Skill / OpenAI

Security Best Practices Codex Skill

Perform language and framework specific security best-practice reviews and suggest improvements.

Docs reviewedChecked 2026-09-20Runtime not tested

What it adds

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

security

Get set up

  1. Ask Codex to install the skill with the built-in skill installer, pointing it at the source below.
  2. Start a new thread so Codex picks up the skill.
$skill-installer security-best-practices
Review before running
Read the installation source

Before you install

    Compatibility & limitations

    Documented for ChatGPT desktop app, Codex CLI, Codex IDE extension

    Cursor: Not confirmed for Cursor.

      This listing is based on source documentation. We have not installed or runtime-tested this asset.

      How it fits together

      Security Ownership Map · SkillAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export...Security Threat Model · SkillRepository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a...Codex Security · PluginSecurity scanning for your codebase.SonarQube · MCP serverOfficial SonarQube MCP Server for code quality and security in AI agents.

      Sources & provenance

      Reviewed 2026-09-20. Source revision: main (mutable; commit not pinned).