All skills
bitwarden avatar

/reviewing-security-architecture

@d5bc17c official
by bitwardenbitwarden/ai-plugins155 stars
20

This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess authorization design", or needs to evaluate system designs for authentication, authorization, data protection, or cryptographic correctness.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/reviewing-security-architecture

This session only. Nothing lands on disk.

referencesarchitectural-anti-patterns.md

≈302 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Architectural Anti-Patterns

Common security architecture anti-patterns and their fixes.

Implicit Trust Between Services

Services communicating over an internal network without authentication. An attacker who gains access to the internal network can impersonate any service.

Fix: Service-to-service authentication (mTLS, service tokens, managed identities).

Single Point of Failure in Security Path

All authentication going through a single service with no fallback or circuit breaking. If that service goes down, either everything is blocked (denial of service) or auth is bypassed (security failure).

Fix: Redundancy for critical security services, fail-closed behavior.

Insecure Defaults Requiring Opt-In Security

Features that are insecure by default and require developers to remember to enable security.

Fix: Secure by default. Security should be the default behavior that must be explicitly opted out of with justification.

Monolithic Auth with No Defense in Depth

A single authorization check at the API gateway with no enforcement in downstream services.

Fix: Authorization at every layer. The gateway check is a first line of defense, not the only one.

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive framework for reviewing security architectures, including authentication, authorization, and cryptographic patterns. It consists entirely of documentation and guidance without any executable code, network operations, or external dependencies. No security risks were identified.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at d5bc17c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
  • authentication
  • authorization
  • encryption
  • security-architecture
  • access-control
  • threat-modeling
  • token-handling
  • data-protection
  • trust-boundaries
  • cryptography

README badge

README badge for bitwarden/ai-plugins/reviewing-security-architecture

Evaluates system designs for authentication, authorization, data protection, and cryptographic correctness against established security patterns. Covers token handling, session management, role-based access control, encryption at rest and in transit, and trust boundary validation.

Generated from the current SKILL.md.

Does this skill cover both authentication and authorization?
Yes. It reviews token handling, session management, credential storage, role-based access control, and object-level authorization patterns.
What encryption standards does this skill evaluate?
It checks for AES-256 or equivalent at rest, TLS 1.2+ in transit, envelope encryption with key management, and end-to-end encryption in vault architectures.
Does this skill identify trust boundaries in system design?
Yes. It maps common trust boundaries (client-to-API, service-to-database, browser-to-extension) and validates input, authentication, authorization, and logging at each crossing.
Can this skill review password storage practices?
Yes. It evaluates whether passwords are hashed with modern KDFs like Argon2id, bcrypt, or PBKDF2, with unique salts and appropriate work factors.
Does this skill assess zero-trust principles in internal networks?
Yes. It reviews whether internal service-to-service calls enforce authentication, authorization, and encryption, rather than trusting network location alone.

Generated from the current SKILL.md. These answers refresh after source changes.