# How to Use the Security-Reviewer Agent in Everything Claude Code

> Learn how to use the security reviewer agent for OWASP Top 10 analysis, secret detection, and hardening. Automate code security checks in your CI pipeline.

- Repository: [WorldFlowAI/everything-claude-code](https://github.com/WorldFlowAI/everything-claude-code)
- Tags: how-to-guide
- Published: 2026-09-07

---

**The security-reviewer agent performs OWASP Top 10 vulnerability analysis, secret detection, and hardening checks on code changes through automated tooling and structured reporting.** Invoke it manually via `HANDOFF:`, automatically through the `/orchestrate` command, or run its bundled security tools directly in CI pipelines.

The **security-reviewer** is one of the core sub-agents in the [WorldFlowAI/everything-claude-code](https://github.com/WorldFlowAI/everything-claude-code) repository, designed to enforce security standards before code reaches production. This guide covers activation methods, the complete workflow, and practical integration patterns.

## When to Invoke the Security-Reviewer Agent

Timing matters for security reviews. The agent definition in [`agents/security-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/security-reviewer.md) specifies three critical trigger points:

| Situation | Recommended Trigger |
|-----------|----------------------|
| New API endpoint, auth flow, or file-upload code | **Immediately** after writing the code |
| Dependency upgrades or CVE announcements | Run a **pre-commit** security scan |
| Before production release or PR merge | Include in the **orchestrate** workflow |

The agent is **model-agnostic** and uses the `opus` model by default. It can be called from any other agent or slash command via the `HANDOFF:` syntax.

## Core Security-Reviewer Workflow

According to the source in [`agents/security-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/security-reviewer.md), the agent executes four sequential phases:

1. **Initial scan** – Automated tools run across the codebase. Supported tools include `npm audit`, `eslint-plugin-security`, `grep`, `trufflehog`, and `semgrep` (see lines 23-49).

2. **OWASP Top 10 checklist** – Each category is examined for proper mitigations: parameterized queries, Content Security Policy headers, rate limiting, and more (see lines 70-78).

3. **Project-specific checks** – Financial, blockchain, authentication, and database security items validated against codebase requirements (see lines 28-71).

4. **Report generation** – A markdown report classifies findings as Critical, High, Medium, or Low, provides remediation snippets, and appends a security checklist (see lines 46-63 and 104-111).

## Three Ways to Run the Security-Reviewer Agent

### Method 1: Manual Hand-off from a Command

Use the `HANDOFF:` syntax to chain agents in sequence:

```markdown

# From a Claude session

HANDOFF: security-reviewer -> code-reviewer -> architect

```

This executes security review first, passes results to code-reviewer for broader quality checks, then routes to architect for design feedback. The hand-off syntax is documented in [`commands/orchestrate.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/commands/orchestrate.md) (see lines 91-106).

### Method 2: Using the Built-in /orchestrate Command

```bash

# In Claude chat

/orchestrate plan   # runs planner → tdd-guide → code-reviewer → security-reviewer

```

The orchestrate command chains agents automatically. The security-reviewer appears last in the default sequence, ensuring security validation occurs only after functional completeness (see agent order in [`commands/orchestrate.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/commands/orchestrate.md), lines 14-18).

### Method 3: Running Security Tools Directly for CI

```bash

# From a terminal inside the repo

npm run security:check   # defined in agents/security-reviewer.md

```

The `security:check` script bundles `npm audit` with `eslint --plugin security`, mirroring the automated portion of the agent's initial scan (see "Security Tools Installation", lines 81-95).

## Key Configuration Files

Understanding these files helps you customize the security-reviewer behavior:

- **[`agents/security-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/security-reviewer.md)** – Full agent definition with workflow, checklists, and report template (lines 2-3 define the agent scope).

- **[`rules/security.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/security.md)** – Mandatory pre-commit security checks that trigger the agent automatically (lines 5-12).

- **[`commands/orchestrate.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/commands/orchestrate.md)** – Orchestration command incorporating security-reviewer into multi-agent pipelines (lines 14-18 for agent sequence, lines 91-106 for hand-off mechanics).

- **[`README.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/README.md)** – Overview of all agents including the security-reviewer (line 99).

- **[`WORLDFLOWAI.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/WORLDFLOWAI.md)** – Quick reference table of agents and responsibilities (agents table section).

## Summary

- **Invoke via `HANDOFF:`** for targeted security reviews on specific code changes.
- **Use `/orchestrate plan`** for full development lifecycle coverage with security as final gate.
- **Run `npm run security:check`** in CI for automated, tool-based scanning without LLM overhead.
- **Review [`agents/security-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/security-reviewer.md)** for complete checklist customization and report templates.
- **Configure [`rules/security.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/rules/security.md)** to enforce mandatory pre-commit security triggers.

## Frequently Asked Questions

### How does the security-reviewer agent detect secrets and credentials?

The agent runs **trufflehog** and custom `grep` patterns during its initial scan phase (lines 23-49 in [`agents/security-reviewer.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/agents/security-reviewer.md)). These tools scan for high-entropy strings, known API key patterns, and common secret formats before the OWASP analysis begins.

### Can I customize the security checklist for my specific domain?

Yes. The **project-specific checks** section (lines 28-71) is designed for extension. Financial, blockchain, authentication, and database security items are templates you can modify to match your application's threat model and compliance requirements.

### What model does the security-reviewer agent use?

The agent is **model-agnostic** and defaults to `opus`. You can override this in your Claude Code configuration if your organization requires different model assignments for cost or latency reasons.

### Why does the orchestrate command run security-reviewer last?

The agent sequence in [`commands/orchestrate.md`](https://github.com/WorldFlowAI/everything-claude-code/blob/main/commands/orchestrate.md) (lines 14-18) orders: planner → tdd-guide → code-reviewer → security-reviewer. This ensures security analysis evaluates **final, reviewed code** rather than incomplete drafts, reducing false positives and redundant security work.