All skills
jwynia avatar

/security-scan

@99a8797
by J Wyniajwynia/agent-skills160 stars
20

Scan code for security vulnerabilities including OWASP Top 10, secrets, and misconfigurations. Use when you need comprehensive security analysis of a codebase.

Use this Skill: https://skilld.dev/gh/jwynia/agent-skills/security-scan

This session only. Nothing lands on disk.

referencespatternspython.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Python Security Patterns

Language-specific vulnerability detection patterns.

Injection Vulnerabilities

SQL Injection

# String formatting in queries
cursor\.execute\s*\([^)]*%\s*\(
cursor\.execute\s*\([^)]*%\s*[a-zA-Z_]
cursor\.execute\s*\([^)]*\.format\s*\(
cursor\.execute\s*\(f['"]
cursor\.executemany\s*\([^)]*%

# ORM raw queries
\.raw\s*\([^)]*%
\.raw\s*\(f['"]
\.extra\s*\([^)]*%
RawSQL\s*\([^)]*%

# Django
objects\.raw\s*\([^)]*%
objects\.raw\s*\(f['"]
connection\.cursor\s*\(\s*\)\.execute\s*\([^)]*%

Command Injection

# os module
os\.system\s*\([^)]*\+
os\.system\s*\(f['"]
os\.popen\s*\([^)]*\+
os\.popen\s*\(f['"]

# subprocess with shell
subprocess\.(call|run|Popen)\s*\([^)]*shell\s*=\s*True
subprocess\.(call|run|Popen)\s*\([^)]*\+[^)]*shell\s*=\s*True

# eval/exec
eval\s*\([^)]*request\.
exec\s*\([^)]*request\.
compile\s*\([^)]*request\.

# Python 2
commands\.getoutput\s*\(
commands\.getstatusoutput\s*\(

Template Injection

# Jinja2 unsafe
render_template_string\s*\([^)]*\+
render_template_string\s*\(f['"]
Template\s*\([^)]*\+
Markup\s*\([^)]*\+

# Django templates
Template\s*\([^)]*request\.
mark_safe\s*\([^)]*request\.

Cryptographic Issues

Weak Hashing

hashlib\.md5\s*\(
hashlib\.sha1\s*\(
hashlib\.new\s*\(\s*['"]md5['"]
hashlib\.new\s*\(\s*['"]sha1['"]

# PyCrypto
MD5\.new\s*\(
SHA\.new\s*\(

# Without salt for passwords
hashlib\.\w+\s*\([^)]*password

Weak Random

random\.random\s*\(
random\.randint\s*\(
random\.choice\s*\(
random\.randrange\s*\(
# When used for security (tokens, IDs, passwords)

Hardcoded Secrets

# Secret keys
(SECRET_KEY|secret_key)\s*=\s*['"][^'"]+['"]
(API_KEY|api_key)\s*=\s*['"][a-zA-Z0-9]{16,}['"]

# Passwords
(PASSWORD|password|passwd)\s*=\s*['"][^'"]+['"]

# Database URIs with credentials
(DATABASE_URL|database_url)\s*=\s*['"][^'"]*:[^@]*@

Insecure TLS

verify\s*=\s*False
ssl\._create_unverified_context
ssl\.CERT_NONE
urllib3\.disable_warnings\s*\(
requests\.(get|post|put|delete)\s*\([^)]*verify\s*=\s*False

Deserialization

# Pickle (dangerous with untrusted data)
pickle\.loads?\s*\(
cPickle\.loads?\s*\(
_pickle\.loads?\s*\(
shelve\.open\s*\(

# YAML without safe loader
yaml\.load\s*\([^)]*\)(?!.*Loader)
yaml\.load\s*\([^)]*Loader\s*=\s*yaml\.Loader
yaml\.unsafe_load\s*\(

# Marshal
marshal\.loads?\s*\(

# Dill
dill\.loads?\s*\(

Path Traversal

# File operations with user input
open\s*\([^)]*request\.(GET|POST|args|form|data)
open\s*\(f['"][^'"]*\{.*request
os\.path\.join\s*\([^)]*request\.
shutil\.(copy|move|rmtree)\s*\([^)]*request\.

