Review Security Issue
Review a security concern through its authorized private workflow. Do not file or expand a vulnerability in a public issue; follow SECURITY.md. A direct request to review authorizes review only, not remediation. For unattended review, inspect current state:* label descriptions, maintainer assignments, and comments to verify that review is authorized.
Assess
- Fetch the issue and comments with
gh issue view <id> --json title,body,state,labels,comments. Inspect current repository labels rather than assuming exact names. Verify that this is an authorized security issue and that a prior review does not already answer the request. - Inspect affected code and verify the claim. Assess impact, exploitability, prerequisites, affected surface, and a concrete attack scenario. Separate evidence from assumptions and give a severity with rationale.
- If actionable, propose a remediation plan with code areas, safe rollout, and focused tests. If not actionable, explain the evidence and recommended disposition. Do not decide product acceptance or silently close the issue.
- Post the review only when the request authorizes posting. Begin the comment with
> **🔒 security-review-agent**so later reviews can detect it. Keep sensitive details in the authorized private venue.
A human decides whether to authorize remediation. Route an authorized fix to fix-security-issue. Do not introduce agent:* workflow labels.