All skills
bitwarden avatar

/perform-security-review

@44659bd official
by bitwardenbitwarden/ai-plugins155 stars
20

Performs a security-focused code review by launching multiple specialized agents and a verification agent to ensure comprehensive coverage and accurate findings. Use this skill when the user asks for a "perform-security-review", "bitwarden-security-review", "execute a security review", "run a comprehensive security audit", "perform an end-to-end security assessment", or needs to coordinate multiple security checks across code, dependencies, secrets, and configurations. The skill manages the workflow, delegates tasks to specialized agents, and presents final findings to the user.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/perform-security-review

This session only. Nothing lands on disk.

referencessecurity-review-rubric.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Review Rubric

The rubric grounds specialized analysis agents during security review.

Bitwarden Security Invariants

Invoke Skill(bitwarden-security-context) for the full security principles (P01–P06), vocabulary, and data classification standards. The invariants below are the non-negotiable rules derived from that context — any violation is automatically 🔴 CRITICAL severity.

Core Invariants

  1. Zero-knowledge invariant: Encryption and decryption happen client-side only. The server MUST never have access to plaintext vault data.
  2. Vault Data protection: Passwords, usernames, secure notes, credit cards, identities, and attachments must always be encrypted before leaving the client.
  3. Key material: The UserKey MUST NOT be exported. It must be protected at rest and in transit. (EK)
  4. Data Exporting: Any operation that causes vault data to leave Bitwarden unprotected requires explicit, informed user consent.
  5. Secure Channel requirement: All communication containing vault data must use at minimum a Secure Channel (confidentiality + integrity). A Trusted Channel (adds receiver identity verification) is required where authenticity of the receiving party must be guaranteed. (SC/TC)

Bitwarden-Specific Code Patterns

  • Controlled Access (P05): Vault data access must remain restricted to explicit user actions or authorized contexts (e.g., autofill, user-joined organizations). Check for any new code path that grants access to vault data outside of explicit user control — including paths that could allow one organization member to access another member's vault data, or that expand collection/group access beyond what the user explicitly authorized.
  • Data Leaking (Definitions): Any unintentional departure of vault data from the Bitwarden secure environment is a leak. Check that vault data values, encryption keys, and metadata are not written to logs, error messages, telemetry, or any unprotected output channel.

Severity × Confidence Threshold Matrix

HIGH Confidence MEDIUM Confidence LOW Confidence
🔴 CRITICAL 🚨 Blocker ⚠️ Improvement 📝 Note
🟠 HIGH 🚨 Blocker ⚠️ Improvement ❌ Dismiss
🟡 MEDIUM ⚠️ Improvement 📝 Note ❌ Dismiss
🔵 LOW 📝 Note 📝 Note ❌ Dismiss
⚪ INFO 📝 Note ❌ Dismiss ❌ Dismiss

Severity Definitions

Severity Meaning Examples
🔴 CRITICAL Immediate exploitation risk; vault data exposure or zero-knowledge invariant violation SQLi, RCE, auth bypass, plaintext vault data reaching server
🟠 HIGH Serious vulnerability, exploit path exists XSS, IDOR, hardcoded secrets, privilege escalation
🟡 MEDIUM Exploitable with conditions or through chaining CSRF, open redirect, weak crypto, defense-in-depth failure
🔵 LOW Best practice violation, low direct risk Verbose errors, missing headers, hardening opportunity
⚪ INFO Observation worth noting, not a vulnerability Outdated dependency (no CVE), advisory note

Confidence Definitions

  • HIGH: Evidence directly supports the finding; not a pre-existing issue
  • MEDIUM: Likely real but may have mitigating context not visible in the diff
  • LOW: Speculative; probable false positive

Vulnerability Checklists

For OWASP Web Top 10, API Top 10, Mobile Top 10, and CWE Top 25 reference tables, read ../../analyzing-code-security/references/framework-checklists.md.

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    This skill coordinates a security code review by delegating tasks to specialized sub-agents. It includes instructions to bypass safety filters for the purpose of the audit and processes untrusted external data (git diffs), which presents a surface for indirect prompt injection.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at 44659bd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
What it can do
Runs commands Reads files Edits files
MCP servers
plugin_aikido_aikido-mcp
All 15 allowed tools
Bash(gh pr diff:*)Bash(gh pr view:*)Bash(gh repo view --json defaultBranchRef:*)Bash(git branch --show-current:*)Bash(git diff:*)Bash(git log:*)Bash(git merge-base:*)Bash(git remote get-url:*)Bash(git rev-parse:*)Bash(printenv GITHUB_ACTIONS)ReadSkillTaskWritemcp__plugin_aikido_aikido-mcp__aikido_issues_list
Other metadata
argument-hint
[--output <chat|file|github>] [--output-dir <path>] [--model <model>] [--base-ref <ref>] [pr-number-or-url|commit-sha|duration]
  • security-review
  • code-review
  • vulnerability-assessment
  • bitwarden
  • multi-agent
  • github
  • secrets
  • dependencies
  • architecture
  • threat-modeling

README badge

README badge for bitwarden/ai-plugins/perform-security-review

Orchestrates a multi-agent security code review by delegating to specialized agents covering injection flaws and OWASP top risks, secrets and dependencies, security architecture and zero-knowledge invariant compliance, and threat modeling. Fetches GitHub scan evidence (code scanning, secret scanning, Dependabot) upfront and routes the diff and findings through a verification agent for triage and confidence rating before generating a classified report.

Generated from the current SKILL.md.

What security domains does this skill cover?
The skill coordinates four specialized agents covering code security (injection flaws, cryptography, OWASP A01-A05), secrets and dependencies (hardcoded credentials, vulnerable packages), security architecture (auth, encryption, zero-knowledge invariant), and threat perspective (data flows, privilege escalation, API abuse).
Can this skill review a GitHub PR, commit, or local changes?
Yes. The skill supports PR mode (PR number or URL), commit mode (commit SHA), time-based mode (duration like "last 48 hours"), local changes mode (unstaged/staged diffs), and branch comparison mode (current branch vs main).
Does this skill fetch GitHub Advanced Security scan results?
Yes. It pre-fetches code scanning, secret scanning, and Dependabot alerts from GitHub, then includes that evidence in agent prompts to triangulate and verify findings.
What output formats are supported?
The skill supports chat (inline), file (saved to disk with `--output-dir` option), and GitHub (posting results as a comment or check, if integrated).
Does this skill verify findings after the four agents report?
Yes. A fifth verification agent reviews all findings, applies the security-review-rubric severity/confidence matrix, and classifies each as Blocker, Improvement, Note, Strength, or Dismiss — but does not remove or introduce findings.

Generated from the current SKILL.md. These answers refresh after source changes.