🔐 Cybersecurity · Application Security
Security-review code with a repeatable checklist
Focused pass over authz, injection, secrets, and deserialization on risky diffs.
intermediate~35 minSecurity EngineersAppSecDevSecOps
Steps
- 1Check authorization at object level: can user A read/write user B's records?
- 2Trace all external input into queries/commands/paths for injection sinks
- 3Scan diffs for hardcoded secrets; verify new config uses secret manager
- 4Flag unsafe deserialization and eval-adjacent constructs
- 5Verify security headers and CORS changes are intentional, not permissive defaults
- 6Document accepted risks inline with ticket references
Common Pitfalls
- ▲IDOR missed because tests only use one user
- ▲'Temporary' debug endpoints reaching production
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill application-security-secure-code-reviewInstall globally
$ npx skills add aniruddhaadak80/skills --skill application-security-secure-code-review -gTags
#code-review#appsec#owasp#cybersecurity#application-security