소개
This skill provides a comprehensive, research-driven framework for modern code reviews, integrating OWASP Top 10 security checks with advanced SAST tool analysis from SonarQube, CodeQL, and Snyk. It balances security, code quality, and performance by identifying vulnerabilities like SQL injection and XSS alongside complex performance bottlenecks such as N+1 queries. Designed for high-velocity DevSecOps environments, it helps teams implement 2025 best practices to achieve significantly faster vulnerability remediation and maintain high standards for maintainability and scalability.