All skills
nielsmadan avatar

/review-security

@6661de7

Security audit for vulnerabilities, secrets, and unsafe patterns. Use before releases, after adding auth code, or when reviewing third-party integrations.

Use this Skill: https://skilld.dev/gh/nielsmadan/agentic-coding/review-security

This session only. Nothing lands on disk.

referencessecurity-checklist.md

≈544 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Checklist — Code Examples & Commands

Injection (OWASP A03)

SQL Injection:

// BAD: String concatenation
const query = `SELECT * FROM users WHERE id = ${userId}`;

// GOOD: Parameterized query
const query = 'SELECT * FROM users WHERE id = ?';
db.query(query, [userId]);

Command Injection:

// BAD: Unsanitized input to shell
exec(`ls ${userInput}`);

// GOOD: Use array form or escape
execFile('ls', [sanitizedPath]);

XSS (Cross-Site Scripting):

// BAD: Direct HTML insertion
element.innerHTML = userContent;

// GOOD: Use textContent or sanitize
element.textContent = userContent;
// Or use DOMPurify for HTML
element.innerHTML = DOMPurify.sanitize(userContent);

Sensitive Data Exposure (OWASP A02)

Hardcoded Secrets:

// BAD: Secrets in code
const apiKey = 'sk-1234567890abcdef';
const password = 'admin123';

// GOOD: Environment variables
const apiKey = process.env.API_KEY;

Patterns to grep for:

password\s*=\s*['"][^'"]+['"]
api[_-]?key\s*=\s*['"][^'"]+['"]
secret\s*=\s*['"][^'"]+['"]
token\s*=\s*['"][^'"]+['"]
Bearer\s+[A-Za-z0-9\-_]+

False-positive filtering: Before reporting a match:

  • Skip lines containing example, placeholder, test, TODO, CHANGEME, or xxx
  • Skip files in test/, __tests__/, *_test.*, *.test.*, *.spec.*
  • Skip .md files (documentation examples)
  • If the matched value is a well-known placeholder (e.g., sk-... with all zeros, your-api-key-here), skip it

Logging Sensitive Data:

// BAD: Logging credentials
console.log('User login:', { email, password });

// GOOD: Redact sensitive fields
console.log('User login:', { email, password: '[REDACTED]' });

Security Misconfiguration (OWASP A05)

CORS Issues:

// BAD: Overly permissive
app.use(cors({ origin: '*' }));

// GOOD: Specific origins
app.use(cors({ origin: ['https://myapp.com'] }));

Dependency Vulnerabilities

Check commands by ecosystem:

# Node.js
npm audit
npx audit-ci --critical

# Python
pip-audit
safety check

# Ruby
bundle audit

# Go
govulncheck ./...

Source: SKILL.md on GitHub

1 warning6mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    This skill is a security auditing tool designed to scan codebases for vulnerabilities, secrets, and configuration issues. It operates by analyzing local file content and executing standard dependency audit tools.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at 6661de7. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
argument-hint
[--staged | --unpushed | --changed | --all]
effort
xhigh

README badge

README badge for nielsmadan/agentic-coding/review-security