Core Security Review
Review agent code changes for auth, authorization, injection, secrets, dependency risk, and unsafe defaults.
Verified Surface
- Provider lane: core
- Native surface: SKILL.md skill packages
- Harness export: core
- Import mode: techtide-synthesis
- Source evidence: load
references/source-evidence.mdbefore promoting third-party material.
Workflow
- Inventory trust boundaries, inputs, outputs, credentials, network calls, and mutable resources.
- Check auth, authorization, input validation, output encoding, CORS, storage, and logging.
- Search for hardcoded credentials, broad tokens, mock bypasses, and sensitive data exposure.
- Classify findings by exploitability and blast radius.
- Require proof for every claimed fix.
Output Contract
Return:
- provider lane and native surface
- source evidence used
- promotion decision or operating recommendation
- security and privacy notes
- verification still required
Guardrails
- Keep third-party source bodies out of public artifacts unless direct import has clean license, attribution, and manual review.
- Do not use star counts, popularity, screenshots, or social posts as the sole evidence for promotion.
- Do not install or execute unreviewed external scripts as part of source research.
- Quarantine missing licenses, unclear ownership, vague prompt packs, duplicate skill packs, and unsupported native-surface claims.
- Preserve Alex Cinovoj / TechTide ownership for TechTide-authored synthesis while citing third-party sources as references.