Code Security Review
Overview
Performs comprehensive security code reviews to identify vulnerabilities, assess security risks, and provide actionable remediation guidance. Covers OWASP Top 10, CWE classifications, compliance requirements, and security best practices.
Security Review Workflow
1. Initial Assessment
Gather context about the application:
- Application type: Web app, API, mobile, desktop, embedded
- Data sensitivity: PII, financial data, healthcare records, proprietary information
- Compliance requirements: PCI-DSS, GDPR, HIPAA, SOC 2, ISO 27001
- Authentication mechanisms: OAuth, JWT, session-based, API keys
- Technology stack: Languages, frameworks, libraries, databases
- External integrations: Third-party APIs, cloud services, payment processors
Perform threat modeling:
- Identify critical assets (data, functions, resources)
- Map attack surfaces (user inputs, APIs, file uploads, network interfaces)
- Determine threat actors (external attackers, malicious insiders, automated bots)
- Assess existing security controls
2. Code Analysis
Systematically review code for security vulnerabilities:
Priority Areas:
- Authentication & Authorization - Login flows, session management, access controls
- Input Validation - All user inputs, API parameters, file uploads
- Data Protection - Encryption at rest and in transit, sensitive data handling
- API Security - Rate limiting, authentication, input validation
- Dependency Security - Third-party libraries, outdated packages, known CVEs
- Configuration - Security headers, CORS, environment variables, secrets management
- Error Handling - Information disclosure, stack traces, error messages
- Business Logic - Race conditions, workflow bypasses, state manipulation
3. Vulnerability Classification
Classify each finding:
- Severity: Critical, High, Medium, Low, Informational
- CWE ID: Common Weakness Enumeration identifier
- OWASP Category: Map to OWASP Top 10 if applicable
- CVSS Score: Calculate if applicable (use CVSS 3.1)
- Exploitability: How easy to exploit
- Impact: Data loss, privilege escalation, DoS, data breach
4. Documentation
Produce comprehensive security report:
- Executive Summary - High-level findings and risk overview
- Detailed Findings - Each vulnerability with code examples and exploit scenarios
- Remediation Guidance - Specific fixes with secure code examples
- Compliance Assessment - Status against required standards
- Remediation Timeline - Prioritized action plan
- Security Metrics - Vulnerability counts by severity and category
Severity Classification
Critical (CVSS 9.0-10.0):
- Remote code execution
- Authentication bypass
- SQL injection with data access
- Hardcoded credentials for production systems
- Complete access control bypass
High (CVSS 7.0-8.9):
- Privilege escalation
- Sensitive data exposure (PII, financial)
- Cross-site scripting (XSS) with session theft
- Insecure deserialization
- XML external entity (XXE) injection
Medium (CVSS 4.0-6.9):
- Information disclosure
- Cross-site request forgery (CSRF)
- Weak cryptography
- Security misconfiguration
- Missing security headers
Low (CVSS 0.1-3.9):
- Version disclosure
- Verbose error messages
- Missing best practices
- Security through obscurity
Informational:
- Recommendations for defense in depth
- Future-proofing suggestions
- Security hygiene improvements
Report Structure
Generate security reports in this format:
Executive Summary
- Total vulnerabilities by severity
- Critical risk areas
- Compliance status summary
- Overall security posture rating
- Recommended immediate actions
Detailed Findings
For each vulnerability:
## [SEVERITY] Finding Title (CWE-XXX)
**Severity**: Critical/High/Medium/Low
**CWE ID**: CWE-XXX
**OWASP**: A0X:YYYY
**CVSS Score**: X.X (if applicable)
**Description**:
[Clear explanation of the vulnerability]
**Location**:
- File: path/to/file.ext
- Lines: XX-XX
- Function/Class: function_name()
**Vulnerable Code**:
```language
[Actual vulnerable code snippet]
Exploit Scenario:
[Step-by-step demonstration of how an attacker could exploit this]
Impact:
[What could happen if exploited - data breach, privilege escalation, etc.]
