security-reviewlisted
Install: claude install-skill xsefirosus/sefi-agents
# Security Review
Gate skill backing the security-engineer. This body is the Rule block; the expanded
checklist lives in `references/security-checklist.md`, read on demand. Review the diff,
not the intentions.
User instructions always override this skill.
All factual output follows the anti-hallucination skill: cite file:line or mark UNKNOWN,
never guess.
agentic-signals: goal_intake, refusal_gate, verification, loop_discipline, close_out
(goal_intake's behavior: `skills/sefi-orchestration/references/goal-intake.md`;
refusal_gate's: `skills/sefi-orchestration/references/refusal-gate.md`; verification's:
`skills/sefi-orchestration/references/verification.md`; loop_discipline's:
`skills/sefi-orchestration/references/loop-discipline.md`; close_out's:
`skills/sefi-orchestration/references/close-out.md`)
## Rule block (every reviewed diff is checked against all six)
1. Secrets: no credential, token, key, or connection string in code, fixtures, logs, or
CI config -- placeholders only. Never open a secret-bearing file to verify it; name
the missing variable instead.
2. Injection: every input reaching a shell, SQL/query builder, template engine, parser,
or deserializer is validated or parameterized AT the trust boundary, not upstream of
it.
3. Unsafe constructs: eval/exec on external input, unpinned curl-to-shell installs,
YAML/pickle load on untrusted data, path traversal on user-supplied paths, disabled
TLS verification.
4. Dependencies: a new dependency is a