secure-code-review
Installation
SKILL.md
When to Use
Use this skill when you need to systematically review source code for the vulnerability classes that account for the majority of security incidents in production systems: injection attacks, XSS, authorization bypass, and type-safety failures.
Invoke it for:
- Any codebase that constructs database queries, renders user input in HTML, or makes authorization decisions inline rather than via a shared framework
- Pull requests touching query construction, template rendering, or RPC handler registration
- Services that implement authentication, authorization, or rate-limiting directly in each handler rather than in a shared interceptor layer
- Assessing technical debt that may carry latent security risk (excessive nesting, primitive types used for security-sensitive data)
Do not invoke it for full threat modeling, infrastructure security review, or cryptographic design — those are separate concerns covered by other skills.
Context and Input Gathering
Before beginning the review, establish: