Performing Security Code ReviewBLOCK
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Bundled resources for security-agent skill
- [ ] report_template.md: A Markdown template for generating security review reports with placeholders for findings, severity ratings, and remediation advice.
- [ ] examplecodevulnerable.py: Example code snippets demonstrating common vulnerabilities.
- [ ] examplecodesecure.py: Corresponding secure code snippets demonstrating how to remediate the vulnerabilities.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: performing-security-code-review description: 'Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like ''security scan'', ''audit'', or ''vulnerability''. ' allowed-tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*) version: 1.28.0 author: Jeremy Longshore <[email protected]> license: MIT tags: - example - security - authentication - audit compatibility: Designed for Claude Code --- # Performing Security Code Review ## Overview Conducts security-focused code reviews by scanning source files for common vulnerability patterns including SQL injection, XSS, authentication flaws, insecure dependencies, and secret exposure. Produces structured severity-rated reports with specific remediation guidance. ## Prerequisites - Read access to all source files in the target project - `grep` available on PATH for pattern matching - Access to `package.json` or equivalent dependency manifest for dependency auditing - Familiarity with OWASP Top 10 vulnerability categories ## Instructions 1. Identify the scope of the review: specific files, directories, or the entire codebase. Confirm the primary language(s) and framework(s) in use. 2. Scan for hardcoded secrets and credentials: - Search for patterns matching API keys, tokens, passwords, AWS access keys (`AKIA...`), and private key headers (`BEGIN PRIVATE KEY`). - Flag any `.env` files or configuration files containing plaintext secrets. 3. Analyze code for injection vulnerabilities: - Identify raw SQL string concatenation (SQL injection risk). - Locate unsanitized user input rendered in HTML (XSS risk). - Check for `eval()`, `exec()`, or `Function()` calls with dynamic input (code injection risk). 4. Review authentication and authorization logic: - Verify password hashing uses strong algorithms (bcrypt, argon2) rather than MD5/SHA1. - Check for missing authentication on sensitive endpoints. - Identify overly permissive CORS configurations. 5. Audit dependencies for known vulnerabilities: - Run `npm audit` or equivalent package manager audit command. - Cross-reference dependency versions against known CVE databases. 6. Check for insecure communication patterns: - Flag HTTP URLs where HTTPS is expected. - Identify disabled TLS certificate verification. 7. Compile findings into a structured report sorted by severity (Critical, High, Medium, Low), including the vulnerable code location, explanation, and remediation steps. ## Output A structured security review report containing: - Summary with total findings count by severity level - Per-finding entries with: file path, line number, vulnerability type, severity, code snippet, explanation, and recommended fix - Dependency audit results with CVE identifiers where applicable - Overall risk assessment (Critical / High / Medium / Low / Clean) ## Error Handling | Error | Cause | Solution | |---|---|---| | No source files found | Incorrect scope path or empty directory | Verify the target directory path and confirm it contains source files | | Binary files in scan | Non-text files matched by search patterns | Exclude binary extensions and `node_modules/` from scans | | Dependency manifest missing | No `package.json`, `requirements.txt`, or equivalent | Skip dependency audit; note in report that dependency analysis was not possible | | Permission denied on files | Restricted file access | Request read permissions or narrow the review scope to accessible files | | False positive on secret pattern | Benign string matching secret regex | Verify context before reporting; mark as potential false positive if the match appears in test fixtures or documentation | ## Examples **SQL injection review:** Trigger: "Review this database query code for SQL injection vulnerabilities." Process: Scan all files containing SQL query construction. Identify string concatenation with user input (`"SELECT * FROM users WHERE id = " + userId`). Report as High severity with remediation: use parameterized queries or prepared statements. **Dependency vulnerability scan:** Trigger: "Check this project's dependencies for known security vulnerabilities." Process: Run `npm audit` on the project. Parse output for vulnerabilities. Report each finding with CVE identifier, affected package, installed version, and patched version. Recommend `npm audit fix` or manual version pinning. **Full codebase security audit:** Trigger: "Run a security scan on this codebase." Process: Execute all seven scan categories (secrets, injection, auth, dependencies, communication, dangerous commands, obfuscation). Produce a comprehensive report with findings grouped by category and sorted by severity. ## Resources - [OWASP Top 10](https://owasp.org/www-project-top-ten/) -- industry-standard vulnerability classification - [Node.js Security Checklist](https://blog.risingstack.com/node-js-security-checklist/) -- Node-specific security guidance - [CWE/SANS Top 25](https://cwe.mitre.org/top25/) -- most dangerous software weaknesses - `${CLAUDE_SKILL_DIR}/references/README.md` -- bundled reference materials
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
obj = pickle.loads(decoded_data)
print(f"Secure random token: {token}")salt = bytes.fromhex(salt_hex)
stored_hash = bytes.fromhex(hash_hex)
decoded_data = base64.b64decode(serialized_data)
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__performing-security-code-review.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | BLOCK | D | 69 | first audit |
Questions
What does the Performing Security Code Review skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Performing Security Code Review safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Performing Security Code Review access on my machine?
The audit observed that it runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.
Which assistants does Performing Security Code Review work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.