Review security
Stack-agnostic agentic-programming workflow skills + documentation scaffold
npx -y skills add gtrabanco/agentic-workflow --skill review-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 19 stars19 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
2.4 KB, as published. Nobody here has run it
Review Security (internal)
Composed by review-change / product-audit within their conversation — on any
agent, follow this file inline as the routed step. Findings only; never edits,
never refactors.
Scope
The diff or path/glob the caller passes; default the current change vs the default branch. State the scope at the top of the returned table.
Checklist (evaluate EVERY item — none is optional; n/a must be stated)
✓ No secrets/credentials/tokens in code, config, tests, or fixtures (grep the diff for key-like strings) ✓ Every external input on the changed paths is validated/sanitized before use ✓ No injection vectors (SQL/command/path/template) — parameterized/escaped, never concatenated ✓ AuthN/AuthZ enforced on every new/changed endpoint or entry point (cite where) ✓ No PII or secrets written to logs/error messages on the changed paths ✓ Webhooks/callbacks verify signatures before processing ✓ Rate limiting / abuse controls considered where a new public surface appears (n/a if none) ✓ New/updated dependencies pinned and free of known-critical advisories (state how you checked) ✓ Error responses don't leak stack traces or internal paths ✓ Unsafe deserialization / dynamic evaluation of untrusted data absent
Return exactly
REVIEW SECURITY — scope: <scope>
| # | Finding | Sev | Evidence | Suggested fix |
|---|---------|-----|----------|---------------|
| 1 | <what> | critical|major|minor | <file:line> | <smallest action> |
Checklist: <n> evaluated, <n> pass, <n> findings, <n> n/a (<which + why>)
Summary: <1-2 sentences>
Decision: PASS | FAIL
FAIL if any critical or major finding is open; PASS otherwise. Minor findings never block — they route to the caller's triage step.
Done when
- Every checklist item was evaluated with evidence (file:line or command output) or explicitly marked n/a with the reason.
- The fixed-format block above is returned — nothing more, nothing less — and no code was changed.