Automation & Ops ✓ OpenAI · Official security-reviewsecure-codingvulnerability-reportingpython-securityjavascript-securitytypescript-securitygo-security

Security Best Practices Review

Security review and secure-by-default guidance for Python, JavaScript/TypeScript, and Go projects.

FollowSkills review · FSRS-2.0
Not recommended
52/ 100 5-point scale 2.6 / 5
Trust17 / 25 · 3.4/5

The skill clearly restricts triggering, supported languages, secret handling, disabling protections, and evidence-based findings. However, it permits online searching when references are missing, and its file-writing, fix workflow, external-data boundaries, and rollback expectations are not fully specified, so points are deducted.

Reliability8 / 20 · 2.0/5

SKILL.md, the agent metadata, and the supplied reference specs are broadly consistent and define workflows, decision logic, report structure, and abnormal cases. Still, key behavior depends on an unshown references directory and model knowledge fallback; static evidence cannot reproduce the key paths, so the score is conservatively limited and reduced.

Adaptability10 / 15 · 3.3/5

Trigger conditions, exclusions, and supported Python, JavaScript/TypeScript, and Go scenarios are fairly clear, with generation, passive review, and active audit modes. Input/output contracts, non-fit boundaries, Chinese-language support, and mainland-China reachability are not established, and core fallback research may depend on overseas services, so points are deducted.

Convention8 / 15 · 2.7/5

The material is layered into overview, workflow, decision tree, report format, fixes, and general advice, and agent metadata is present. License, version, changelog, maintenance ownership, update path, and complete installation/reference prerequisites are not documented in the supplied skill evidence, so points are deducted.

Effectiveness6 / 15 · 2.0/5

The skill can guide secure coding, identify issues during editing, and produce structured reports; the references contain actionable rules and remediation patterns. However, output quality depends on the target repository, complete reference coverage, and reviewer judgment, with no statically verifiable representative outputs, so the score remains below the static ceiling.

Verifiability3 / 10 · 1.5/5

Rule IDs, detection hints, evidence requirements, and remediation formats provide some audit traceability. There are no committed tests, CI execution artifacts, or independent reproduction materials, and the supplied external citations are not directly verifiable here, so only a low score is justified.

Evidence confidence:Low Reviewed Jul 20, 2026 Reviewed revision 49f948faa925
Before you use it
  • Core guidance depends on the references directory, which is not fully supplied; verify all relevant files in the actual package.
  • The fallback permits online searching; verify network reachability, source trustworthiness, and that sensitive code is not sent to external services.
  • Report path, permissions, overwrite behavior, and post-fix testing or rollback procedures are unspecified.
  • License, versioning, changelog, and maintenance/update ownership are not documented.
Review evidence [1][2][3][4][5][6][7]
See the full review method →

What it does & when to use it

This skill is intended for explicit requests involving security best-practice guidance, security reviews, reports, or secure-by-default coding. It supports Python, JavaScript/TypeScript, and Go, and identifies the languages and primary frameworks in scope. It reads matching reference material to guide secure code, passive detection of major issues, or prioritized vulnerability reports. It comes from the deprecated openai/skills catalog, whose README points current examples to the OpenAI Plugins repository.

Identifies all relevant languages and primary frameworks; reads matching security documents from the skill's references directory; uses that guidance to write secure-by-default code or passively flag major vulnerabilities; produces reports with an executive summary, numbered findings, severity, urgency, impact statements, and code line numbers when requested; proposes fixes one finding at a time.

  1. A Python developer requests secure-by-default guidance for a backend service.
  2. A JavaScript or TypeScript team wants a security review and prioritized vulnerability report.
  3. A Go service maintainer wants major security issues identified with suggested fixes.
  4. A full-stack project needs security guidance checked for both its frontend and backend.
  5. A team wants high-impact security issues flagged passively while code is being developed.

Pros & cons

Pros
  • Clear supported-language and activation scope.
  • Can address both frontend and backend frameworks.
  • Supports secure-by-default coding, passive vulnerability detection, and formal reports.
  • Report requirements include severity, priority, identifiers, and code line numbers for easier tracking.
Limitations
  • Limited to Python, JavaScript/TypeScript, and Go.
  • The supplied material does not include the references directory, so framework coverage cannot be confirmed.
  • No test suite or validation results are provided.
  • The repository is deprecated, and the individual skill license file was not supplied.

