security-review

Installation
SKILL.md

Security Review

Audit code for vulnerabilities. Report each finding with: location (file:line), severity (CRITICAL/HIGH/MEDIUM/LOW), description, and fix.

Review Order (by priority)

  1. Secrets -- No hardcoded keys, tokens, or passwords. All secrets in env vars. .env* in .gitignore.
  2. Input validation -- All user input validated with Zod schemas. File uploads restricted (size, type, extension). No direct use of user input in queries.
  3. SQL injection -- All queries parameterized. No string concatenation in SQL.
  4. Auth/Authz -- Tokens in httpOnly cookies (not localStorage). Authorization checks before sensitive operations. RBAC enforced.
  5. XSS -- User HTML sanitized with DOMPurify. CSP headers configured. No unvalidated dangerouslySetInnerHTML.
  6. CSRF -- CSRF tokens on state-changing operations. SameSite=Strict on cookies.
  7. Rate limiting -- All API endpoints rate-limited. Stricter limits on expensive operations (search, AI generation).
  8. Data exposure -- No secrets in logs. Generic error messages for users. No stack traces exposed.
  9. Dependencies -- npm audit clean. Lock files committed.

Quick Checks

Installs
1
GitHub Stars
4
First Seen
Aug 11, 2026
security-review — cor-incorporated/claude-code-skills