cyberneticlibrary

Review security and secrets in PRs

sv-security-reviewersubagentsetup L11,223
sceneview/sceneview
What it does

Review code diffs for security vulnerabilities

Best for

Pre-merge security gate for open-source projects shipping to app stores

Inputs
  • · git diff main...HEAD
  • · uncommitted changes
Outputs
  • · Security verdict (PASS/FAIL/PASS_WITH_WARNINGS)
  • · findings with file:line and severity
Preconditions

Open-source SDK context; Play/App store publishing scope

Failure modes
  • · Inventing findings without evidence
  • · Overlapping with other security reviewers
Trust signals
  • · Hard checks list (blocks merge)
  • · Read-only (never edits or pushes)