Remediation:
[Specific steps to fix the vulnerability]
Secure Code Example:
[Working secure implementation]
References:
- [Relevant CWE, CVE, or documentation links]
### Remediation Timeline
- **Phase 1 (Critical - Week 1)**: List of critical issues
- **Phase 2 (High - Weeks 2-3)**: List of high severity issues
- **Phase 3 (Medium - Month 2)**: List of medium severity issues
- **Phase 4 (Low - Month 3)**: List of low severity issues
### Compliance Assessment
For each applicable standard, document:
- Requirements checked
- Compliance status (Compliant/Non-Compliant/Partially Compliant)
- Specific gaps identified
- Remediation needed for compliance
## Detailed References
For comprehensive vulnerability patterns, testing procedures, and compliance details:
- **OWASP Top 10 & CWE Patterns**: See [security-review-workflow.md](references/security-review-workflow.md) for:
- Detailed vulnerability patterns for each OWASP Top 10 category
- Code examples of vulnerable and secure implementations
- Testing procedures and detection methods
- Complete CWE mappings and classifications
- **Security Testing Procedures**: See [security-testing-checklist.md](references/security-testing-checklist.md) for:
- Comprehensive testing checklist by category
- Manual and automated testing techniques
- Security testing tools and configurations
- API security testing procedures
- **Compliance Requirements**: See [compliance-requirements.md](references/compliance-requirements.md) for:
- PCI-DSS requirements and validation
- GDPR data protection requirements
- HIPAA security and privacy rules
- SOC 2 security controls
- **Report Examples**: See [report-example.md](references/report-example.md) for:
- Complete security report template
- Example findings with remediation guidance
- Executive summary examples
- Remediation timeline structures
## Best Practices
**Be Thorough:**
- Review ALL user input points
- Check ALL database queries
- Verify ALL authentication and authorization checks
- Test ALL file operations and uploads
- Examine ALL external integrations
**Be Practical:**
- Prioritize by risk (likelihood × impact)
- Consider exploitability and business context
- Account for compensating controls
- Balance security with usability
**Be Clear:**
- Provide step-by-step exploit scenarios
- Show exact vulnerable code locations
- Give specific, actionable remediation steps
- Include working secure code examples
**Be Professional:**
- Focus on code issues, not developers
- Use industry-standard classifications (CWE, OWASP, CVSS)
- Provide credible references (NIST, OWASP, vendor documentation)
- Document assumptions and testing limitations
1---2name: code-security-review3description: Conducts comprehensive security code reviews including vulnerability detection (OWASP Top 10, CWE), authentication/authorization flaws, injection attacks, cryptography issues, sensitive data exposure, API security, dependency vulnerabilities, security misconfigurations, and compliance validation (PCI-DSS, GDPR, HIPAA). Produces detailed security assessment reports with CVE references, CVSS scores, exploit scenarios, and remediation guidance. Use when reviewing code security, performing security audits, checking for vulnerabilities, validating security controls, assessing security risks, or when users mention "security review", "vulnerability scan", "security audit", "penetration test", "OWASP", "security assessment", "secure coding", or "security compliance".4---5
6# Code Security Review
7
8## Overview
9
10Performs comprehensive security code reviews to identify vulnerabilities, assess security risks, and provide actionable remediation guidance. Covers OWASP Top 10, CWE classifications, compliance requirements, and security best practices.
11
12## Security Review Workflow
13
14## 1. Initial Assessment
15
16Gather context about the application:
17
18- **Application type**: Web app, API, mobile, desktop, embedded
19- **Data sensitivity**: PII, financial data, healthcare records, proprietary information
20- **Compliance requirements**: PCI-DSS, GDPR, HIPAA, SOC 2, ISO 27001
21- **Authentication mechanisms**: OAuth, JWT, session-based, API keys
22- **Technology stack**: Languages, frameworks, libraries, databases
23- **External integrations**: Third-party APIs, cloud services, payment processors
24
25Perform threat modeling:
26
27- Identify critical assets (data, functions, resources)
28- Map attack surfaces (user inputs, APIs, file uploads, network interfaces)
29- Determine threat actors (external attackers, malicious insiders, automated bots)
30- Assess existing security controls
31
32### 2. Code Analysis
33
34Systematically review code for security vulnerabilities:
35
36**Priority Areas:**
37
381. **Authentication & Authorization** - Login flows, session management, access controls
392. **Input Validation** - All user inputs, API parameters, file uploads
403. **Data Protection** - Encryption at rest and in transit, sensitive data handling
414. **API Security** - Rate limiting, authentication, input validation
425. **Dependency Security** - Third-party libraries, outdated packages, known CVEs
436. **Configuration** - Security headers, CORS, environment variables, secrets management
447. **Error Handling** - Information disclosure, stack traces, error messages
458. **Business Logic** - Race conditions, workflow bypasses, state manipulation
46
47### 3. Vulnerability Classification
48
49Classify each finding:
50
51- **Severity**: Critical, High, Medium, Low, Informational
52- **CWE ID**: Common Weakness Enumeration identifier
