Equipo Seguridad · v3.1.0
Security Review Board
Cuatro revisores que discuten entre ellos para que los atacantes no tengan que hacerlo.
A review-only team that never writes features. Point it at a PR, a service or a whole repository: the Threat Modeler maps the surface, the AppSec Reviewer reads the code, the Supply-Chain Auditor reads the lockfile, and the Chair writes a report your CISO can sign.
Findings come with severity, exploit scenario and a proposed patch, never with a lecture.
Agentes 4
- 01Threat ModelerAssets, trust boundaries, abuse cases.
- 02AppSec ReviewerInjection, authz, crypto, secrets in code.
- 03Supply-Chain AuditorDependencies, lockfiles, CI permissions.
- 04Review ChairConsolidates findings into a signed report.
Skills 7
- 01OWASP Top 10Detection patterns and fixes per category.
- 02Secrets HygieneDetection, rotation, prevention hooks.
- 03Dependency AuditAdvisories, pinning, provenance.
- 04AuthZ PatternsRBAC, ABAC, tenant isolation checks.
- 05Crypto ReviewAlgorithms, key management, TLS config.
- 06CI HardeningLeast privilege for pipelines and tokens.
- 07Report WritingSeverity rubric and executive summary.
Workflows 2
- README.mdsetup, roles, conventions
- LICENSEHIRRE commercial license
- install.shcopies .claude/ into your repo
- .claude/
- agents/
- threat-modeler.mdAssets, trust boundaries, abuse cases.
- appsec-reviewer.mdInjection, authz, crypto, secrets in code.
- supply-chain-auditor.mdDependencies, lockfiles, CI permissions.
- review-chair.mdConsolidates findings into a signed report.
- skills/
- owasp-top-10/
- SKILL.mdDetection patterns and fixes per category.
- secrets-hygiene/
- SKILL.mdDetection, rotation, prevention hooks.
- dependency-audit/
- SKILL.mdAdvisories, pinning, provenance.
- authz-patterns/
- SKILL.mdRBAC, ABAC, tenant isolation checks.
- crypto-review/
- SKILL.mdAlgorithms, key management, TLS config.
- ci-hardening/
- SKILL.mdLeast privilege for pipelines and tokens.
- report-writing/
- SKILL.mdSeverity rubric and executive summary.
- settings.jsonpermissions, hooks, defaults
- workflows/
- pr-review.md
- repo-audit.md
Instalar
unzip security-review-board-3.1.0.zip && ./security-review-board/install.sh- v3.1.028 ago 2026
- Supply-chain auditor reads GitHub Actions permissions.
- v3.0.030 may 2026
- Report format aligned with CVSS 4.0.
149 €pago único
→ Compañeros
También merece la pena contratar
Full-Stack Squad
Ocho especialistas que llevan un ticket de la especificación al release sin que tengas que vigilarlos.
SaaS Launch Crew
Auth, facturación, onboarding y email: el 80 % aburrido de un SaaS, bien hecho.
Data Platform Team
Pipelines, modelos, controles de calidad y dashboards que coinciden entre sí.