Skip to main content
Run any Skill in Manus
with one click

security-reviewer

Stars29
Forks3
UpdatedJuly 15, 2026 at 23:02

Security review skill for the JPPhotoManager project (Spring Boot 3.4 / Java 21 backend + Angular 19 frontend). TRIGGER when code touches authentication, authorization, file I/O, user input handling, dependency changes, or data persistence — including when implementing OpenSpec tasks that affect any of these areas. Do not wait to be asked: run this review proactively after writing security-sensitive code. Covers dependency vulnerabilities, sensitive data handling, path traversal, injection, Spring Security misconfigurations, JWT/cookie security, and frontend storage anti-patterns. A full-codebase sweep of the whole web application produces one report per architecture layer instead of a single consolidated report — see "Full-Codebase Sweeps" below. Also TRIGGERS when asked to fix, address, resolve, or work through findings from an existing dated SECURITY_REVIEW_FINDINGS report — see "Fix Workflow" below.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly