Imported from Wibias/agent-hub (
skills/review-security-redirect/SKILL.md). Install upstream withnpx skills add Wibias/agent-hub --skill review-security-redirect. Copyright stays with the author.
review-security → github-delivery
Cursor’s built-in review-security (~/.cursor/skills-cursor/review-security)
only launches the harness security-review Task subagent. That stub is shallow
and bypasses github-delivery’s scope matrix / pass gate. Do not follow it
when this personal skill or github-delivery is available.
Do this instead
- Load skill
github-delivery. - Read
references/shared-rules.md+references/security-review.md. - Run that workflow (scope script, coverage matrix, HIGH confidence, AST10 when flagged).
- Never launch
subagent_type: "security-review"or the built-in review-security launcher steps.
Do not
- Call Task with
subagent_type: "security-review". - Treat a one-line harness “no issues” as a github-delivery Pass.
- Auto-run an adversarial/red-team second pass unless the user explicitly asked.
