aboutsummaryrefslogtreecommitdiffstats
path: root/modules/development/pi-coding-agent/skills/security-review/SKILL.md
diff options
context:
space:
mode:
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review/SKILL.md')
-rw-r--r--modules/development/pi-coding-agent/skills/security-review/SKILL.md9
1 files changed, 8 insertions, 1 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
index 0b2d307..3f534ab 100644
--- a/modules/development/pi-coding-agent/skills/security-review/SKILL.md
+++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
@@ -7,6 +7,13 @@ description: "Look for secrets, injection, unsafe shell execution, auth/authz mi
Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc.
+## Subagents
+When you need to delegate sub‑tasks, use the `pi-subagents` skill.
+
+**Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel.
+
+*You may adapt the delegation pattern to fit the exact requirements of the codebase.*
+
## Checklist
### Secrets & Credentials
@@ -47,4 +54,4 @@ Look for secrets, injection, unsafe shell execution, auth/authz mistakes, depend
### Insecure Defaults
- [ ] Secure defaults enabled
- [ ] Debug endpoints disabled
-- [ ] Proper CORS configuration \ No newline at end of file
+- [ ] Proper CORS configuration