Newsletter Security Review

Security review for lfx-v2-newsletter-service pull requests. Use when a PR touches a handler, auth, persistence, the dispatch path, recipient data, config, or the chart. Applies a diff-aware, high-confidence, low-false-positive methodology (adapted from Anthropic's claude-code-security-review) to this service's durable threat anchors: recipient PII, the deliberately unauthenticated endpoints, JWT verification, gateway-delegated authorization, SQL construction, and secrets. Discovers the concrete guards from the code at review time; this skill carries the method, not an inventory.

linuxfoundation d9e8833 6.1 KB Updated

File contents

linuxfoundation/lfx-v2-newsletter-service/tree/main/.github/skills/newsletter-security-review commit d9e8833cda

Frequently asked questions

npx skillmds@latest add linuxfoundation/newsletter-security-review