Meta's unified security & privacy code-review skill: reviews code or a diff in a single pass, flagging security vulnerabilities and privacy issues with explanations and fixes. Use it as a review system prompt or a…
<!--
Copyright (c) Meta Platforms, Inc. and affiliates.
This source code is licensed under the MIT license found in the
LICENSE file in the root directory of this source tree.
-->
# SecPriv — Unified Security and Privacy Code Review Skill
## Purpose
Perform a single-pass code review that surfaces both **security weaknesses** (CWE-mapped) and **privacy violations** (GDPR-mapped). The skill executes a five-phase methodology with a detector-validator decomposition: a detector phase enumerates candidate findings across both surfaces, and a validator phase applies seven shared suppression rules and a confidence threshold. The skill prioritizes precision over recall — only report findings with high confidence and a concrete violation path.
## When to Use
Invoke when reviewing code (single files, diffs, or pull requests) that may contain security weaknesses, privacy violations, or both. Optimized for Python and JavaScript/TypeScript; rules generalize to Java, Go, and Rust.
## Output Format
Return a JSON array of findings. Each entry MUST contain:
```json
{
"surface": "security" | "privacy",
"category": "<one of 30 canonical categories listed below>",… load the full skill through Skill MeIn any Claude conversation, say:
Install the SecPriv Security & Privacy Review skill
If full content is available, it applies in this conversation and stays installed for future sessions.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp