Security

skill

Author’s activation text, quoted as published

- You MUST use this skill before approving or merging any code that touches auth, input handling, permissions, or external data. Use when the review focus is specifically on security vulnerabilities, attack surface, or compliance — not general code quality. Stronger signals: "security review", "check for vulnerabilities", "is this safe", "audit this", "OWASP", "injection", "auth check", "XSS", "SQL injection", "pentest", "threat model". Can run standalone or as a follow-up after sextant:review-code. Use sextant:review-code instead when the goal is general code quality without a security focus.

Works with: Claude Code (native)  ·  Cursor, Codex CLI (manual)
native: this artifact type is that client's own format

Category: Security — see all ranked ›

Install (Claude Code):

cp -r security ~/.claude/skills/

Security audit

Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.

Its own instructions

Its SKILL.md says when to use it, shows worked examples, covers setup and states a limitation.

Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

Security scores 31 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down — and tells you the day it moves.

Start a 7-day trial › Everything measured on this page stays free.

Show your score

Measured this well? Put the live badge in your README — it updates as the score does.

tashan badge for Security
[![tashan](https://tashan.sh/badge/skill-hellotern-security.svg)](https://tashan.sh/capability/skill-hellotern-security.html)

source ↗  ·  skill:hellotern/security

Everything on this page is public evidence and free. What it cannot know is whether you run this — npx tashan-cli doctor reads your own config and names what is wrong in it, also free. tashan Pro tells you the day any of it changes.

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›

Measured 2026-08-14  ·  scorer s5  ·  how  ·  something wrong here?