In this article
Security Reviewer
| Field | Value |
|---|---|
| Kind | agent |
| Source | .github/agents/security/security-reviewer.agent.md |
| Invocation | Selected from the chat agent picker as Security Reviewer |
| Interactive | Yes |
What it does
Security skill assessment orchestrator for codebase profiling and vulnerability reporting
When to use it
Use Security Reviewer to audit repository security, review a changed surface, or assess a plan before implementation. It profiles technologies, selects applicable security skills, verifies findings where the mode permits, and consolidates a report. Use Security Planner to develop a security model and control roadmap.
How to use it
- Select
Security Reviewerand identifyaudit,diff, orplanmode and the target scope. - Supply any skill focus, prior report, or plan. For audit or diff correlation, identify the security-plan baseline explicitly.
- Review skill findings, verification results, exclusions, and report limitations. Plan-mode risks are not current-code vulnerability findings.
- Resolve the report's priorities through the appropriate owner. Request TM7 work separately when needed, and retain the required professional-review boundary.
Example usage
Ask: "Review the changed upload and authorization paths in diff mode. Focus on the changed behavior, verify actionable findings, and report excluded or unavailable checks. Do not modify source files."
Expect a scoped security report with evidence and verification outcomes. Success means confirmed findings are separated from unassessed areas, and a narrow diff is not presented as a full-system audit.