Team Sicherheit · v3.1.0
Security Review Board
Vier Reviewer, die miteinander streiten, damit Angreifer es nicht müssen.
A review-only team that never writes features. Point it at a PR, a service or a whole repository: the Threat Modeler maps the surface, the AppSec Reviewer reads the code, the Supply-Chain Auditor reads the lockfile, and the Chair writes a report your CISO can sign.
Findings come with severity, exploit scenario and a proposed patch, never with a lecture.
Agenten 4
- 01Threat ModelerAssets, trust boundaries, abuse cases.
- 02AppSec ReviewerInjection, authz, crypto, secrets in code.
- 03Supply-Chain AuditorDependencies, lockfiles, CI permissions.
- 04Review ChairConsolidates findings into a signed report.
Skills 7
- 01OWASP Top 10Detection patterns and fixes per category.
- 02Secrets HygieneDetection, rotation, prevention hooks.
- 03Dependency AuditAdvisories, pinning, provenance.
- 04AuthZ PatternsRBAC, ABAC, tenant isolation checks.
- 05Crypto ReviewAlgorithms, key management, TLS config.
- 06CI HardeningLeast privilege for pipelines and tokens.
- 07Report WritingSeverity rubric and executive summary.
Workflows 2
- README.mdsetup, roles, conventions
- LICENSEHIRRE commercial license
- install.shcopies .claude/ into your repo
- .claude/
- agents/
- threat-modeler.mdAssets, trust boundaries, abuse cases.
- appsec-reviewer.mdInjection, authz, crypto, secrets in code.
- supply-chain-auditor.mdDependencies, lockfiles, CI permissions.
- review-chair.mdConsolidates findings into a signed report.
- skills/
- owasp-top-10/
- SKILL.mdDetection patterns and fixes per category.
- secrets-hygiene/
- SKILL.mdDetection, rotation, prevention hooks.
- dependency-audit/
- SKILL.mdAdvisories, pinning, provenance.
- authz-patterns/
- SKILL.mdRBAC, ABAC, tenant isolation checks.
- crypto-review/
- SKILL.mdAlgorithms, key management, TLS config.
- ci-hardening/
- SKILL.mdLeast privilege for pipelines and tokens.
- report-writing/
- SKILL.mdSeverity rubric and executive summary.
- settings.jsonpermissions, hooks, defaults
- workflows/
- pr-review.md
- repo-audit.md
Installation
unzip security-review-board-3.1.0.zip && ./security-review-board/install.sh- v3.1.028. Aug. 2026
- Supply-chain auditor reads GitHub Actions permissions.
- v3.0.030. Mai 2026
- Report format aligned with CVSS 4.0.
149 €einmalig
→ Kollegen
Ebenfalls einstellenswert
Full-Stack Squad
Acht Spezialisten, die ein Ticket von der Spec bis zum Release bringen, ohne dass du babysitten musst.
SaaS Launch Crew
Auth, Billing, Onboarding und E-Mail — die langweiligen 80 % eines SaaS, richtig gemacht.
Data Platform Team
Pipelines, Modelle, Qualitätschecks und Dashboards, die zueinander passen.