aboutsummaryrefslogtreecommitdiffstats
path: root/modules/development/pi-coding-agent/skills/security-review/SKILL.md
diff options
context:
space:
mode:
authorArpit Chakladar <arpit@chakladar.me>2026-09-29 23:45:25 +0530
committerArpit Chakladar <arpit@chakladar.me>2026-09-29 23:45:25 +0530
commit33519df0fff478526d217d04190577b33c5bf7d0 (patch)
tree18f6ee9bb8101381212038d16099e59d250b7080 /modules/development/pi-coding-agent/skills/security-review/SKILL.md
parent7975de6d03289bcc143137d5458486def5adc672 (diff)
parent871a29efd370088f669c4f2b9e20b8992406a444 (diff)
downloadhome-manager-config-33519df0fff478526d217d04190577b33c5bf7d0.tar.gz
home-manager-config-33519df0fff478526d217d04190577b33c5bf7d0.zip
Merge branch 'adding-pi-harness'
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review/SKILL.md')
-rw-r--r--modules/development/pi-coding-agent/skills/security-review/SKILL.md57
1 files changed, 57 insertions, 0 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
new file mode 100644
index 0000000..3f534ab
--- /dev/null
+++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
@@ -0,0 +1,57 @@
+---
+name: security-review
+description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc."
+---
+
+# Security Review Skill
+
+Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc.
+
+## Subagents
+When you need to delegate sub‑tasks, use the `pi-subagents` skill.
+
+**Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel.
+
+*You may adapt the delegation pattern to fit the exact requirements of the codebase.*
+
+## Checklist
+
+### Secrets & Credentials
+- [ ] No hardcoded secrets
+- [ ] No keys in config files
+- [ ] Environment variables used properly
+
+### Injection
+- [ ] SQL injection prevention
+- [ ] Command injection prevention
+- [ ] XSS prevention
+
+### Shell Execution
+- [ ] No unsanitized user input in shell
+- [ ] Use exec over shell when possible
+- [ ] Validate and escape inputs
+
+### Auth/Authz
+- [ ] Proper authentication checks
+- [ ] Authorization on all endpoints
+- [ ] No broken access control
+
+### Dependencies
+- [ ] Known vulnerabilities checked
+- [ ] Minimal dependency surface
+- [ ] Lockfiles maintained
+
+### Path Traversal
+- [ ] Input validation on file paths
+- [ ] Canonical path resolution
+- [ ] Sandboxed file operations
+
+### SSRF
+- [ ] URL validation
+- [ ] Internal network blocking
+- [ ] Allowlist for external calls
+
+### Insecure Defaults
+- [ ] Secure defaults enabled
+- [ ] Debug endpoints disabled
+- [ ] Proper CORS configuration