Skip to main content

security-review

Perform a security-focused review of current git changes. Use when reviewing staged/unstaged diffs, checking for vulnerabilities, and deciding merge readiness.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
SpecterOps/skills
آخر نشاط في المصدر
٢٩ مايو ٢٠٢٦ في ١٥:٥١
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٦٢٥
التفرعات
٦٨

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

مستكشف الملفات
4 ملفات

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
security-review
description
Perform a security-focused review of current git changes. Use when reviewing staged/unstaged diffs, checking for vulnerabilities, and deciding merge readiness.
metadata
{"author":"GhostWorks"}
# Security Review Review local git changes with emphasis on exploitability, trust boundaries, and safe-by-default behavior. ## Input Parsing Accept input as: `SCOPE` Supported scopes: - `all` (default): staged and unstaged changes - `staged`: only staged changes - `unstaged`: only unstaged changes Examples: - `$security-review` - `$security-review staged` - `$security-review unstaged` ## Review Workflow 1. Determine scope: - staged: `git diff --staged` - unstaged: `git diff` - all: both 2. Run `git status` for context. 3. Read full changed files (not only hunks) to catch cross-function issues. 4. Analyze findings by categories below. 5. Report findings ordered by severity with actionable fixes. 6. Provide merge verdict (`safe to merge`, `needs fixes`, `needs rework`). ## Security Categories - Injection risks: SQL/command/LDAP/template/XSS paths. - Secrets exposure: API keys, credentials, tokens, private keys, connection strings. - Path/file handling: traversal, unsafe joins, arbitrary read/write. - Insecure deserialization: unsafe loaders, implicit object decoding. - Crypto misuse: weak algorithms, static keys/IVs, incorrect modes. - SSRF/open redirect: unvalidated URLs or callback targets. - AuthN/AuthZ flaws: missing checks, IDOR, privilege escalation. - Session/JWT issues: weak secrets, missing expiry/validation, algorithm confusion. - CORS and headers: overly permissive policies, missing protective headers. ## Correctness and Reliability - Boundary and off-by-one issues. - Error handling gaps that leak sensitive details. - Resource lifecycle leaks. - Concurrency/race condition hazards. ## Reporting Format For each finding include: - `severity` - `file:line` - `issue` - `impact` - `recommended fix` Then include: - total findings by severity - overall merge verdict ## Quality Rules - Focus findings first; keep summary brief. - Avoid speculative claims without code evidence. - Prefer concrete fix guidance over generic advice.
عرض على GitHub