Security Best Practices Codex Skill
Perform language and framework specific security best-practice reviews and suggest improvements.
What it adds
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
security
Get set up
- Ask Codex to install the skill with the built-in skill installer, pointing it at the source below.
- Start a new thread so Codex picks up the skill.
$skill-installer security-best-practicesReview before running
Before you install
Compatibility & limitations
Documented for ChatGPT desktop app, Codex CLI, Codex IDE extension
Cursor: Not confirmed for Cursor.
This listing is based on source documentation. We have not installed or runtime-tested this asset.
How it fits together
Security Ownership Map · SkillAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export...Security Threat Model · SkillRepository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a...Codex Security · PluginSecurity scanning for your codebase.SonarQube · MCP serverOfficial SonarQube MCP Server for code quality and security in AI agents.Sources & provenance
Reviewed 2026-09-20. Source revision: main (mutable; commit not pinned).