# Django
FileResponse\s*\([^)]*request\.
sendfile\s*\([^)]*request\.

SSRF

# Requests library
requests\.(get|post|put|delete|head|patch)\s*\([^)]*request\.(GET|POST|args|form)
requests\.(get|post|put|delete|head|patch)\s*\(f['"]

# urllib
urllib\.request\.urlopen\s*\([^)]*request\.
urllib\.request\.urlretrieve\s*\([^)]*request\.

# httpx
httpx\.(get|post|put|delete)\s*\([^)]*request\.

Authentication Issues

Weak Password Policy

len\s*\(\s*password\s*\)\s*>=?\s*[1-7]\b
if\s+len\s*\(\s*password\s*\)\s*<\s*[2-7]:
MIN_PASSWORD_LENGTH\s*=\s*[1-7]\b

Session Issues

# Session in cookies without secure flag
SESSION_COOKIE_SECURE\s*=\s*False
SESSION_COOKIE_HTTPONLY\s*=\s*False

# Flask session secret
app\.secret_key\s*=\s*['"][^'"]+['"]

# Debug mode
DEBUG\s*=\s*True
app\.run\s*\([^)]*debug\s*=\s*True

Django-Specific

Security Settings

# Dangerous settings
DEBUG\s*=\s*True
ALLOWED_HOSTS\s*=\s*\[['"]?\*['"]?\]
CSRF_COOKIE_SECURE\s*=\s*False
SESSION_COOKIE_SECURE\s*=\s*False
SECURE_SSL_REDIRECT\s*=\s*False

Template Issues

# Unescaped output
\{\{[^}]*\|safe\}\}
mark_safe\s*\(
format_html\s*\([^)]*\+

ORM Issues

# Raw SQL
\.raw\s*\(
\.extra\s*\(
RawSQL\s*\(
cursor\.execute\s*\(

Flask-Specific

Security Issues

# Debug mode
app\.run\s*\([^)]*debug\s*=\s*True
FLASK_DEBUG\s*=\s*1

# Secret key
app\.secret_key\s*=\s*['"]

# Template injection
render_template_string\s*\([^)]*request\.

FastAPI-Specific

Security Issues

# Debug/docs in production
app\s*=\s*FastAPI\s*\([^)]*docs_url
app\s*=\s*FastAPI\s*\([^)]*redoc_url

# Missing auth on endpoints
@app\.(get|post|put|delete)\s*\([^)]*\)\s*\n(async\s+)?def\s+\w+\s*\([^)]*\)(?!.*Depends)

Logging Issues

# Sensitive data in logs
(logging|logger)\.\w+\s*\([^)]*password
(logging|logger)\.\w+\s*\([^)]*secret
(logging|logger)\.\w+\s*\([^)]*token
(logging|logger)\.\w+\s*\([^)]*api_key
print\s*\([^)]*password
print\s*\([^)]*secret

Regex Denial of Service

# Nested quantifiers
re\.compile\s*\([^)]*(\+|\*)[^)]*(\+|\*)
re\.(match|search|findall)\s*\([^)]*(\+|\*)[^)]*(\+|\*)

Secure Patterns (False Positive Filtering)

# Parameterized queries
cursor\.execute\s*\([^)]*,\s*\[
cursor\.execute\s*\([^)]*,\s*\(
%s[^%]*,\s*\(

# Secure random
secrets\.token_
secrets\.choice\s*\(
os\.urandom\s*\(
random\.SystemRandom\s*\(

# Safe YAML
yaml\.safe_load\s*\(
yaml\.load\s*\([^)]*Loader\s*=\s*yaml\.SafeLoader

# Input sanitization
bleach\.clean\s*\(
escape\s*\(
quote\s*\(

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The security-scan skill is a comprehensive utility designed to guide an AI agent through the process of auditing codebases for security vulnerabilities. It provides structured detection patterns for OWASP Top 10 flaws, hardcoded secrets, and cryptographic weaknesses across various programming languages. The skill serves as a reference and instruction set for static analysis and does not contain any malicious code, unauthorized network operations, or persistence mechanisms.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    9/9 files flagged

Signed by skilld at 99a8797. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago
Other metadata
metadata
{
  "author": "jwynia",
  "version": "1.0",
  "type": "utility",
  "mode": "evaluative",
  "domain": "development"
}

README badge

README badge for jwynia/agent-skills/security-scan