--- name: security-review description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc." --- # Security Review Skill Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc. ## Subagents When you need to delegate sub‑tasks, use the `pi-subagents` skill. **Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel. *You may adapt the delegation pattern to fit the exact requirements of the codebase.* ## Checklist ### Secrets & Credentials - [ ] No hardcoded secrets - [ ] No keys in config files - [ ] Environment variables used properly ### Injection - [ ] SQL injection prevention - [ ] Command injection prevention - [ ] XSS prevention ### Shell Execution - [ ] No unsanitized user input in shell - [ ] Use exec over shell when possible - [ ] Validate and escape inputs ### Auth/Authz - [ ] Proper authentication checks - [ ] Authorization on all endpoints - [ ] No broken access control ### Dependencies - [ ] Known vulnerabilities checked - [ ] Minimal dependency surface - [ ] Lockfiles maintained ### Path Traversal - [ ] Input validation on file paths - [ ] Canonical path resolution - [ ] Sandboxed file operations ### SSRF - [ ] URL validation - [ ] Internal network blocking - [ ] Allowlist for external calls ### Insecure Defaults - [ ] Secure defaults enabled - [ ] Debug endpoints disabled - [ ] Proper CORS configuration