How to Use the Security-Reviewer Agent in Everything Claude Code
The security-reviewer agent performs OWASP Top 10 vulnerability analysis, secret detection, and hardening checks on code changes through automated tooling and structured reporting. Invoke it manually via HANDOFF:, automatically through the /orchestrate command, or run its bundled security tools directly in CI pipelines.
The security-reviewer is one of the core sub-agents in the WorldFlowAI/everything-claude-code repository, designed to enforce security standards before code reaches production. This guide covers activation methods, the complete workflow, and practical integration patterns.
When to Invoke the Security-Reviewer Agent
Timing matters for security reviews. The agent definition in agents/security-reviewer.md specifies three critical trigger points:
| Situation | Recommended Trigger |
|---|---|
| New API endpoint, auth flow, or file-upload code | Immediately after writing the code |
| Dependency upgrades or CVE announcements | Run a pre-commit security scan |
| Before production release or PR merge | Include in the orchestrate workflow |
The agent is model-agnostic and uses the opus model by default. It can be called from any other agent or slash command via the HANDOFF: syntax.
Core Security-Reviewer Workflow
According to the source in agents/security-reviewer.md, the agent executes four sequential phases:
-
Initial scan – Automated tools run across the codebase. Supported tools include
npm audit,eslint-plugin-security,grep,trufflehog, andsemgrep(see lines 23-49). -
OWASP Top 10 checklist – Each category is examined for proper mitigations: parameterized queries, Content Security Policy headers, rate limiting, and more (see lines 70-78).
-
Project-specific checks – Financial, blockchain, authentication, and database security items validated against codebase requirements (see lines 28-71).
-
Report generation – A markdown report classifies findings as Critical, High, Medium, or Low, provides remediation snippets, and appends a security checklist (see lines 46-63 and 104-111).
Three Ways to Run the Security-Reviewer Agent
Method 1: Manual Hand-off from a Command
Use the HANDOFF: syntax to chain agents in sequence:
# From a Claude session
HANDOFF: security-reviewer -> code-reviewer -> architect
This executes security review first, passes results to code-reviewer for broader quality checks, then routes to architect for design feedback. The hand-off syntax is documented in commands/orchestrate.md (see lines 91-106).
Method 2: Using the Built-in /orchestrate Command
# In Claude chat
/orchestrate plan # runs planner → tdd-guide → code-reviewer → security-reviewer
The orchestrate command chains agents automatically. The security-reviewer appears last in the default sequence, ensuring security validation occurs only after functional completeness (see agent order in commands/orchestrate.md, lines 14-18).
Method 3: Running Security Tools Directly for CI
# From a terminal inside the repo
npm run security:check # defined in agents/security-reviewer.md
The security:check script bundles npm audit with eslint --plugin security, mirroring the automated portion of the agent's initial scan (see "Security Tools Installation", lines 81-95).
Key Configuration Files
Understanding these files helps you customize the security-reviewer behavior:
-
agents/security-reviewer.md– Full agent definition with workflow, checklists, and report template (lines 2-3 define the agent scope). -
rules/security.md– Mandatory pre-commit security checks that trigger the agent automatically (lines 5-12). -
commands/orchestrate.md– Orchestration command incorporating security-reviewer into multi-agent pipelines (lines 14-18 for agent sequence, lines 91-106 for hand-off mechanics). -
README.md– Overview of all agents including the security-reviewer (line 99). -
WORLDFLOWAI.md– Quick reference table of agents and responsibilities (agents table section).
Summary
- Invoke via
HANDOFF:for targeted security reviews on specific code changes. - Use
/orchestrate planfor full development lifecycle coverage with security as final gate. - Run
npm run security:checkin CI for automated, tool-based scanning without LLM overhead. - Review
agents/security-reviewer.mdfor complete checklist customization and report templates. - Configure
rules/security.mdto enforce mandatory pre-commit security triggers.
Frequently Asked Questions
How does the security-reviewer agent detect secrets and credentials?
The agent runs trufflehog and custom grep patterns during its initial scan phase (lines 23-49 in agents/security-reviewer.md). These tools scan for high-entropy strings, known API key patterns, and common secret formats before the OWASP analysis begins.
Can I customize the security checklist for my specific domain?
Yes. The project-specific checks section (lines 28-71) is designed for extension. Financial, blockchain, authentication, and database security items are templates you can modify to match your application's threat model and compliance requirements.
What model does the security-reviewer agent use?
The agent is model-agnostic and defaults to opus. You can override this in your Claude Code configuration if your organization requires different model assignments for cost or latency reasons.
Why does the orchestrate command run security-reviewer last?
The agent sequence in commands/orchestrate.md (lines 14-18) orders: planner → tdd-guide → code-reviewer → security-reviewer. This ensures security analysis evaluates final, reviewed code rather than incomplete drafts, reducing false positives and redundant security work.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →