security-review
Installation
SKILL.md
Security Review
Audit code for vulnerabilities. Report each finding with: location (file:line), severity (CRITICAL/HIGH/MEDIUM/LOW), description, and fix.
Review Order (by priority)
- Secrets -- No hardcoded keys, tokens, or passwords. All secrets in env vars.
.env*in.gitignore. - Input validation -- All user input validated with Zod schemas. File uploads restricted (size, type, extension). No direct use of user input in queries.
- SQL injection -- All queries parameterized. No string concatenation in SQL.
- Auth/Authz -- Tokens in httpOnly cookies (not localStorage). Authorization checks before sensitive operations. RBAC enforced.
- XSS -- User HTML sanitized with DOMPurify. CSP headers configured. No unvalidated
dangerouslySetInnerHTML. - CSRF -- CSRF tokens on state-changing operations.
SameSite=Stricton cookies. - Rate limiting -- All API endpoints rate-limited. Stricter limits on expensive operations (search, AI generation).
- Data exposure -- No secrets in logs. Generic error messages for users. No stack traces exposed.
- Dependencies --
npm auditclean. Lock files committed.