AthenodeAthenode

Security Review

Defensive security review of your own codebase with a coding agent: code review for vulnerabilities, dependency and supply-chain audit, secret scanning, CI workflow and IaC checks, and threat modeling.

Start with /security-audit (whole repository, a path, or the current diff). It fans out to three subagents — code reviewer, dependency auditor and a verifier that tries to disprove each finding — and returns one report with only the findings that survived.

Works with no account. /security-scan runs whichever open-source scanners are installed (semgrep, osv-scanner, gitleaks, trivy) and says which are missing; the review skills need nothing. The Socket MCP server (remote, sign-in on first use) scores dependencies.

Third-party skills, imported unmodified: security-review and gha-security-review from https://github.com/getsentry/skills (Apache-2.0; reference material based on the OWASP Cheat Sheet Series, CC BY-SA 4.0), owasp-security from https://github.com/agamm/claude-code-owasp (MIT), stride-analysis-patterns from https://github.com/wshobson/agents (MIT). Not affiliated with their authors.

For reviewing code you own or are authorized to test; it contains no offensive tooling.

AGENTS.md

Instructions every agent follows
Security review
  • Review only code and systems the user owns or is authorized to test. Do not write exploits against third-party targets, and do not send requests to systems outside the project to confirm a finding.
  • A finding needs evidence: the file and line, the path by which attacker-controlled input reaches it, and the impact. Without that path, report it as a question or a hardening note, not as a vulnerability.

Ready to ship better, together?

Spec it. Decompose it. Ship it. All with your AI agent.

Start for free

Join engineers building with Athenode today.