⚡AgentSkills
🔐 Cybersecurity · Application Security

Security-review code with a repeatable checklist

Focused pass over authz, injection, secrets, and deserialization on risky diffs.

intermediate~35 minSecurity EngineersAppSecDevSecOps

Steps

  1. 1Check authorization at object level: can user A read/write user B's records?
  2. 2Trace all external input into queries/commands/paths for injection sinks
  3. 3Scan diffs for hardcoded secrets; verify new config uses secret manager
  4. 4Flag unsafe deserialization and eval-adjacent constructs
  5. 5Verify security headers and CORS changes are intentional, not permissive defaults
  6. 6Document accepted risks inline with ticket references

Common Pitfalls

  • ▲IDOR missed because tests only use one user
  • ▲'Temporary' debug endpoints reaching production

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill application-security-secure-code-review
Install globally
$ npx skills add aniruddhaadak80/skills --skill application-security-secure-code-review -g

Tags

#code-review#appsec#owasp#cybersecurity#application-security

Related skills

STRIDE-lite walkthrough producing mitigations wired into tickets before code exists.

🔐 Cybersecurity·~40m

Generation, storage, rotation, and leak response for credentials humans inevitably touch.

🔐 Cybersecurity·~25m