code-review-security

Security-focused review lens for identifying injection risks, auth flaws, secret exposure, unsafe configuration, and missing validation during code review.

voku/agent-skills5 installsMITSynced Aug 22

Works with

Claude CodeCursorCodex CLIGitHub CopilotGemini CLI
---
name: code-review-security
description: Security-focused review lens for identifying injection risks, auth flaws, secret exposure, unsafe configuration, and missing validation during code review.
license: MIT
---

# Code Review Security

Targeted security lens for vulnerabilities, validation, data protection, auth/authz, and secure defaults.

## Review Focus

| Priority | Category | Prefix |
|----------|----------|--------|
| CRITICAL | Injection vulnerabilities | `sec-injection-vulnerabilities` |
| CRITICAL | Authentication & authorization | `sec-auth-authorization` |
| HIGH | Data protection | `sec-data-protection` |
| HIGH | Input validation | `sec-input-validation` |
| MEDIUM | Dependency security | `sec-dependency-security` |
| HIGH | Configuration security | `sec-configuration-security` |

Look for SQL/command/template/path injection, authorization gaps, unsafe session/token handling, secret or PII exposure, missing validation, vulnerable dependencies, and insecure defaults.

## Scope

Run this lens when security is the dominant concern or a workflow explicitly dispatches it. Do not broaden into a generic review bundle.

Out of scope as primary concerns: type coverage, retry hygiene without security impact, performance/architecture trade-offs, readability-only feedback.

## Handoff

When another concern becomes dominant, emit **at most one** focused handoff with the observed `path:line` and why that concern is dominant:

- `code-review-error-handling` for cleanup/retry/failure behavior weakening controls;
- `code-review-type-safety` for untrusted shape or validation proof;
- `code-review-architecture` for broken authz/trust boundaries;
- `code-review-performance` for user-triggerable cost amplification.

## Evidence Discipline

- Identify the trust boundary and concrete sink/control before claiming a vulnerability.
- When the diff changes untrusted input, authorization, persistence, or output encoding, construct one relevant adversarial input and trace validation, authorization, persistence, and output handling.
- Keep sanitization, persistence formatting, and output escaping context-specific; do not treat one as a substitute for another.
- If required trust-boundary evidence cannot be inspected, return `blocked` instead of guessing.
- Prefer secure defaults and smaller attack surface over configurable complexity.

## Terminal Contract

```text
STATUS: findings
<path>:<line>: <CRITICAL|HIGH|MEDIUM|LOW> <problem>. <concrete fix>.
HANDOFF: <code-review-* lens> <path>:<line> <why this concern is dominant>   # optional, at most one
```

```text
STATUS: clean
```

```text
STATUS: blocked
UNKNOWN: <exact missing evidence>.
```

`STATUS` is this lens' judgment only. The caller owns merge, dedupe, precedence, approval, persistence, and workflow progression.

## Severity

- **CRITICAL**: exploitable vulnerability, privilege escalation, or material data exposure.
- **HIGH**: missing control with plausible security impact.
- **MEDIUM**: defense-in-depth gap with concrete value.
- **LOW**: minor hardening or hygiene.

## References

- [Pi Ensemble security lens](https://raw.githubusercontent.com/randomm/pi-ensemble/main/skill/code-review-security/SKILL.md)
- [OWASP Top 10](https://owasp.org/www-project-top-ten/)

More Code Review skills

pr-to-video

heygen-com/hyperframes

Turn a GitHub pull request (a PR URL, owner/repo#N, or 'this PR' in a checked-out repo) into a code-change explainer video — changelog, feature reveal, fix, or refactor walkthrough built from the diff, commits, and files: the input is a code change, not a website. Not a product promo (/product-launch-video) or a no-PR topic explainer (/faceless-explainer). Unclear → /hyperframes.

178.9k

receiving-code-review

obra/superpowers

Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation

178.0k

public-relations

coreyhaines31/marketingskills

When the user wants help with public relations, earned media, press coverage, journalist outreach, or media strategy (not pull requests). Also use when the user mentions 'PR,' 'public relations,' 'press,' 'press release,' 'press coverage,' 'media outreach,' 'pitch a journalist,' 'get featured,' 'media list,' 'media kit,' 'press kit,' 'newsjacking,' 'news hijack,' 'HARO,' 'Qwoted,' 'Featured,' 'Help A Reporter,' 'reporter request,' 'tech press,' 'TechCrunch,' 'earned media,' 'thought leadership placement,' 'op-ed,' 'guest article,' 'press contacts,' 'podcast prep,' 'going on a podcast,' 'podcast guest,' 'prep me for this podcast,' or 'how do I get press.' Use this for earned media work — finding journalists, pitching stories, newsjacking, prepping podcast appearances, and responding to press requests. For startup/SaaS/AI directory submissions, see directory-submissions. For product launches, see launch. For social-media engagement, see social. For cold-email outreach to prospects, see cold-email.

33.1k

← All Code Review skills

Check your AI visibility

One URL in, a 0–100 score and the exact fixes out.

RUN THE CHECK

Browse all the tools

15 tools across six categories
13 of them never send your data anywhere

Free · No signup · No trial clock

SEE THE DIRECTORY