security-review
Review a design, PR, or feature for security issues before it ships. Use when asked to do a security review, security-review a change/PR, or check a…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Security Review Skill
A security review is a focused pass for the ways a change could be abused — before it reaches production.
This skill reviews a design, PR, or feature against the recurring risk areas, ranks findings by severity, and
gives a clear verdict with concrete fixes. It's for code/systems you own or are authorized to review, and it
complements (not replaces) automated scanners and a formal pentest.
Required Inputs
Ask for these only if they aren't already provided:
- What's under review — the design/diff/feature, and what it does.
- Context — the stack, where it runs, what data/permissions it touches, who can reach it (internet-facing? authenticated?).
- Sensitivity — the assets involved (PII, credentials, money, admin capability) and the threat context.
Output Format
Security review: [change/feature]
Summary & verdict — one-line read and a call: ✅ ship / 🔁 fix-first / ⛔ block, with the gating issue(s).
Review by risk area — scan each and note findings:
- AuthN / AuthZ — is identity verified, and is every action authorized (incl. object-level / IDOR, privilege escalation)?
- Input handling — validation/encoding; injection (SQL/command/template), SSRF, path traversal, deserialization, XSS.
- Secrets & crypto — hard-coded secrets, key handling, weak/absent crypto, tokens in logs/URLs.
- Data exposure — over-broad responses, PII in logs/errors, missing encryption in transit/at rest, verbose errors.
- Dependencies & config — known-vuln libraries, insecure defaults, missing security headers, CORS, permissions.
- Abuse & availability — rate-limiting, resource exhaustion, business-logic abuse, missing audit logging.
Findings (ranked) — each with severity, where, why it's exploitable, and the fix:
| Severity | Area | Finding (how it's exploited) | Fix |
|---|---|---|---|
| 🔴 Critical/High | | | |
| 🟡 Medium | | | |
| 🔵 Low / hardening | | | |
What's done well — controls already in place (so they're kept).
Follow-ups — anything needing a scanner, a pentest, or a deeper look.
Quality Checks
- [ ] Every standard risk area is considered (authz incl. IDOR, input/injection, secrets, data exposure, deps, abuse)
- [ ] Findings are ranked by severity with a concrete, actionable fix each
- [ ] Exploitability is explained — why it's a real issue in this context, not a generic warning
- [ ] A clear ship / fix-first / block verdict names the gating issues
- [ ] Existing good controls are acknowledged; deeper follow-ups (scanner/pentest) are flagged
Anti-Patterns
- [ ] Do not produce a generic checklist — tie each finding to this code/design and its exploit path
- [ ] Do not rank everything the same — separate critical from hardening nits
- [ ] Do not report an issue without a fix — give the concrete remediation
- [ ] Do not miss authorization (IDOR/privilege) — it's the most common real-world web flaw
- [ ] Do not review code you don't own or aren't authorized to assess
Based On
Secure code/design review practice (OWASP Top 10 & ASVS risk areas, severity-ranked findings, actionable remediation).
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/pm-security/skills/security-review/SKILL.md同一个仓库里的其他技能
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 security-review 的技能。它们内容并不相同,别混用:
- mohitagw15856/pm-claude-skills — Review a design, PR, or feature for security issues before it ships. Use when asked to do
- mohitagw15856/pm-claude-skills — Review a design, PR, or feature for security issues before it ships. Use when asked to do