aboutsummaryrefslogtreecommitdiffstats
path: root/modules/development/pi-coding-agent/skills/security-review
diff options
context:
space:
mode:
authorArpit Chakladar <arpitchakladar@gmail.com>2026-09-27 06:08:52 +0530
committerArpit Chakladar <arpit@chakladar.me>2026-09-29 23:42:32 +0530
commit0c4f95c8106e77abcbdd94917c4b7cf3c7a3c63f (patch)
tree7889d93ac9461b91ad4b0dbc137cc72eff4a8dd6 /modules/development/pi-coding-agent/skills/security-review
parenta693ec73036cfe4c3aafb49bebd4480bcc1bc9ab (diff)
downloadhome-manager-config-0c4f95c8106e77abcbdd94917c4b7cf3c7a3c63f.tar.gz
home-manager-config-0c4f95c8106e77abcbdd94917c4b7cf3c7a3c63f.zip
feat(development/pi-coding-agent): added custom skills
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review')
-rw-r--r--modules/development/pi-coding-agent/skills/security-review/SKILL.md50
1 files changed, 50 insertions, 0 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
new file mode 100644
index 0000000..0b2d307
--- /dev/null
+++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
@@ -0,0 +1,50 @@
+---
+name: security-review
+description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc."
+---
+
+# Security Review Skill
+
+Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc.
+
+## Checklist
+
+### Secrets & Credentials
+- [ ] No hardcoded secrets
+- [ ] No keys in config files
+- [ ] Environment variables used properly
+
+### Injection
+- [ ] SQL injection prevention
+- [ ] Command injection prevention
+- [ ] XSS prevention
+
+### Shell Execution
+- [ ] No unsanitized user input in shell
+- [ ] Use exec over shell when possible
+- [ ] Validate and escape inputs
+
+### Auth/Authz
+- [ ] Proper authentication checks
+- [ ] Authorization on all endpoints
+- [ ] No broken access control
+
+### Dependencies
+- [ ] Known vulnerabilities checked
+- [ ] Minimal dependency surface
+- [ ] Lockfiles maintained
+
+### Path Traversal
+- [ ] Input validation on file paths
+- [ ] Canonical path resolution
+- [ ] Sandboxed file operations
+
+### SSRF
+- [ ] URL validation
+- [ ] Internal network blocking
+- [ ] Allowlist for external calls
+
+### Insecure Defaults
+- [ ] Secure defaults enabled
+- [ ] Debug endpoints disabled
+- [ ] Proper CORS configuration \ No newline at end of file