aboutsummaryrefslogtreecommitdiffstats
path: root/modules/development/pi-coding-agent/skills/security-review
diff options
context:
space:
mode:
Diffstat (limited to 'modules/development/pi-coding-agent/skills/security-review')
-rw-r--r--modules/development/pi-coding-agent/skills/security-review/SKILL.md57
1 files changed, 57 insertions, 0 deletions
diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
new file mode 100644
index 0000000..3f534ab
--- /dev/null
+++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md
@@ -0,0 +1,57 @@
+---
+name: security-review
+description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc."
+---
+
+# Security Review Skill
+
+Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc.
+
+## Subagents
+When you need to delegate sub‑tasks, use the `pi-subagents` skill.
+
+**Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel.
+
+*You may adapt the delegation pattern to fit the exact requirements of the codebase.*
+
+## Checklist
+
+### Secrets & Credentials
+- [ ] No hardcoded secrets
+- [ ] No keys in config files
+- [ ] Environment variables used properly
+
+### Injection
+- [ ] SQL injection prevention
+- [ ] Command injection prevention
+- [ ] XSS prevention
+
+### Shell Execution
+- [ ] No unsanitized user input in shell
+- [ ] Use exec over shell when possible
+- [ ] Validate and escape inputs
+
+### Auth/Authz
+- [ ] Proper authentication checks
+- [ ] Authorization on all endpoints
+- [ ] No broken access control
+
+### Dependencies
+- [ ] Known vulnerabilities checked
+- [ ] Minimal dependency surface
+- [ ] Lockfiles maintained
+
+### Path Traversal
+- [ ] Input validation on file paths
+- [ ] Canonical path resolution
+- [ ] Sandboxed file operations
+
+### SSRF
+- [ ] URL validation
+- [ ] Internal network blocking
+- [ ] Allowlist for external calls
+
+### Insecure Defaults
+- [ ] Secure defaults enabled
+- [ ] Debug endpoints disabled
+- [ ] Proper CORS configuration