ai-agent

claude-code-security-review: Secure Code

Get AI-powered security reviews with claude-code-security-review.
intermediate30 minutes💵 Free
6,079 stars659 forksPythonGuide quality 8/10Updated 2/11/2026100% free · open source
What it is

Analyzes code changes for security vulnerabilities using AI.

Real use case example

"A founder builds a new e-commerce project on GitHub. They set up this security review automation, and every time they push code changes, it automatically scans for vulnerabilities, ensuring their project stays secure. This frees up time to focus on building and launching their project."

Best insideClaude APICursorCodex CLISelf-hosted
When to use it
  • When merging new code into the main branch to ensure no security vulnerabilities are introduced
  • During regular code audits to identify and remediate existing security issues
  • When onboarding new developers to ensure they understand the security requirements and best practices for the project
Ready-to-paste prompt
To trigger a security review for a specific pull request, add the following step to your workflow file: `uses: Anthropics/claude-code-security-review@v1` and configure the `claude_api_key` and `paths` inputs accordingly
Heads up: Before using claude-code-security-review, you need to obtain a Claude API key and ensure you have the necessary permissions and credentials to access the Claude API, as well as a GitHub Actions workflow configured to trigger the analysis on your repository
Saves to your device
Use with Claude
New

Skip the builder — one click puts this in Claude, Cursor, Antigravity and more.

🛠️ Technical setup

Expect 20–40 minutes in a terminal — or let your AI agent drive it.

Try it instantly — no install
Claude Code
mkdir -p ~/.claude/skills/claude-code-security-review && curl -fsSL https://workflowstacks.com/api/skills/claude-code-security-review/claude-skill -o ~/.claude/skills/claude-code-security-review/SKILL.md
Open in another AI app

Opens the app with this repo with the prompt ready to go — no copy-paste needed.

Connect the whole catalog (MCP)
claude mcp add --transport http workflowstacks https://workflowstacks.com/api/mcp

Adds a WorkflowStacks connector to Claude Code: search and load any skill here by chatting.

How claude-code-security-review: Secure Code works
Codeflow
Free to inspect

Claude-code-security-review: Secure Code is a medium Python project (~7.5k lines across 27 code files). Expect some technical setup — comfortable with a terminal, or ask a developer. Last commit 7 months ago, MIT license, has a test suite.

Size
Medium codebase
~7.5k lines · 27 code files · ~1 h to skim
Setup
Some technical setup
Comfortable with a terminal? 20–40 min. Otherwise ask a dev.
Runs on
Python
No API keys detected
Python 90%TypeScript 7%JavaScript 3%
Where to start reading
  1. 1
    README.md
    Start here — what it does and how to install it
  2. 2
    action.yml
    Where the program starts running
  3. 3
    examples/custom-false-positive-filtering.txt
    A worked example — copy this to get going
What's in each folder
docs/Documentation2 files
examples/Examples you can copy2 files
claudecode/Folder26 files
scripts/Helper scripts3 files
.github/CI / automation (GitHub Actions)2 files
.claude/Editor / agent settings1 files
READMEHas testsDocumentedCI checksExamples includedMIT licenseLast update 7 mo ago
Quick Actions
Details
Creator
anthropics
Language
Python
Category
ai-agent
Published
8/4/2025

Are you the creator of this tool? Claim your listing → and earn 85% of every sale.

Ready-to-run pack · one-time $29

Review Watchdog

Catch every bad review the day it lands — with a reply ready.

Includes the tested workflow and a written setup playbook. Needs: Google Places API key (free tier).

See what you get