aboutsummaryrefslogtreecommitdiffstats
path: root/modules/development/pi-coding-agent/skills/security-review/SKILL.md
blob: 0b2d30789ccdd04e660d9449da56e07868b8b909 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
---
name: security-review
description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc."
---

# Security Review Skill

Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc.

## Checklist

### Secrets & Credentials
- [ ] No hardcoded secrets
- [ ] No keys in config files
- [ ] Environment variables used properly

### Injection
- [ ] SQL injection prevention
- [ ] Command injection prevention
- [ ] XSS prevention

### Shell Execution
- [ ] No unsanitized user input in shell
- [ ] Use exec over shell when possible
- [ ] Validate and escape inputs

### Auth/Authz
- [ ] Proper authentication checks
- [ ] Authorization on all endpoints
- [ ] No broken access control

### Dependencies
- [ ] Known vulnerabilities checked
- [ ] Minimal dependency surface
- [ ] Lockfiles maintained

### Path Traversal
- [ ] Input validation on file paths
- [ ] Canonical path resolution
- [ ] Sandboxed file operations

### SSRF
- [ ] URL validation
- [ ] Internal network blocking
- [ ] Allowlist for external calls

### Insecure Defaults
- [ ] Secure defaults enabled
- [ ] Debug endpoints disabled
- [ ] Proper CORS configuration