All skills
getsentry avatar

/security-review

@3482d8d official
by Sentrygetsentry/skills1k stars
53

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

Use this Skill: https://skilld.dev/gh/getsentry/skills/security-review

This session only. Nothing lands on disk.

referencesinjection.md

≈1.7k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Injection Prevention Reference

Overview

Injection flaws occur when untrusted data is sent to an interpreter as part of a command or query. The attacker's hostile data tricks the interpreter into executing unintended commands or accessing data without proper authorization.

SQL Injection

Primary Defenses

1. Prepared Statements (Parameterized Queries) - REQUIRED

The database distinguishes between code and data regardless of user input.

// SAFE: Parameterized query
String query = "SELECT * FROM users WHERE username = ?";
PreparedStatement pstmt = connection.prepareStatement(query);
pstmt.setString(1, userInput);
# SAFE: Parameterized query
cursor.execute("SELECT * FROM users WHERE username = %s", (user_input,))
// SAFE: Parameterized query (node-postgres)
const result = await client.query('SELECT * FROM users WHERE id = $1', [userId]);

2. Stored Procedures

Safe when implemented without dynamic SQL construction.

// SAFE: Stored procedure
CallableStatement cs = connection.prepareCall("{call sp_getUser(?)}");
cs.setString(1, username);

3. Allow-list Input Validation

For elements that cannot be parameterized (table names, column names, sort order).

// SAFE: Allowlist for table names
switch(tableName) {
    case "users": return "users";
    case "orders": return "orders";
    default: throw new InputValidationException("Invalid table");
}

Vulnerable Patterns to Find

# VULNERABLE: String concatenation
query = "SELECT * FROM users WHERE name = '" + user_input + "'"

# VULNERABLE: f-string interpolation
query = f"SELECT * FROM users WHERE id = {user_id}"

# VULNERABLE: format() method
query = "SELECT * FROM users WHERE name = '{}'".format(user_input)
// VULNERABLE: Template literal
const query = `SELECT * FROM users WHERE id = ${userId}`;

// VULNERABLE: String concatenation
const query = "SELECT * FROM users WHERE name = '" + userName + "'";

ORM Safety Considerations

Django ORM

# SAFE: ORM methods
User.objects.filter(username=user_input)

# VULNERABLE: raw() with interpolation
User.objects.raw(f"SELECT * FROM users WHERE name = '{user_input}'")

# VULNERABLE: extra() with unvalidated input
User.objects.extra(where=[f"name = '{user_input}'"])

SQLAlchemy

# SAFE: ORM methods
session.query(User).filter(User.name == user_input)

# VULNERABLE: text() with interpolation
session.execute(text(f"SELECT * FROM users WHERE name = '{user_input}'"))

NoSQL Injection

MongoDB Injection Patterns

// VULNERABLE: User-controlled query operators
db.users.find({ username: req.body.username, password: req.body.password });
// Attack: { "username": "admin", "password": { "$gt": "" } }

// SAFE: Explicit type checking
const username = String(req.body.username);
const password = String(req.body.password);
db.users.find({ username: username, password: password });

Dangerous Operators

  • $where - Allows JavaScript execution
  • $regex - Can be used for ReDoS
  • $gt, $ne, $in - Query manipulation when user-controlled

OS Command Injection

Primary Defenses

1. Avoid Shell Commands - PREFERRED

Use language built-in functions instead of shell commands.

# VULNERABLE: Shell command
os.system(f"mkdir {directory_name}")

# SAFE: Built-in function
os.makedirs(directory_name, exist_ok=True)

2. Parameterization

# VULNERABLE: Shell=True with user input
subprocess.run(f"convert {input_file} {output_file}", shell=True)

# SAFE: List of arguments, shell=False
subprocess.run(["convert", input_file, output_file], shell=False)

3. Input Validation

# Allowlist for permitted commands
ALLOWED_COMMANDS = {"convert", "resize", "rotate"}
if command not in ALLOWED_COMMANDS:
    raise ValueError("Invalid command")

# Validate arguments against safe patterns
if not re.match(r'^[a-zA-Z0-9_\-\.]+$', filename):
    raise ValueError("Invalid filename")

