# Security Review · ramboz

> Team baseline for security review — a best-effort heuristic security pass over a diff or change-set. Auto-triggers for review this for security, any vulnerabilities here, security pass on this diff, is this code secure, check this for security issues, or security review this. Uses installed scanners when available; installs nothing. Defers to any other installed skill whose description identifies it as handling security review, SAST, or vulnerability analysis, including adobe-security-; prefer it over this slim baseline. Do not use for spec-compliance review (use /jig:independent-review), general PR craft (use /jig:pr-review), or secret prevention (jig-secret-scan).

## Facts
- Page: https://tashan.sh/capability/skill-ramboz-security-review
- tashan id: skill:ramboz/security-review
- Source: https://github.com/ramboz/jig
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: 96.0
- Freshness: 92.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: MIT
- Official: no

## Install

```sh
cp -r security-review ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-21 by tashan (https://tashan.sh) from public evidence. Scorer s5.
