secure-code-review

v2026.09.25

Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.

GitHub
安装命令
npx skhub add securityskills/secure-code-review
Markdown
SKILL.md

Secure Code Review

Review code for vulnerabilities systematically, not line-by-line.

1. Orient

  • What does this code do? Identify: entry points, trust boundaries, data stores, privileged operations
  • Read the tests — what invariants do they reveal?
  • Check the diff's blast radius: auth logic? parsing? file handling? crypto?

2. Trace Untrusted Data

Follow each input from entry point to sink:

Sink ClassWhat to Verify
SQL/NoSQLParameterized; no string-built queries; identifiers whitelisted
Command execNo user data in shell strings; argv-array APIs; no shell=True
HTML/renderingContextual auto-escaping; raw/unsafe HTML flags justified
File pathsBasename/allowlist; canonicalize + prefix check; no user paths in includes
DeserializationTyped formats (JSON) over object serializers; validation post-parse
RedirectsRelative-only or allowlisted targets
Eval/dynamic codeJustified and input-free, or rejected

3. Audit Auth and Access Control

  • Every endpoint enforces authz server-side; role checks at the resource, not the controller only
  • Object-level checks (IDOR): does the query filter by the caller's tenant/user ID?
  • Session management: rotation, invalidation, secure cookie flags
  • Password reset flows: token entropy, expiry, single-use, no account enumeration

4. Audit Secrets and Config

  • No hardcoded credentials/keys/API tokens; no secrets in logs or error messages
  • Crypto: approved algorithms, library primitives (not hand-rolled), correct modes, random from CSPRNG

5. Race and State

  • TOCTOU on file checks, check-then-use on quotas/credits
  • Concurrency on mutable shared state; missing transactions on multi-step writes

Communication

Report findings with severity, the specific code path, an exploit sketch, and a suggested fix. Distinguish "must fix" from "harden later."

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

2026年9月25日

分类

未分类

许可证

未指定

源路径

secure-code-review/secure-code-review

默认分支

main

最新提交

b2b6b52

Tree SHA

8db485b