Secure Code Review

Performs a security-focused review of code or a diff, hunting for injection, broken authentication/authorization, insecure crypto, hardcoded secrets, unsafe deserialization, SSRF, path traversal, and missing input validation, with exploit scenarios and concrete fixes ranked by severity. Use this skill when the user asks to "do a security review", "audit this code for vulnerabilities", "is this code secure", "check for security issues before deploy", "review this auth/crypto code", or wants a security pass on a PR. Complements general code review with a threat-focused lens.

JayRHa 76c2379 4 files · 13.4 KB Updated

File contents

JayRHa/AgentSkills/tree/main/secure-code-review commit 76c2379902

Frequently asked questions

npx skillmds@latest add jayrha/secure-code-review