pr-security
Focused lens review: evaluate security vulnerabilities, edge cases, and adversarial paths in a PR. Use /pr-review for integrated multi-lens coverage.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Focused lens review: evaluate security vulnerabilities, edge cases, and adversarial paths in a PR. Use /pr-review for integrated multi-lens coverage.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Drive a feature end-to-end across multiple protocol sessions — the coordinator role's protocol home
Create a GitHub pull request from the current branch, deriving the PR body from the associated work item's plan and notes.
Holistic multi-lens PR review with adaptive lens selection, cross-lens synthesis, and structured findings; --self runs the same pipeline as an author's self-review. Use individual lens skills (/pr-correctness, /pr-security, etc.) for focused single-concern analysis.
Create a technical specification — `/spec short` for single-pass plans, `/spec` for full team-based investigation
Check project status, remaining tasks, and session context — USE FIRST when asked 'what's left', 'what should I do', 'remaining work', or status questions. Also: create, update, archive, search work items.
Focused lens review: trace the impact of PR changes on code outside the diff. Use /pr-review for integrated multi-lens coverage.
| name | pr-security |
| description | Focused lens review: evaluate security vulnerabilities, edge cases, and adversarial paths in a PR. Use /pr-review for integrated multi-lens coverage. |
| user_invocable | true |
| argument_description | [PR_number_or_URL] — PR to analyze for security vulnerabilities, input validation, auth/authz issues, and adversarial paths |
Focused variant. For holistic coverage, use /pr-review.
You are running the security lens — a focused review that evaluates PR changes for security vulnerabilities, edge cases, and adversarial attack paths. This lens examines input validation, injection risks, auth/authz boundaries, cryptographic misuse, secrets exposure, and concurrency issues. It complements the 8-point agent-code checklist in /pr-review; it targets security concerns, not general correctness.
Findings are structured JSON written to a shared work item. Posting to GitHub is a separate step via post-review.sh.
This lens resolves its model through the settings layer — the reviewer role in the pr-review ceremony — rather than inheriting the invoking session's model. When dispatching this skill (or this lens's analysis) as a subagent, resolve the binding once at launch preparation and stamp the result as the agent's model parameter, on the first launch and on every retry:
source ~/.lore/scripts/lib.sh
resolve_model_for_role reviewer pr-review
A resolver miss (non-zero exit or empty output) composes no model parameter — the agent inherits the invoking session's model — and is named alongside the presented findings. Never substitute a hardcoded tier for a miss. When this skill runs inline with no subagent, the analysis runs on the current session's model; /pr-review's lens batch applies this same routing at its Step 3b.
Argument provided: $ARGUMENTS
Parse the first token as a PR number (digits) or GitHub URL. Extract the numeric PR identifier.
If no PR identifier is found, ask the user for the PR number.
Resolve the repo owner/name from the git remote:
REMOTE_URL=$(git remote get-url origin)
Extract OWNER/REPO from the remote URL.
bash ~/.lore/scripts/fetch-pr-data.sh <PR_NUMBER>
gh pr diff <PR_NUMBER>
gh pr view <PR_NUMBER> --json files,title,body,commits
From the fetched data, identify:
isOutdated: true threads. Note any security concerns already raised to avoid duplication.Read review protocol sections (severity classification, enrichment, findings format, security methodology):
cat ~/.lore/claude-md/review-protocol/severity.md
cat ~/.lore/claude-md/review-protocol/enrichment.md
cat ~/.lore/claude-md/review-protocol/findings-format.md
cat ~/.lore/claude-md/review-protocol/review-voice.md
cat ~/.lore/claude-md/review-protocol/security-methodology.md
For each file with security-relevant changes, apply the Security Lens Methodology defined in the protocol:
3a. Input validation — For every function that accepts external input (user data, API parameters, file contents, environment variables, URL parameters):
3b. Injection risk analysis — For code that constructs queries, commands, or markup from dynamic data:
3c. Auth/authz boundary violations — For code that gates access to resources or operations:
3d. Cryptographic misuse — For code that uses cryptographic operations:
3e. Secrets exposure — For code changes that handle credentials, tokens, or keys:
3f. Edge cases (empty/null/concurrent) — Security-specific edge cases beyond general correctness:
3g. Adversarial path analysis — Think like an attacker:
3h. Finding grounding — Before finalizing each finding, trace the full chain from vulnerability to human/operational consequence: name the attack vector, identify who can exploit it, describe what they gain, specify what preconditions are needed, and land on the downstream impact (data exposure, service disruption, compliance violation, etc.).
name parameter is interpolated into shell command at line 42 without sanitization — an attacker with access to the API endpoint can inject arbitrary commands via ; <cmd>, gaining code execution on the server"name parameter is interpolated into shell command at line 42 without sanitization — any authenticated user can inject arbitrary commands via ; <cmd>, gaining code execution on the server and access to environment variables including database credentials and API keys"A finding that names only a class of vulnerability (e.g., "missing validation", "weak auth") without specifying the concrete exploit path is incomplete. A finding that stops at the exploit mechanism ("gains code execution") without stating the downstream consequence is weak. Reject vague findings and rewrite them with: the specific code location, the exploit mechanism, and the observable human/operational impact.
Scoping for large diffs: If more than ~10 files have security-relevant changes, prioritize: (1) authentication/authorization boundaries, (2) external input handlers, (3) cryptographic operations, (4) new endpoints or API surfaces. Apply full methodology to priority files; do a lighter pass on the rest.
Mandatory for every finding. For each finding, query the knowledge store using the canonical enrichment query in claude-md/review-protocol/enrichment.md (read into the protocol preamble in Step 3), substituting the finding topic for <topic>.
Attach relevant citations as knowledge_context entries in the finding. Follow the enrichment gate and output cap from the shared protocol. If no relevant knowledge is found, set knowledge_context to an empty array.
If a finding involves cross-boundary security concerns (auth checks spanning multiple modules, permission propagation across layers) and the knowledge store has no relevant entries, escalate per the Investigation Escalation protocol in claude-md/review-protocol/escalation.md. Budget: maximum 2 escalations per lens run.
5a. Build findings JSON conforming to the Findings Output Format schema in claude-md/review-protocol/findings-format.md:
{
"lens": "security",
"pr": <PR_NUMBER>,
"repo": "<OWNER>/<REPO>",
"findings": [...]
}
Classify each finding using the Severity Classification definitions. Default to suggestion when uncertain between blocking and suggestion. Typical severity patterns for this lens:
5b. Present findings to the user grouped by severity (blocking first, then suggestions, then questions). For each finding show: severity, title, file:line, body, and knowledge context. Strip internal protocol headers (**Grounding:**, **Severity:**, etc.) from user-visible output — these are internal scaffolding. The grounding content (the concrete attack vector or improvement claim) must be preserved as the substance of the finding.
5c. Write to work item. Create or update the shared lens review work item:
/work create pr-lens-review-<PR_NUMBER>
If the work item already exists, load it instead of creating a duplicate. Append the findings JSON under a ## Security Lens heading in notes.md as a fenced JSON code block.
5d. Notify about posting. After writing findings, remind the user:
Findings written to work item. To post as a PR review, run:
bash ~/.lore/scripts/post-review.sh <findings.json> --pr <PR_NUMBER> [--dry-run]
/remember PR security analysis from PR #<N> — capture: security patterns and conventions observed in the codebase, auth/authz architecture, input validation approaches, cryptographic usage patterns, secrets management practices. Use confidence: medium for reviewer observations. Skip: findings specific to this PR that don't generalize, style preferences.
gh auth login