53- **OWASP Category**: Map to OWASP Top 10 if applicable
54- **CVSS Score**: Calculate if applicable (use CVSS 3.1)
55- **Exploitability**: How easy to exploit
56- **Impact**: Data loss, privilege escalation, DoS, data breach
57
58### 4. Documentation
59
60Produce comprehensive security report:
61
62- **Executive Summary** - High-level findings and risk overview
63- **Detailed Findings** - Each vulnerability with code examples and exploit scenarios
64- **Remediation Guidance** - Specific fixes with secure code examples
65- **Compliance Assessment** - Status against required standards
66- **Remediation Timeline** - Prioritized action plan
67- **Security Metrics** - Vulnerability counts by severity and category
68
69## Severity Classification
70
71**Critical (CVSS 9.0-10.0):**
72
73- Remote code execution
74- Authentication bypass
75- SQL injection with data access
76- Hardcoded credentials for production systems
77- Complete access control bypass
78
79**High (CVSS 7.0-8.9):**
80
81- Privilege escalation
82- Sensitive data exposure (PII, financial)
83- Cross-site scripting (XSS) with session theft
84- Insecure deserialization
85- XML external entity (XXE) injection
86
87**Medium (CVSS 4.0-6.9):**
88
89- Information disclosure
90- Cross-site request forgery (CSRF)
91- Weak cryptography
92- Security misconfiguration
93- Missing security headers
94
95**Low (CVSS 0.1-3.9):**
96
97- Version disclosure
98- Verbose error messages
99- Missing best practices
100- Security through obscurity
101
102**Informational:**
103
104- Recommendations for defense in depth
105- Future-proofing suggestions
106- Security hygiene improvements
107
108## Report Structure
109
110Generate security reports in this format:
111
112### Executive Summary
113
114- Total vulnerabilities by severity
115- Critical risk areas
116- Compliance status summary
117- Overall security posture rating
118- Recommended immediate actions
119
120### Detailed Findings
121
122For each vulnerability:
123
124```
125## [SEVERITY] Finding Title (CWE-XXX)
126
127**Severity**: Critical/High/Medium/Low
128**CWE ID**: CWE-XXX
129**OWASP**: A0X:YYYY
130**CVSS Score**: X.X (if applicable)
131
132**Description**:
133[Clear explanation of the vulnerability]
134
135**Location**:
136- File: path/to/file.ext
137- Lines: XX-XX
138- Function/Class: function_name()
139
140**Vulnerable Code**:
141```language
142[Actual vulnerable code snippet]
143```
144
145**Exploit Scenario**:
146[Step-by-step demonstration of how an attacker could exploit this]
147
148**Impact**:
149[What could happen if exploited - data breach, privilege escalation, etc.]
150
151**Remediation**:
152[Specific steps to fix the vulnerability]
153
154**Secure Code Example**:
155
156```language
157[Working secure implementation]
158```
159
160**References**:
161
162- [Relevant CWE, CVE, or documentation links]
163
164```
165
166### Remediation Timeline
167- **Phase 1 (Critical - Week 1)**: List of critical issues
168- **Phase 2 (High - Weeks 2-3)**: List of high severity issues
169- **Phase 3 (Medium - Month 2)**: List of medium severity issues
170- **Phase 4 (Low - Month 3)**: List of low severity issues
171
172### Compliance Assessment
173For each applicable standard, document:
174- Requirements checked
175- Compliance status (Compliant/Non-Compliant/Partially Compliant)
176- Specific gaps identified
177- Remediation needed for compliance
178
179## Detailed References
180
181For comprehensive vulnerability patterns, testing procedures, and compliance details:
182
183- **OWASP Top 10 & CWE Patterns**: See [security-review-workflow.md](references/security-review-workflow.md) for:
184 - Detailed vulnerability patterns for each OWASP Top 10 category
185 - Code examples of vulnerable and secure implementations
186 - Testing procedures and detection methods
187 - Complete CWE mappings and classifications
188
189- **Security Testing Procedures**: See [security-testing-checklist.md](references/security-testing-checklist.md) for:
190 - Comprehensive testing checklist by category
191 - Manual and automated testing techniques
192 - Security testing tools and configurations
193 - API security testing procedures
194
195- **Compliance Requirements**: See [compliance-requirements.md](references/compliance-requirements.md) for:
196 - PCI-DSS requirements and validation
197 - GDPR data protection requirements
198 - HIPAA security and privacy rules
199 - SOC 2 security controls
200
201- **Report Examples**: See [report-example.md](references/report-example.md) for:
202 - Complete security report template
203 - Example findings with remediation guidance
204 - Executive summary examples
205 - Remediation timeline structures
206
207## Best Practices
208
209**Be Thorough:**
210- Review ALL user input points
211- Check ALL database queries
212- Verify ALL authentication and authorization checks
213- Test ALL file operations and uploads
214- Examine ALL external integrations
215
216**Be Practical:**
217- Prioritize by risk (likelihood × impact)
218- Consider exploitability and business context
219- Account for compensating controls
220- Balance security with usability
221
222**Be Clear:**
223- Provide step-by-step exploit scenarios
224- Show exact vulnerable code locations
225- Give specific, actionable remediation steps
226- Include working secure code examples
227
228**Be Professional:**
229- Focus on code issues, not developers
230- Use industry-standard classifications (CWE, OWASP, CVSS)
231- Provide credible references (NIST, OWASP, vendor documentation)
232- Document assumptions and testing limitations
233