diff options
| author | Arpit Chakladar <arpitchakladar@gmail.com> | 2026-09-27 06:08:52 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpit@chakladar.me> | 2026-09-29 23:42:32 +0530 |
| commit | 0c4f95c8106e77abcbdd94917c4b7cf3c7a3c63f (patch) | |
| tree | 7889d93ac9461b91ad4b0dbc137cc72eff4a8dd6 /modules/development/pi-coding-agent/skills/security-review/SKILL.md | |
| parent | a693ec73036cfe4c3aafb49bebd4480bcc1bc9ab (diff) | |
| download | home-manager-config-0c4f95c8106e77abcbdd94917c4b7cf3c7a3c63f.tar.gz home-manager-config-0c4f95c8106e77abcbdd94917c4b7cf3c7a3c63f.zip | |
feat(development/pi-coding-agent): added custom skills
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review/SKILL.md')
| -rw-r--r-- | modules/development/pi-coding-agent/skills/security-review/SKILL.md | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md new file mode 100644 index 0000000..0b2d307 --- /dev/null +++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md @@ -0,0 +1,50 @@ +--- +name: security-review +description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc." +--- + +# Security Review Skill + +Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc. + +## Checklist + +### Secrets & Credentials +- [ ] No hardcoded secrets +- [ ] No keys in config files +- [ ] Environment variables used properly + +### Injection +- [ ] SQL injection prevention +- [ ] Command injection prevention +- [ ] XSS prevention + +### Shell Execution +- [ ] No unsanitized user input in shell +- [ ] Use exec over shell when possible +- [ ] Validate and escape inputs + +### Auth/Authz +- [ ] Proper authentication checks +- [ ] Authorization on all endpoints +- [ ] No broken access control + +### Dependencies +- [ ] Known vulnerabilities checked +- [ ] Minimal dependency surface +- [ ] Lockfiles maintained + +### Path Traversal +- [ ] Input validation on file paths +- [ ] Canonical path resolution +- [ ] Sandboxed file operations + +### SSRF +- [ ] URL validation +- [ ] Internal network blocking +- [ ] Allowlist for external calls + +### Insecure Defaults +- [ ] Secure defaults enabled +- [ ] Debug endpoints disabled +- [ ] Proper CORS configuration
\ No newline at end of file |
