Security Code Review Guide
Overview
Perform thorough security reviews of code to identify vulnerabilities, misconfigurations, and security anti-patterns. This skill helps you think like an attacker while providing actionable fixes.
Process
Phase 1: Reconnaissance
Before diving into code, understand the attack surface:
1.1 Identify Entry Points
- HTTP endpoints (routes, controllers, handlers)
- API endpoints (REST, GraphQL, gRPC)
- WebSocket handlers
- File upload handlers
- Authentication endpoints
- Admin/privileged endpoints
1.2 Identify Data Flows
- User input sources (forms, query params, headers, cookies)
- Database queries and ORM usage
- External API calls
- File system operations
- Command execution
- Serialization/deserialization
1.3 Identify Trust Boundaries
- Authentication checks
- Authorization/permission checks
- Input validation layers
- Output encoding layers
Phase 2: Vulnerability Hunting
Systematically check for each vulnerability class:
2.1 Injection Vulnerabilities
SQL Injection
- Look for string concatenation in queries
- Check ORM usage for raw queries
- Verify parameterized queries are used
- Check stored procedures for dynamic SQL
Command Injection
- Find all
exec, system, popen, subprocess calls
- Check for user input in command arguments
- Verify proper escaping or allowlisting
XSS (Cross-Site Scripting)
- Find all places user input is rendered in HTML
- Check for proper output encoding
- Look for
innerHTML, dangerouslySetInnerHTML, v-html
- Check CSP headers
Template Injection
- Find template rendering with user input
- Check for SSTI in Jinja2, Twig, ERB, etc.
2.2 Authentication & Session
Authentication Flaws
- Password hashing (bcrypt/argon2 vs MD5/SHA1)
- Timing-safe comparison for secrets
- Account enumeration via error messages
- Brute force protection
- Password reset flow security
Session Management
- Session token entropy
- Secure cookie flags (HttpOnly, Secure, SameSite)
- Session fixation protection
- Session timeout/invalidation
2.3 Authorization
Broken Access Control
- IDOR (Insecure Direct Object References)
- Missing function-level access control
- Privilege escalation paths
- JWT validation issues
2.4 Cryptography
Crypto Weaknesses
- Hardcoded secrets/keys
- Weak algorithms (MD5, SHA1, DES, RC4)
- ECB mode usage
- Missing or weak random number generation
- Certificate validation disabled
2.5 Data Exposure
Sensitive Data
- Secrets in logs
- PII in error messages
- Sensitive data in URLs
- Missing encryption at rest
- Verbose error messages in production
Phase 3: Reporting
For each finding, document:
- Vulnerability Type: CWE ID and name
- Severity: Critical/High/Medium/Low
- Location: File, line number, function
- Description: What the vulnerability is
- Impact: What an attacker could do
- Proof of Concept: How to exploit (if safe)
- Remediation: Specific fix with code example
Phase 4: Fix Verification
After fixes are applied:
- Verify the fix addresses the root cause
- Check for regression in related code
- Ensure fix doesn't introduce new issues
- Add tests to prevent regression
Reference Files
Load these as needed during review:
Quick Reference: OWASP Top 10 (2021)
| # |
Vulnerability |
What to Look For |
| A01 |
Broken Access Control |
Missing auth checks, IDOR, privilege escalation |
| A02 |
Cryptographic Failures |
Weak hashing, hardcoded secrets, missing encryption |
| A03 |
Injection |
SQL, command, XSS, template injection |
| A04 |
Insecure Design |
Missing threat modeling, insecure patterns |
| A05 |
Security Misconfiguration |
Default creds, verbose errors, missing headers |
| A06 |
Vulnerable Components |
Outdated dependencies with known CVEs |
| A07 |
Auth Failures |
Weak passwords, missing MFA, session issues |
| A08 |
Data Integrity Failures |
Insecure deserialization, missing integrity checks |
| A09 |
Logging Failures |
Missing audit logs, sensitive data in logs |
| A10 |
SSRF |
Unvalidated URLs, internal network access |
1---2name: security-review-audit3description: Full codebase security audit with OWASP Top 10 guidance, language-specific patterns, checklists, and fix examples. Use for comprehensive audits split by module/area.4license: MIT5---67# Security Code Review Guide89## Overview1011Perform thorough security reviews of code to identify vulnerabilities, misconfigurations, and security anti-patterns. This skill helps you think like an attacker while providing actionable fixes.1213---1415# Process1617## Phase 1: Reconnaissance1819Before diving into code, understand the attack surface:2021### 1.1 Identify Entry Points22- HTTP endpoints (routes, controllers, handlers)23- API endpoints (REST, GraphQL, gRPC)24- WebSocket handlers25- File upload handlers26- Authentication endpoints27- Admin/privileged endpoints2829### 1.2 Identify Data Flows30- User input sources (forms, query params, headers, cookies)31- Database queries and ORM usage32- External API calls33- File system operations34- Command execution35- Serialization/deserialization3637### 1.3 Identify Trust Boundaries38- Authentication checks39- Authorization/permission checks40- Input validation layers41- Output encoding layers4243---4445## Phase 2: Vulnerability Hunting4647Systematically check for each vulnerability class:4849### 2.1 Injection Vulnerabilities5051**SQL Injection**52- Look for string concatenation in queries53- Check ORM usage for raw queries54- Verify parameterized queries are used55- Check stored procedures for dynamic SQL5657**Command Injection**58- Find all `exec`, `system`, `popen`, `subprocess` calls59- Check for user input in command arguments60- Verify proper escaping or allowlisting6162**XSS (Cross-Site Scripting)**63- Find all places user input is rendered in HTML64- Check for proper output encoding65- Look for `innerHTML`, `dangerouslySetInnerHTML`, `v-html`66- Check CSP headers6768**Template Injection**69- Find template rendering with user input70- Check for SSTI in Jinja2, Twig, ERB, etc.7172### 2.2 Authentication & Session7374**Authentication Flaws**75- Password hashing (bcrypt/argon2 vs MD5/SHA1)76- Timing-safe comparison for secrets77- Account enumeration via error messages78- Brute force protection79- Password reset flow security8081**Session Management**82- Session token entropy83- Secure cookie flags (HttpOnly, Secure, SameSite)84- Session fixation protection85- Session timeout/invalidation8687### 2.3 Authorization8889**Broken Access Control**90- IDOR (Insecure Direct Object References)91- Missing function-level access control92- Privilege escalation paths93- JWT validation issues9495### 2.4 Cryptography9697**Crypto Weaknesses**98- Hardcoded secrets/keys99- Weak algorithms (MD5, SHA1, DES, RC4)100- ECB mode usage101- Missing or weak random number generation102- Certificate validation disabled103104### 2.5 Data Exposure105106**Sensitive Data**107- Secrets in logs108- PII in error messages109- Sensitive data in URLs110- Missing encryption at rest111- Verbose error messages in production112113---114115## Phase 3: Reporting116117For each finding, document:1181191. **Vulnerability Type**: CWE ID and name1202. **Severity**: Critical/High/Medium/Low1213. **Location**: File, line number, function1224. **Description**: What the vulnerability is1235. **Impact**: What an attacker could do1246. **Proof of Concept**: How to exploit (if safe)1257. **Remediation**: Specific fix with code example126127---128129## Phase 4: Fix Verification130131After fixes are applied:132- Verify the fix addresses the root cause133- Check for regression in related code134- Ensure fix doesn't introduce new issues135- Add tests to prevent regression136137---138139# Reference Files140141Load these as needed during review:142143- [OWASP Top 10](./reference/owasp_top_10.md) - Most critical web vulnerabilities144- [Language Patterns](./reference/language_patterns.md) - Language-specific vulnerability patterns145- [Secure Coding Checklist](./reference/checklist.md) - Quick reference checklist146- [Common Fixes](./reference/common_fixes.md) - Code examples for common fixes147148---149150# Quick Reference: OWASP Top 10 (2021)151152| # | Vulnerability | What to Look For |153|---|--------------|------------------|154| A01 | Broken Access Control | Missing auth checks, IDOR, privilege escalation |155| A02 | Cryptographic Failures | Weak hashing, hardcoded secrets, missing encryption |156| A03 | Injection | SQL, command, XSS, template injection |157| A04 | Insecure Design | Missing threat modeling, insecure patterns |158| A05 | Security Misconfiguration | Default creds, verbose errors, missing headers |159| A06 | Vulnerable Components | Outdated dependencies with known CVEs |160| A07 | Auth Failures | Weak passwords, missing MFA, session issues |161| A08 | Data Integrity Failures | Insecure deserialization, missing integrity checks |162| A09 | Logging Failures | Missing audit logs, sensitive data in logs |163| A10 | SSRF | Unvalidated URLs, internal network access |