agentsclimarketplace

Security review

Skill iCodeCraft/anti-slop/skills/security-review

Drop-in skills that stop AI coding agents from shipping garbage — kill-slop, security-review, PR hygiene

Install
npx -y skills add iCodeCraft/anti-slop --skill security-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • 18 days oldThe repository was created 18 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
  • 23 stars23 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review code for security issues before merge — authz gaps, injection, secrets, unsafe defaults, SSRF, path traversal. Use when reviewing a PR, auditing a diff, shipping auth/payments/uploads, or when the user asks for a security review or OWASP check.

SKILL.md

2.2 KB, as published. Nobody here has run it

Security Review

Review the current change like a security-minded senior. Prefer concrete findings over generic advice.

Scope

Focus on the diff and directly related call paths. Do not audit the whole repo unless asked.

Checklist

Auth & access

  • Every sensitive action checks authentication and authorization
  • IDs from the client are not trusted for ownership (userId in body ≠ proof)
  • Admin/debug routes are gated; no "temporary" open endpoints

Input & data

  • User input is validated at the boundary (type, length, allowlist)
  • SQL/NoSQL/search queries are parameterized — no string concat
  • HTML/Markdown/user content is escaped or sanitized where rendered
  • File uploads: size limits, type allowlist, stored outside web root, randomized names
  • Path joins cannot escape intended directories (../)

Secrets & config

  • No secrets in source, logs, client bundles, or example env files with real values
  • New env vars documented; defaults are safe for production
  • Tokens/passwords not written to analytics or error trackers

Network & server

  • Outbound fetches do not accept raw user URLs without allowlisting (SSRF)
  • CORS is least-privilege; credentials only when required
  • Cookies: HttpOnly, Secure, SameSite where applicable

Dangerous APIs

  • No eval, dangerouslySetInnerHTML, shell exec with unsanitized input
  • Deserialization of untrusted data is avoided or hardened
  • Crypto/auth libraries are standard — no home-rolled JWT/crypto

Output format

Group findings:

SeverityRuleWhereWhy it mattersFix
Critical / High / Medium / Low / Noteshort namefile:line or symbol1 sentenceconcrete change

End with:

  • Blockers — must fix before merge
  • Safe to ship with follow-ups — optional

If no issues: say so explicitly and list what you checked.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.