security-review
FeaturedSecurity checklist for code changes with severity classification
AI & Automation 21 stars
4 forks Updated 6 days ago MIT
Install
Quality Score: 88/100
Stars 20%
Recency 20%
Frontmatter 20%
Documentation 15%
Issue Health 10%
License 10%
Description 5%
Skill Content
# Security Review
Systematic security checklist for code changes. Catch vulnerabilities before they ship.
## When to Use
- After writing authentication or authorization code
- After handling user input (forms, query params, file uploads)
- After creating or modifying API endpoints
- After touching secrets, tokens, or credentials
- Before any commit that touches security-sensitive code
## Procedure
### Step 1: Identify Scope
Determine which checks apply based on changed files:
- Auth code: full checklist
- API endpoints: input validation, injection, rate limiting
- Frontend: XSS, CSRF
- Config/infra: secrets, permissions
### Step 2: Run Checklist
| Check | Severity | What to Look For |
|-------|----------|------------------|
| Hardcoded secrets | CRITICAL | API keys, passwords, tokens in source |
| SQL injection | CRITICAL | String concatenation in queries |
| Auth bypass | CRITICAL | Missing auth checks on protected routes |
| XSS | HIGH | Unsanitized user input in HTML output |
| CSRF | HIGH | Missing CSRF tokens on state-changing requests |
| Input validation | HIGH | Unvalidated user input passed to logic |
| Rate limiting | MEDIUM | Endpoints without rate limits |
| Error leaks | MEDIUM | Stack traces or internal details in responses |
| Authz checks | HIGH | Missing permission verification |
| Dependency vulns | MEDIUM | Known CVEs in dependencies |
### Step 3: Scan Code
```bash
# Check for hardcoded secrets (patterns)
g...
Details
- Author
- mshadmanrahman
- Repository
- mshadmanrahman/pm-pilot
- Created
- 6 months ago
- Last Updated
- 6 days ago
- Language
- TypeScript
- License
- MIT
Integrates with
Similar Skills
Semantically similar based on skill content — not just same category
Code & Development Listed
security-review
Use when changes touch authentication, authorization, user input, file uploads, secrets, cryptography, dependencies, payments or personal data, or when asked for a security review or audit
0 Updated today
rkaliev AI & Automation Listed
security-review
Review code for the vulnerabilities that actually get exploited, ranked by real risk with concrete attack scenarios. Use when reviewing changes that touch input handling, auth, secrets, files, queries, or network calls.
8 Updated 2 weeks ago
Amey-Thakur Code & Development Listed
security-review
Use when reviewing changes for security — secrets, auth, injection, access control, and hardening. Triggers on "security review", "check for vulnerabilities", "安全审查", "安全审计", "漏洞检查".
3 Updated 1 weeks ago
int2t05