Security Reviewer by affaan-m
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication…
- Type
- Subagent
- Repository
- affaan-m/ECC
- GitHub stars
- 268k
- License
- MIT
- Repo last updated
- Sep 24, 2026
What Security Reviewer by affaan-m is
Security Reviewer by affaan-m is a subagent published in the affaan-m/ECC repository on GitHub, which has about 268k stars. The repository describes itself as: “The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Security Reviewer and get back a compact result.
How to install Security Reviewer by affaan-m
Claude Code
- Download security-reviewer-2.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
We couldn't retrieve the source file for this entry. Browse the repository on GitHub to find it and read the README before installing.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Security Reviewer by affaan-m?
Security Reviewer by affaan-m is a subagent for Claude Code and Claude Cowork from the affaan-m/ECC repository on GitHub. Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication…
How do I install Security Reviewer by affaan-m in Claude Code?
Download security-reviewer-2.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Security Reviewer by affaan-m in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Security Reviewer by affaan-m safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Go Build Resolver Go build, vet, and compilation error resolution specialist. Fixes build errors, go vet issues, and linter warnings with minimal changes. Use when Go builds fail. Subagent · affaan-m/ECC
- Gan Generator GAN Harness — Generator agent. Implements features according to the spec, reads evaluator feedback, and iterates until quality threshold is met. Subagent · affaan-m/ECC
- Harmonyos App Resolver HarmonyOS application development expert specializing in ArkTS and ArkUI. Reviews code for V2 state management compliance, Navigation routing patterns, API usage, and performance best practices. Use for HarmonyOS/OpenHarmony projects. Subagent · affaan-m/ECC
- Go Reviewer Expert Go code reviewer specializing in idiomatic Go, concurrency patterns, error handling, and performance. Use for all Go code changes. MUST BE USED for Go projects. Subagent · affaan-m/ECC
- Seo Specialist SEO specialist for technical SEO audits, on-page optimization, structured data, Core Web Vitals, and content/keyword mapping. Use for site… Subagent · affaan-m/ECC
- Rust Reviewer Expert Rust code reviewer specializing in ownership, lifetimes, error handling, unsafe usage, and idiomatic patterns. Use for all Rust code changes. MUST BE USED for Rust projects. Subagent · affaan-m/ECC
- Silent Failure Hunter Review code for silent failures, swallowed errors, bad fallbacks, and missing error propagation. Subagent · affaan-m/ECC
- Rust Build Resolver Rust build, compilation, and dependency error resolution specialist. Fixes cargo build errors, borrow checker issues, and Cargo.toml problems with minimal changes. Use when Rust builds fail. Subagent · affaan-m/ECC