All skills
bitwarden avatar

/reviewing-security-architecture

@d5bc17c official
by bitwardenbitwarden/ai-plugins155 stars
20

This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess authorization design", or needs to evaluate system designs for authentication, authorization, data protection, or cryptographic correctness.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/reviewing-security-architecture

This session only. Nothing lands on disk.

referencescrypto-algorithms.md

≈485 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cryptographic Patterns

Algorithm Selection

Use Case Recommended Deprecated / Avoid
Symmetric encryption AES-256-GCM, ChaCha20-Poly1305 DES, 3DES, AES-ECB, Blowfish
Hashing SHA-256, SHA-384, SHA-512, BLAKE2 MD5, SHA-1
Password hashing Argon2id, bcrypt, PBKDF2 (high iterations) MD5, SHA-*, plain bcrypt with low cost
Asymmetric encryption RSA-OAEP (2048+ bits), ECIES RSA-PKCS1v1.5, RSA < 2048 bits
Digital signatures Ed25519, ECDSA P-256, RSA-PSS RSA-PKCS1v1.5, DSA
Key exchange ECDH P-256, X25519 DH with small primes
Random generation RandomNumberGenerator (.NET), crypto.getRandomValues() (JS) Math.random(), System.Random

Common Crypto Anti-Patterns

ECB Mode

// WRONG — ECB mode (reveals patterns in plaintext)
var aes = Aes.Create();
aes.Mode = CipherMode.ECB;

// CORRECT — GCM mode (authenticated encryption)
var aesGcm = new AesGcm(key);

Predictable IV

// WRONG — predictable IV
var iv = new byte[16]; // All zeros

// CORRECT — random IV for each encryption operation
var iv = RandomNumberGenerator.GetBytes(16);

Insecure Random

// WRONG — Math.random() for security-sensitive values
const token = Math.random().toString(36);

// CORRECT — cryptographic random
const token = crypto.getRandomValues(new Uint8Array(32));

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive framework for reviewing security architectures, including authentication, authorization, and cryptographic patterns. It consists entirely of documentation and guidance without any executable code, network operations, or external dependencies. No security risks were identified.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at d5bc17c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
  • authentication
  • authorization
  • encryption
  • security-architecture
  • access-control
  • threat-modeling
  • token-handling
  • data-protection
  • trust-boundaries
  • cryptography

README badge

README badge for bitwarden/ai-plugins/reviewing-security-architecture

Evaluates system designs for authentication, authorization, data protection, and cryptographic correctness against established security patterns. Covers token handling, session management, role-based access control, encryption at rest and in transit, and trust boundary validation.

Generated from the current SKILL.md.

Does this skill cover both authentication and authorization?
Yes. It reviews token handling, session management, credential storage, role-based access control, and object-level authorization patterns.
What encryption standards does this skill evaluate?
It checks for AES-256 or equivalent at rest, TLS 1.2+ in transit, envelope encryption with key management, and end-to-end encryption in vault architectures.
Does this skill identify trust boundaries in system design?
Yes. It maps common trust boundaries (client-to-API, service-to-database, browser-to-extension) and validates input, authentication, authorization, and logging at each crossing.
Can this skill review password storage practices?
Yes. It evaluates whether passwords are hashed with modern KDFs like Argon2id, bcrypt, or PBKDF2, with unique salts and appropriate work factors.
Does this skill assess zero-trust principles in internal networks?
Yes. It reviews whether internal service-to-service calls enforce authentication, authorization, and encryption, rather than trusting network location alone.

Generated from the current SKILL.md. These answers refresh after source changes.