diff options
| author | Arpit Chakladar <arpit@chakladar.me> | 2026-09-29 23:45:25 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpit@chakladar.me> | 2026-09-29 23:45:25 +0530 |
| commit | 33519df0fff478526d217d04190577b33c5bf7d0 (patch) | |
| tree | 18f6ee9bb8101381212038d16099e59d250b7080 /modules/development/pi-coding-agent/skills/security-review | |
| parent | 7975de6d03289bcc143137d5458486def5adc672 (diff) | |
| parent | 871a29efd370088f669c4f2b9e20b8992406a444 (diff) | |
| download | home-manager-config-33519df0fff478526d217d04190577b33c5bf7d0.tar.gz home-manager-config-33519df0fff478526d217d04190577b33c5bf7d0.zip | |
Merge branch 'adding-pi-harness'
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review')
| -rw-r--r-- | modules/development/pi-coding-agent/skills/security-review/SKILL.md | 57 |
1 files changed, 57 insertions, 0 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md new file mode 100644 index 0000000..3f534ab --- /dev/null +++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md @@ -0,0 +1,57 @@ +--- +name: security-review +description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc." +--- + +# Security Review Skill + +Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc. + +## Subagents +When you need to delegate sub‑tasks, use the `pi-subagents` skill. + +**Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel. + +*You may adapt the delegation pattern to fit the exact requirements of the codebase.* + +## Checklist + +### Secrets & Credentials +- [ ] No hardcoded secrets +- [ ] No keys in config files +- [ ] Environment variables used properly + +### Injection +- [ ] SQL injection prevention +- [ ] Command injection prevention +- [ ] XSS prevention + +### Shell Execution +- [ ] No unsanitized user input in shell +- [ ] Use exec over shell when possible +- [ ] Validate and escape inputs + +### Auth/Authz +- [ ] Proper authentication checks +- [ ] Authorization on all endpoints +- [ ] No broken access control + +### Dependencies +- [ ] Known vulnerabilities checked +- [ ] Minimal dependency surface +- [ ] Lockfiles maintained + +### Path Traversal +- [ ] Input validation on file paths +- [ ] Canonical path resolution +- [ ] Sandboxed file operations + +### SSRF +- [ ] URL validation +- [ ] Internal network blocking +- [ ] Allowlist for external calls + +### Insecure Defaults +- [ ] Secure defaults enabled +- [ ] Debug endpoints disabled +- [ ] Proper CORS configuration |
