Self Serve Security Review

Security review for lfx-self-serve (LFX One) pull requests. Use when a PR touches the auth middleware or route classification, the OIDC session or token-exchange paths, a server controller or service, a proxy call to an upstream microservice, the public surface, user identity, impersonation or persona-based authorization, PII or logging, URL handling or redirects, anything rendered with `[innerHTML]`, or what crosses the SSR-to-client boundary. Applies a diff-aware, high-confidence, low-false-positive methodology (adapted from Anthropic's claude-code-security-review) to this application's durable threat anchors. Discovers the concrete guards from the code at review time; this skill carries the method, not an inventory.

linuxfoundation 42552b2 14.7 KB Updated

File contents

linuxfoundation/lfx-self-serve/tree/main/.github/skills/self-serve-security-review commit 42552b2b2c

Frequently asked questions

npx skillmds@latest add linuxfoundation/self-serve-security-review