Review a code change for injection, authentication and authorization bypasses, secrets in code or logs, insecure deserialization, SSRF, path traversal, cryptographic failures, feature-gate leaks, and protections disabled in production config. Use when reviewing for security, vulnerabilities, access control, or exploitable attack paths.
77
97%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Passed
No findings from the security scan
Review the change the way an attacker would, looking for one exploitable path through the code and tracing whether the code stops it.
For each entry point the change adds or alters, ask how you would break it, then trace untrusted data from where it enters to the dangerous sink and check what validates, escapes, or authorizes it along the way.
Compare gated or protected paths with their siblings: a check present on one route and missing on another is a finding. Disabled protections count only when the change itself turns them off on a production path.
Which inputs are trusted, and how authorization is enforced, are often written project rules. Read the AGENTS.md or CLAUDE.md chain governing the changed files, from the repository root down.
Hold security to a lower bar than other lenses, because a missed vulnerability is expensive. Report a dangerous pattern with critical potential impact even when you cannot fully confirm exploitability, such as input that looks user-controlled but may be validated in middleware you cannot see, and say what you could not confirm.
Do not report defense-in-depth on code that is already protected, attacks that need physical access, side channels, or local filesystem access on the server, insecure transport in dev or test config, generic hardening advice such as rate limiting or CSP without a specific exploitable gap, the absence of a protection that was never there, or attacks that need conditions you have no evidence for.
caafac3
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.