1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
|
---
name: security-review
description: "Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc."
---
# Security Review Skill
Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc.
## Checklist
### Secrets & Credentials
- [ ] No hardcoded secrets
- [ ] No keys in config files
- [ ] Environment variables used properly
### Injection
- [ ] SQL injection prevention
- [ ] Command injection prevention
- [ ] XSS prevention
### Shell Execution
- [ ] No unsanitized user input in shell
- [ ] Use exec over shell when possible
- [ ] Validate and escape inputs
### Auth/Authz
- [ ] Proper authentication checks
- [ ] Authorization on all endpoints
- [ ] No broken access control
### Dependencies
- [ ] Known vulnerabilities checked
- [ ] Minimal dependency surface
- [ ] Lockfiles maintained
### Path Traversal
- [ ] Input validation on file paths
- [ ] Canonical path resolution
- [ ] Sandboxed file operations
### SSRF
- [ ] URL validation
- [ ] Internal network blocking
- [ ] Allowlist for external calls
### Insecure Defaults
- [ ] Secure defaults enabled
- [ ] Debug endpoints disabled
- [ ] Proper CORS configuration
|