All skills
bitwarden avatar

/analyzing-code-security

@0f6d9c7 official
by bitwardenbitwarden/ai-plugins155 stars
20

This skill should be used when the user asks to "analyze code for security issues", "check for OWASP vulnerabilities", "review code against CWE Top 25", "find injection vulnerabilities", "do a security code review", or needs manual security analysis against OWASP Top 10, API Top 10, Mobile Top 10, or CWE/SANS frameworks.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/analyzing-code-security

This session only. Nothing lands on disk.

referencesvulnerability-patterns.md

≈835 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Language-Specific Vulnerability Patterns

CORRECT/WRONG code examples for common vulnerabilities in Bitwarden's stack. Consult these when reviewing code or recommending fixes.

C# / .NET

// WRONG — SQL injection via string concatenation
var query = $"SELECT * FROM Users WHERE Id = '{userId}'";
var result = connection.Execute(query);

// CORRECT — parameterized query
var query = "SELECT * FROM Users WHERE Id = @UserId";
var result = connection.Execute(query, new { UserId = userId });
// WRONG — insecure deserialization with type handling
JsonConvert.DeserializeObject<object>(input, new JsonSerializerSettings {
    TypeNameHandling = TypeNameHandling.All
});

// CORRECT — no type name handling on untrusted input
JsonConvert.DeserializeObject<ExpectedType>(input);
// WRONG — path traversal via user input
var filePath = Path.Combine(baseDir, userInput);
var content = File.ReadAllText(filePath);

// CORRECT — canonicalize and validate
var filePath = Path.GetFullPath(Path.Combine(baseDir, userInput));
if (!filePath.StartsWith(Path.GetFullPath(baseDir)))
    throw new UnauthorizedAccessException();
var content = File.ReadAllText(filePath);
// WRONG — SSRF via user-controlled URL
var response = await httpClient.GetAsync(userProvidedUrl);

// CORRECT — validate against allowlist
var uri = new Uri(userProvidedUrl);
if (!AllowedHosts.Contains(uri.Host))
    throw new ArgumentException("Host not allowed");
var response = await httpClient.GetAsync(uri);
// WRONG — XXE via default XML settings
var doc = new XmlDocument();
doc.LoadXml(userInput);

// CORRECT — disable DTD and external entities
var doc = new XmlDocument();
doc.XmlResolver = null;
doc.LoadXml(userInput);

TypeScript / Angular

// WRONG — XSS via innerHTML
element.innerHTML = userInput;

// CORRECT — use framework text binding
// In Angular templates: {{ userInput }} (auto-escaped)
// Or use DomSanitizer with explicit trust only for known-safe content
// WRONG — bypassing Angular security without justification
this.sanitizer.bypassSecurityTrustHtml(userInput);

// CORRECT — only bypass for content fully controlled by the application
const trustedContent = this.generateSafeHtml(); // no user input
this.sanitizer.bypassSecurityTrustHtml(trustedContent);
// WRONG — open redirect
window.location.href = params.get("redirect");

// CORRECT — validate redirect target
const redirect = params.get("redirect");
const url = new URL(redirect, window.location.origin);
if (url.origin !== window.location.origin) {
  throw new Error("Invalid redirect");
}
window.location.href = url.toString();
// WRONG — insecure postMessage (no origin check)
window.addEventListener("message", (event) => {
  processData(event.data);
});

// CORRECT — validate origin
window.addEventListener("message", (event) => {
  if (event.origin !== "https://expected-origin.com") return;
  processData(event.data);
});

SQL

-- WRONG — dynamic SQL with concatenation
EXECUTE('SELECT * FROM Users WHERE Name = ''' + @Name + '''');

-- CORRECT — parameterized dynamic SQL
EXECUTE sp_executesql N'SELECT * FROM Users WHERE Name = @Name', N'@Name NVARCHAR(100)', @Name = @Name;

Source: SKILL.md on GitHub

No alerts14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    This skill provides a set of instructional guidelines and reference material for performing manual security code reviews. It includes checklists for OWASP Top 10 and CWE frameworks, alongside code examples demonstrating common vulnerabilities and their secure alternatives. No executable code or suspicious patterns were detected.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

Signed by skilld at 0f6d9c7. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 8 months ago
  • security-review
  • owasp
  • cwe
  • code-analysis
  • vulnerability-detection
  • injection
  • access-control
  • xss
  • ssrf

README badge

README badge for bitwarden/ai-plugins/analyzing-code-security

Conducts manual security code reviews by mapping data flows from untrusted inputs to dangerous operations, checking against OWASP Top 10, API Top 10, Mobile Top 10, and CWE Top 25 frameworks. Traces injection, broken access control, XSS, SSRF, deserialization, path traversal, and cryptographic failures through C#/.NET, TypeScript/Angular, and SQL codebases.

Generated from the current SKILL.md.

Does this skill check code automatically or require manual review?
This skill provides a structured methodology for manual security code review. It does not run automated scanners; instead it guides you through identifying attack surfaces, tracing data flows, and applying OWASP and CWE frameworks to find vulnerabilities.
What frameworks and languages does this skill cover?
The skill includes examples and checklists for C#/.NET, TypeScript/Angular, and SQL. It references OWASP Top 10 (Web, API, Mobile) and CWE Top 25 across all supported stacks.
Does this skill provide code examples for vulnerable vs. secure patterns?
Yes. The skill references `references/vulnerability-patterns.md` which contains CORRECT/WRONG code examples for C#, TypeScript, and SQL across common vulnerability categories.
What should I do if I find a vulnerability?
Map every finding to a specific CWE ID, document the code location, and trace the data flow that makes it exploitable. Classify findings by practical exploitability rather than theoretical risk.

Generated from the current SKILL.md. These answers refresh after source changes.