cd /news/ai-tools/dedicated-security-review-command-no… · home topics ai-tools article
[ARTICLE · art-24079] src=github.blog ↗ pub= topic=ai-tools verified=true sentiment=↑ positive

Dedicated security review command now available in Copilot CLI

GitHub has released a new experimental `/security-review` slash command for Copilot CLI, now available in public preview, that analyzes local code changes for security vulnerabilities such as injection flaws and cross-site scripting. The command provides high-confidence findings with severity scores and actionable suggestions directly in the terminal, complementing existing tools like GitHub code scanning and Dependabot. Users must enable experimental mode in Copilot CLI to access the feature.

read1 min publishedJun 10, 2026

You can now run a security review on your code changes directly from GitHub Copilot CLI. The new /security-review

slash command is shipping as an experimental feature in public preview, giving you a fast, AI-driven way to catch security vulnerabilities before they reach production code.

What it does /security-review

analyzes your local code changes and returns:

  • High-confidence security findings, scored by severity and confidence.
  • Actionable suggestions you can apply without leaving the terminal.
  • A focused review that lives in your existing workflow.

The scan is tuned to flag common, high-impact vulnerability classes such as injection flaws, cross-site scripting, insecure data handling, path traversal, and weak cryptography.

This is a Copilot-driven scan that doesn’t rely on GitHub code scanning, Dependabot, or GitHub secret scanning. It complements those tools by giving you a lightweight, on-demand way to review your changes before you commit.

This is an experimental command. To try it, turn on experimental mode in Copilot CLI, then run /security-review

in any project to scan your current changes.

Join the discussion and share your feedback within the GitHub Community.

── more in #ai-tools 4 stories · sorted by recency
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/dedicated-security-r…] indexed:0 read:1min 2026-06-10 ·