← ClaudeAtlas

review-securitylisted

Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.
gtrabanco/agentic-workflow · ★ 21 · AI & Automation · score 78
Install: claude install-skill gtrabanco/agentic-workflow
# Review Security (internal) Composed by `review-change` / `product-audit` within their conversation — on any agent, follow this file inline as the routed step. **Findings only; never edits, never refactors.** ## Scope The diff or path/glob the caller passes; default the current change vs the default branch. State the scope at the top of the returned table. ## Checklist (evaluate EVERY item — none is optional; n/a must be stated) ✓ No secrets/credentials/tokens in code, config, tests, or fixtures (grep the diff for key-like strings) ✓ Every external input on the changed paths is validated/sanitized before use ✓ No injection vectors (SQL/command/path/template) — parameterized/escaped, never concatenated ✓ AuthN/AuthZ enforced on every new/changed endpoint or entry point (cite where) ✓ No PII or secrets written to logs/error messages on the changed paths ✓ Webhooks/callbacks verify signatures before processing ✓ Rate limiting / abuse controls considered where a new public surface appears (n/a if none) ✓ New/updated dependencies pinned and free of known-critical advisories (state how you checked) ✓ Error responses don't leak stack traces or internal paths ✓ Unsafe deserialization / dynamic evaluation of untrusted data absent ## Return exactly ``` REVIEW SECURITY — scope: <scope> | # | Finding | Sev | Evidence | Suggested fix | |---|---------|-----|----------|---------------| | 1 | <what> | critical|major|minor | <file:line> | <smallest action> | Checklist: <n