coderabbit-security-basics
Installation
SKILL.md
CodeRabbit Security Controls
Overview
Use documented CodeRabbit Security and tools while retaining independent scanners and human review. AI findings cannot prove absence of vulnerabilities.
Prerequisites
- Identify the CodeRabbit organization, Git provider, repository, plan, and accountable owner.
- Read
references/official-docs.mdand re-check any time-sensitive contract before execution. - Use synthetic or read-only evidence until the approval boundary is satisfied.
- Preserve the repository's independent CI, security, and human-review requirements.
Current Contract
- CodeRabbit documents repo security scanning and security Change Stack views.
- The tool catalog includes static, secret, dependency, and infrastructure analyzers.
- CodeRabbit can ingest GitHub Checks.
- SkillSpector scans agent skills and MCP configuration.