How to Use the Security-Reviewer Agent in Everything Claude Code

The security-reviewer agent performs OWASP Top 10 vulnerability analysis, secret detection, and hardening checks on code changes through automated tooling and structured reporting. Invoke it manually via HANDOFF:, automatically through the /orchestrate command, or run its bundled security tools directly in CI pipelines.

The security-reviewer is one of the core sub-agents in the WorldFlowAI/everything-claude-code repository, designed to enforce security standards before code reaches production. This guide covers activation methods, the complete workflow, and practical integration patterns.

When to Invoke the Security-Reviewer Agent

Timing matters for security reviews. The agent definition in agents/security-reviewer.md specifies three critical trigger points:

Situation Recommended Trigger
New API endpoint, auth flow, or file-upload code Immediately after writing the code
Dependency upgrades or CVE announcements Run a pre-commit security scan
Before production release or PR merge Include in the orchestrate workflow

The agent is model-agnostic and uses the opus model by default. It can be called from any other agent or slash command via the HANDOFF: syntax.

Core Security-Reviewer Workflow

According to the source in agents/security-reviewer.md, the agent executes four sequential phases:

  1. Initial scan – Automated tools run across the codebase. Supported tools include npm audit, eslint-plugin-security, grep, trufflehog, and semgrep (see lines 23-49).

  2. OWASP Top 10 checklist – Each category is examined for proper mitigations: parameterized queries, Content Security Policy headers, rate limiting, and more (see lines 70-78).

  3. Project-specific checks – Financial, blockchain, authentication, and database security items validated against codebase requirements (see lines 28-71).

  4. Report generation – A markdown report classifies findings as Critical, High, Medium, or Low, provides remediation snippets, and appends a security checklist (see lines 46-63 and 104-111).

Three Ways to Run the Security-Reviewer Agent

Method 1: Manual Hand-off from a Command

Use the HANDOFF: syntax to chain agents in sequence:


# From a Claude session

HANDOFF: security-reviewer -> code-reviewer -> architect

This executes security review first, passes results to code-reviewer for broader quality checks, then routes to architect for design feedback. The hand-off syntax is documented in commands/orchestrate.md (see lines 91-106).

Method 2: Using the Built-in /orchestrate Command


# In Claude chat

/orchestrate plan   # runs planner → tdd-guide → code-reviewer → security-reviewer

The orchestrate command chains agents automatically. The security-reviewer appears last in the default sequence, ensuring security validation occurs only after functional completeness (see agent order in commands/orchestrate.md, lines 14-18).

Method 3: Running Security Tools Directly for CI


# From a terminal inside the repo

npm run security:check   # defined in agents/security-reviewer.md

The security:check script bundles npm audit with eslint --plugin security, mirroring the automated portion of the agent's initial scan (see "Security Tools Installation", lines 81-95).

Key Configuration Files

Understanding these files helps you customize the security-reviewer behavior:

  • agents/security-reviewer.md – Full agent definition with workflow, checklists, and report template (lines 2-3 define the agent scope).

  • rules/security.md – Mandatory pre-commit security checks that trigger the agent automatically (lines 5-12).

  • commands/orchestrate.md – Orchestration command incorporating security-reviewer into multi-agent pipelines (lines 14-18 for agent sequence, lines 91-106 for hand-off mechanics).

  • README.md – Overview of all agents including the security-reviewer (line 99).

  • WORLDFLOWAI.md – Quick reference table of agents and responsibilities (agents table section).

Summary

  • Invoke via HANDOFF: for targeted security reviews on specific code changes.
  • Use /orchestrate plan for full development lifecycle coverage with security as final gate.
  • Run npm run security:check in CI for automated, tool-based scanning without LLM overhead.
  • Review agents/security-reviewer.md for complete checklist customization and report templates.
  • Configure rules/security.md to enforce mandatory pre-commit security triggers.

Frequently Asked Questions

How does the security-reviewer agent detect secrets and credentials?

The agent runs trufflehog and custom grep patterns during its initial scan phase (lines 23-49 in agents/security-reviewer.md). These tools scan for high-entropy strings, known API key patterns, and common secret formats before the OWASP analysis begins.

Can I customize the security checklist for my specific domain?

Yes. The project-specific checks section (lines 28-71) is designed for extension. Financial, blockchain, authentication, and database security items are templates you can modify to match your application's threat model and compliance requirements.

What model does the security-reviewer agent use?

The agent is model-agnostic and defaults to opus. You can override this in your Claude Code configuration if your organization requires different model assignments for cost or latency reasons.

Why does the orchestrate command run security-reviewer last?

The agent sequence in commands/orchestrate.md (lines 14-18) orders: planner → tdd-guide → code-reviewer → security-reviewer. This ensures security analysis evaluates final, reviewed code rather than incomplete drafts, reducing false positives and redundant security work.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →