diff options
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review')
| -rw-r--r-- | modules/development/pi-coding-agent/skills/security-review/SKILL.md | 57 |
1 files changed, 57 insertions, 0 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md new file mode 100644 index 0000000..3f534ab --- /dev/null +++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md @@ -0,0 +1,57 @@ +--- +name: security-review +description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc." +--- + +# Security Review Skill + +Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc. + +## Subagents +When you need to delegate sub‑tasks, use the `pi-subagents` skill. + +**Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel. + +*You may adapt the delegation pattern to fit the exact requirements of the codebase.* + +## Checklist + +### Secrets & Credentials +- [ ] No hardcoded secrets +- [ ] No keys in config files +- [ ] Environment variables used properly + +### Injection +- [ ] SQL injection prevention +- [ ] Command injection prevention +- [ ] XSS prevention + +### Shell Execution +- [ ] No unsanitized user input in shell +- [ ] Use exec over shell when possible +- [ ] Validate and escape inputs + +### Auth/Authz +- [ ] Proper authentication checks +- [ ] Authorization on all endpoints +- [ ] No broken access control + +### Dependencies +- [ ] Known vulnerabilities checked +- [ ] Minimal dependency surface +- [ ] Lockfiles maintained + +### Path Traversal +- [ ] Input validation on file paths +- [ ] Canonical path resolution +- [ ] Sandboxed file operations + +### SSRF +- [ ] URL validation +- [ ] Internal network blocking +- [ ] Allowlist for external calls + +### Insecure Defaults +- [ ] Secure defaults enabled +- [ ] Debug endpoints disabled +- [ ] Proper CORS configuration |
