Add a security-review pass to every PR
متى تستخدمه: Your PRs currently go straight from code-review to merge — no security eyes.
المتطلبات الأساسية
- Skills installed — git clone https://github.com/trailofbits/skills ~/.claude/skills/trailofbits
الخطوات
-
Scope the diffUse trailofbits/pr-review skill on the current PR. List files the skill thinks are security-relevant with reasons.✓ تم النسخ→ Concrete file-by-file relevance reasons
-
Deep reviewFor each flagged file, run the appropriate domain skill (crypto, input-validation, auth). Report findings with severity.✓ تم النسخ→ Severity-ranked list with code refs
-
Summary for reviewerWrite a 5-bullet PR comment summarizing the findings, non-scary but precise.✓ تم النسخ→ Reviewer-friendly summary with exact line citations
النتيجة: A security review comment on every PR that catches real issues without drowning you in false positives.
المزالق
- Skill flags style issues as security — Calibrate by prompting: "focus on exploitable issues only"