Dangerous Characters

Block or escape: & | ; $ > < \ ! ' " ( ) { } [ ] \n \r

Language-Specific Dangerous Functions

Language Dangerous Functions
Python os.system(), subprocess.run(shell=True), os.popen(), eval(), exec()
JavaScript child_process.exec(), eval()
PHP exec(), shell_exec(), system(), passthru(), backticks
Ruby system(), exec(), backticks, %x{}
Java Runtime.exec(), ProcessBuilder with shell

LDAP Injection

Prevention

// SAFE: Escape special characters
String safeName = LdapEncoder.filterEncode(userName);
String filter = "(&(uid=" + safeName + ")(userPassword=" + safePassword + "))";

Characters to Escape in LDAP

  • Filter context: * ( ) \ NUL
  • DN context: \ # + < > ; " = /

Template Injection

Server-Side Template Injection (SSTI)

# VULNERABLE: User input in template
template = Template(f"Hello {user_input}")

# SAFE: Pass user input as variable
template = Template("Hello {{ name }}")
template.render(name=user_input)

Detection Payloads

  • Jinja2: {{7*7}} → 49
  • FreeMarker: ${7*7} → 49
  • Thymeleaf: [[${7*7}]] → 49

XPath Injection

Prevention

// VULNERABLE: String concatenation
String query = "//users/user[name='" + userName + "']";

// SAFE: Use parameterized XPath
XPathExpression expr = xpath.compile("//users/user[name=$name]");
expr.setVariable("name", userName);

Key Grep Patterns for Detection

# SQL Injection
grep -rn "execute.*+" --include="*.py"
grep -rn "raw_sql\|rawQuery\|raw(" --include="*.py" --include="*.js"
grep -rn "\\.query\\(.*\\+" --include="*.js"
grep -rn "\\$.*\\+" --include="*.php"

# Command Injection
grep -rn "os\\.system\\|subprocess\\.run.*shell=True\\|os\\.popen" --include="*.py"
grep -rn "child_process\\.exec" --include="*.js"
grep -rn "system(\\|exec(\\|shell_exec(" --include="*.php"

# Template Injection
grep -rn "Template(.*\\+" --include="*.py"
grep -rn "render_template_string" --include="*.py"

# LDAP Injection
grep -rn "ldap_search\\|ldap_bind" --include="*.py" --include="*.php"

References

Source: SKILL.md on GitHub

3 alerts2d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub2d

    The skill is a comprehensive security auditing tool designed to help AI agents identify vulnerabilities in codebases. It contains extensive documentation and examples of common security flaws (such as SQL injection, XSS, and supply chain attacks) to guide the analysis process. Automated scanner alerts regarding malware and code injection are false positives triggered by the inclusion of these educational examples within the documentation.

  • Socket2d

    1 alert: gptMalware

  • Snyk2d

    Risk: LOW · No issues

  • Runlayer7mo

    20/22 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at 3482d8d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
All 1 allowed tools
Read Grep Glob Bash Task
  • Security
  • code-review
  • vulnerabilities
  • owasp
  • injection
  • xss
  • authentication
  • authorization

README badge

README badge for getsentry/skills/security-review

Performs systematic security code review to identify exploitable vulnerabilities in injection, XSS, authentication, authorization, and cryptography. Reports only high-confidence findings after researching the codebase to confirm attacker-controlled input and framework mitigations, following OWASP guidelines.

Generated from the current SKILL.md.

Does this skill flag theoretical vulnerabilities or only confirmed exploitable issues?
Only HIGH CONFIDENCE findings—clear vulnerable patterns with attacker-controlled input confirmed through codebase research. Theoretical, best-practice, or defense-in-depth issues are not reported.
Will this skill review test files and commented code?
No. Test files, dead code, and commented code are excluded from review unless explicitly requested. Documentation strings are also skipped.
Does this skill flag hardcoded URLs or configuration values as SSRF vulnerabilities?
No. Server-controlled values like Django settings, environment variables, and hardcoded configuration are considered safe. Only user-input URLs are flagged as SSRF.
What languages and frameworks does this skill cover?
Python (Django, Flask, FastAPI), JavaScript/TypeScript (Node, Express, React, Vue, Next.js), Go, Rust, and Java (Spring). It loads language-specific guides to check for framework-mitigated patterns before flagging.
Does this skill check for hardcoded secrets and credentials?
Yes. Hardcoded passwords, API keys, AWS secrets, and private keys are always flagged as Critical severity.

Generated from the current SKILL.md. These answers refresh after source changes.