All skills
aktsmm avatar

/review-security-structure

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Review owned or authorized code for security using structure-first evidence: AST/structure maps, call graphs, complexity, Source/Sink flow, and defensive findings. Use when asked for security review, vulnerability review, AST structure map review, SAST triage, Source/Sink, taint flow, parser/scanner hardening, CI/CD security, LLM/agent tool boundary review, 脆弱性レビュー, 構造マップ, セキュリティレビュー.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/review-security-structure

This session only. Nothing lands on disk.

referencesoutput-format.md

≈455 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Output Format

Lead with Findings. If there are no confirmed findings, state that clearly first.

Findings

# Severity Confidence Target Structural Signal Reachability Impact Defensive Verification Minimal Fix

Structure Map Summary

Item Value
Source existing artifact / newly generated / quick extraction / unavailable
Artifact saved path, or none
Scope reviewed paths and boundaries
Method tools, scripts, or manual extraction used
Limits unparsed or approximate areas
Redaction redacted secret values, or none applicable

Hypotheses

# Hypothesis Missing Evidence Next Check

Code to Inspect

Priority Path / Symbol Why

Recommended Fix Plan

  1. Fix clear, reachable, high-impact issues first.
  2. Add safety guards such as size limits, timeouts, input validation, path normalization, auth checks, and log redaction.
  3. Split high-complexity code only where it reduces risk or enables tests.
  4. Verify the Source -> Sink path is blocked or constrained after the fix.

Verification Summary

  • Checks run: command/tool/read-only review performed, or not run with reason
  • Remaining risk: unresolved items, or none
  • External references: URLs used, or none

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill provides a comprehensive framework for performing defensive security reviews of code and architectural structures. It emphasizes a structure-first approach, modeling trust boundaries, and includes explicit safety guidelines to prevent unauthorized activities and ensure secret redaction.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 18 hours ago.

Activeupdated 3 months ago
argument-hint
対象パス、構造マップ、ASTレポート、call graph、scan結果など
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}

README badge

README badge for aktsmm/agent-skills/review-security-structure