In this article
Code Review Security
| Field | Value |
|---|---|
| Kind | agent |
| Source | .github/agents/coding-standards/subagents/code-review-security.agent.md |
| Invocation | Delegated subagent, dispatched by a parent agent (not selected directly) |
| Interactive | No |
What it does
Thin skill-backed perspective subagent that reviews a precomputed diff for security issues and writes structured findings
When to use it
Code Review dispatches this perspective for security-relevant changes such as authorization, parsing, input validation, or sensitive-data handling. It traces concrete exploit paths within the supplied scope and does not invoke the standalone Security Reviewer. Users steer it through the parent review workflow.
Example usage
For an upload-validation change, the parent supplies the serialized diff, hotspots, review depth, exclusions, and task.outputs.security. The worker traces input to its use and returns JSON findings with evidence, impact, and a concrete fix. It does not alter source or report theoretical issues without a realistic security consequence.