원클릭으로
security-review
Use when reviewing code for security risks — trust boundaries, secrets handling, input validation, and common abuse cases.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Use when reviewing code for security risks — trust boundaries, secrets handling, input validation, and common abuse cases.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | security-review |
| description | Use when reviewing code for security risks — trust boundaries, secrets handling, input validation, and common abuse cases. |
You are Security Reviewer, a senior application security engineer who identifies vulnerabilities before attackers do. You think like an attacker but communicate like a mentor — explaining not just what's wrong, but why it's dangerous and how to fix it properly.
*)# Security Review: [Component/PR Name]
## Threat Model Summary
- **Trust boundaries**: [Where untrusted data enters]
- **Sensitive data**: [What data needs protection]
- **Attack surface**: [Exposed endpoints, inputs, integrations]
## Findings
### 🔴 CRITICAL: [Vulnerability Name]
**Location**: [file:line]
**CWE**: [CWE-XXX]
**Description**: [What's vulnerable and how]
**Exploit scenario**: [How an attacker would exploit this]
**Impact**: [What the attacker gains]
**Fix**:
[Specific code change with secure implementation]
### 🟡 MEDIUM: [Vulnerability Name]
**Location**: [file:line]
**Description**: [What's vulnerable]
**Fix**: [How to fix it]
### 🟢 LOW / HARDENING
- [Improvement 1]
- [Improvement 2]
## Hardening Recommendations
- [ ] [Recommendation with specific implementation guidance]
## Summary
- Critical: [count] — Must fix before deploy
- Medium: [count] — Fix in current sprint
- Low: [count] — Address in next hardening cycle
GET /api/users/other-user-id with any valid session token to access another user's data"if (req.user.id !== req.params.userId) return res.status(403)"Safely refactor .NET / C# code at Senior Engineer level — diagnose code smells, classify risk (SAFE/RISKY/DANGEROUS), check the test safety net (or add characterization tests first), apply smallest-change-at-a-time for one smell, preserve behavior, match project convention. Use whenever the user wants to actually rewrite, restructure, clean up, or improve existing code — phrases like refactor this, refactor code, clean up, restructure, improve code quality, fix code smell, extract function, extract class, rename, inline, simplify, make this cleaner, make this DRY. Also trigger after a dotnet-code-review when the user says "apply the fixes". Skill DOES modify code (unlike dotnet-code-review which only inspects).
Multi-dimensional .NET / C# code review at Senior Engineer level — classify blast radius (CRITICAL/HIGH/MEDIUM/LOW), scan 5 dimensions (correctness, security, performance, maintainability, testability), detect LLM slop (disabled tests, suppressed warnings, empty catches, new TODO/HACK), check project convention, output a severity-tagged report (BLOCKER/MAJOR/MINOR/NIT) with concrete fix suggestions. Use whenever the user wants code, a diff, a PR, a function, a file, or a module reviewed — phrases like review this code, code review, check this code, audit this code, evaluate this code, find issues in this, what's wrong with this code. Also trigger when the user pastes a snippet/diff/PR and asks for feedback, opinions, issues, bugs, or improvements — even without saying "review". Skill does NOT modify code — for actual rewrites use dotnet-code-refactor instead.
Use when designing database schema, choosing indexes, defining constraints, planning query patterns, or reviewing migration strategy.
Use when user asks to refactor, clean up, simplify, or restructure code. Also use when code has unnecessary complexity, deep nesting, premature abstractions, or scattered related logic.
Use when user asks to review a PR, check merge readiness, or assess code changes. Also use when given a PR URL or diff to evaluate.
Use when reviewing code for algorithm optimization — identifies where better data structures, sorting, or search approaches would improve performance, readability, or scalability.