Appsec Compliance Review

Use when a PR diff touches application code, or any committed configuration that can carry credentials, governed by an organization's written security policy. Enforces five AppSec rules on the CHANGED code only - authentication/authorization on sensitive endpoints, injection, SSRF, debug/test code reachable in production, and hardcoded secrets - reporting per-rule per-file coverage so an unevaluated rule is never a silent skip. Skip only for docs-only diffs.

gvago Updated

File contents

gvago/unofficial-qodo-review-skills/tree/main/skills/appsec-compliance-review commit 96ecc0aa13

Frequently asked questions

npx skillmds@latest add gvago/appsec-compliance-review