How to install

The README says curated skills can be installed in Codex with $skill-installer security-best-practices, followed by a Codex restart. The repository is deprecated, and the README recommends the OpenAI Plugins repository for current skill and plugin examples. Further installation details are not provided in the source material.

How to use

Make an explicit security request, such as “review this Python project against security best practices and produce a report” or “help me write this TypeScript code securely by default.” The skill is limited to Python, JavaScript/TypeScript, and Go; it should not trigger for general code review, debugging, or non-security tasks.

Compared to similar skills

The README names the OpenAI Plugins repository as the current source for Codex skill and plugin examples. No other functional alternative is named in the source material.

FAQ

Is this intended for general code review?
No. It should trigger only for explicit security best-practice, security-review, security-report, or secure-by-default coding requests.
Which languages are supported?
Python, JavaScript/TypeScript, and Go.
Does installation require a restart?
Yes. The README says to restart Codex after installing a skill so it can be picked up.
Will missing TLS or HSTS always be reported as security issues?
No. The source specifically cautions against automatically reporting missing TLS in development and against casually recommending Secure cookies or HSTS without considering deployment context.

More skills from this repository

All from openai/skills

Productivity & Collaboration ✓ OpenAI · Official

Goal Definition Assistant

Turn vague intentions into measurable, verifiable goals with clear scope and stopping conditions.

Dev & Engineering ✓ OpenAI · Official

Codex CLI Builder

Turn APIs, scripts, and existing tools into durable, composable command-line interfaces.

Design & Frontend ✓ OpenAI · Official

Codex Image Studio

Generate and edit production-ready raster assets for projects.

Dev & Engineering ✓ OpenAI · Official

OpenAI Developer Docs Assistant

Current, official guidance for building with OpenAI products, APIs, and Codex.

Dev & Engineering ✓ OpenAI · Official

Skill Creator Guide

A practical guide to designing, writing, validating, and iterating reusable Codex skills.

Dev & Engineering ✓ OpenAI · Official

ASP.NET Core Engineering Guide

Guides developers through building, reviewing, and upgrading ASP.NET Core apps.

Dev & Engineering ✓ OpenAI · Official

ChatGPT Apps Builder

Build documented ChatGPT apps that pair an MCP server with a widget UI.

Design & Frontend ✓ OpenAI · Official

Figma Code Connect Mapper

Link Figma components to their code implementations for traceable design-code consistency.

Design & Frontend ✓ OpenAI · Official

Figma Blank File Creator

Create a blank Figma Design or FigJam file in the selected drafts folder.

Design & Frontend ✓ OpenAI · Official

Figma Design Implementer

Turn Figma specifications into production-ready frontend code with verifiable visual fidelity.

Dev & Engineering ✓ OpenAI · Official

Playwright Browser Automation Skill

Drive a real browser from the terminal for web interaction, extraction, and UI debugging.

Design & Frontend ✓ OpenAI · Official

Hatch Pet Animation Workshop

Turn character or brand cues into validated, packageable Codex animated pets.

Productivity & Collaboration ✓ OpenAI · Official

Linear Workflow Manager

Manage Linear tickets, projects, and team workflows directly through Codex.

Automation & Ops ✓ OpenAI · Official

Repository Threat Modeler

Builds evidence-grounded, actionable AppSec threat models for code repositories.

Automation & Ops ✓ OpenAI · Official

Sentry Production Error Explorer

Inspect Sentry issues, events, and basic production health through the Sentry CLI.

Design & Frontend ✓ OpenAI · Official

Figma Design System Rules Builder

Generates project-specific rules for consistent Figma-to-code implementation.

Writing & Content ✓ OpenAI · Official

Audio Transcribe

Turn audio or video speech into text with optional speaker labels.

Design & Frontend ✓ OpenAI · Official

Figma Design System Builder

Build and validate a professional Figma design system from code.

Design & Frontend ✓ OpenAI · Official

Figma Design-to-Code Assistant

Fetch Figma design context and turn selected nodes into production code.

Data & Analysis ✓ OpenAI · Official

Jupyter Notebook Workflow Assistant

Create, refactor, and validate reproducible Jupyter notebooks with templates and a scaffold script.

Related skills