Atlas / Skills / jeremylongshore / Performing Security Code Review

Performing Security Code ReviewBLOCK

skills/jeremylongshore/performing-security-code-review

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.28.0
Hosts
1 documented
License
MIT
Stars
2,823
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Bundled resources for security-agent skill

  • [ ] report_template.md: A Markdown template for generating security review reports with placeholders for findings, severity ratings, and remediation advice.
  • [ ] examplecodevulnerable.py: Example code snippets demonstrating common vulnerabilities.
  • [ ] examplecodesecure.py: Corresponding secure code snippets demonstrating how to remediate the vulnerabilities.
Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: performing-security-code-review
description: 'Execute this skill enables AI assistant to conduct a security-focused
  code review using the security-agent plugin. it analyzes code for potential vulnerabilities
  like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant
  uses this skill wh... Use when assessing security or running audits. Trigger with
  phrases like ''security scan'', ''audit'', or ''vulnerability''.

  '
allowed-tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*)
version: 1.28.0
author: Jeremy Longshore <[email protected]>
license: MIT
tags:
- example
- security
- authentication
- audit
compatibility: Designed for Claude Code
---
# Performing Security Code Review

## Overview

Conducts security-focused code reviews by scanning source files for common vulnerability patterns including SQL injection, XSS, authentication flaws, insecure dependencies, and secret exposure. Produces structured severity-rated reports with specific remediation guidance.

## Prerequisites

- Read access to all source files in the target project
- `grep` available on PATH for pattern matching
- Access to `package.json` or equivalent dependency manifest for dependency auditing
- Familiarity with OWASP Top 10 vulnerability categories

## Instructions

1. Identify the scope of the review: specific files, directories, or the entire codebase. Confirm the primary language(s) and framework(s) in use.
2. Scan for hardcoded secrets and credentials:
   - Search for patterns matching API keys, tokens, passwords, AWS access keys (`AKIA...`), and private key headers (`BEGIN PRIVATE KEY`).
   - Flag any `.env` files or configuration files containing plaintext secrets.
3. Analyze code for injection vulnerabilities:
   - Identify raw SQL string concatenation (SQL injection risk).
   - Locate unsanitized user input rendered in HTML (XSS risk).
   - Check for `eval()`, `exec()`, or `Function()` calls with dynamic input (code injection risk).
4. Review authentication and authorization logic:
   - Verify password hashing uses strong algorithms (bcrypt, argon2) rather than MD5/SHA1.
   - Check for missing authentication on sensitive endpoints.
   - Identify overly permissive CORS configurations.
5. Audit dependencies for known vulnerabilities:
   - Run `npm audit` or equivalent package manager audit command.
   - Cross-reference dependency versions against known CVE databases.
6. Check for insecure communication patterns:
   - Flag HTTP URLs where HTTPS is expected.
   - Identify disabled TLS certificate verification.
7. Compile findings into a structured report sorted by severity (Critical, High, Medium, Low), including the vulnerable code location, explanation, and remediation steps.

## Output

A structured security review report containing:

- Summary with total findings count by severity level
- Per-finding entries with: file path, line number, vulnerability type, severity, code snippet, explanation, and recommended fix
- Dependency audit results with CVE identifiers where applicable
- Overall risk assessment (Critical / High / Medium / Low / Clean)

## Error Handling

| Error | Cause | Solution |
|---|---|---|
| No source files found | Incorrect scope path or empty directory | Verify the target directory path and confirm it contains source files |
| Binary files in scan | Non-text files matched by search patterns | Exclude binary extensions and `node_modules/` from scans |
| Dependency manifest missing | No `package.json`, `requirements.txt`, or equivalent | Skip dependency audit; note in report that dependency analysis was not possible |
| Permission denied on files | Restricted file access | Request read permissions or narrow the review scope to accessible files |
| False positive on secret pattern | Benign string matching secret regex | Verify context before reporting; mark as potential false positive if the match appears in test fixtures or documentation |

## Examples

**SQL injection review:**
Trigger: "Review this database query code for SQL injection vulnerabilities."
Process: Scan all files containing SQL query construction. Identify string concatenation with user input (`"SELECT * FROM users WHERE id = " + userId`). Report as High severity with remediation: use parameterized queries or prepared statements.

**Dependency vulnerability scan:**
Trigger: "Check this project's dependencies for known security vulnerabilities."
Process: Run `npm audit` on the project. Parse output for vulnerabilities. Report each finding with CVE identifier, affected package, installed version, and patched version. Recommend `npm audit fix` or manual version pinning.

**Full codebase security audit:**
Trigger: "Run a security scan on this codebase."
Process: Execute all seven scan categories (secrets, injection, auth, dependencies, communication, dangerous commands, obfuscation). Produce a comprehensive report with findings grouped by category and sorted by severity.

## Resources

- [OWASP Top 10](https://owasp.org/www-project-top-ten/) -- industry-standard vulnerability classification
- [Node.js Security Checklist](https://blog.risingstack.com/node-js-security-checklist/) -- Node-specific security guidance
- [CWE/SANS Top 25](https://cwe.mitre.org/top25/) -- most dangerous software weaknesses
- `${CLAUDE_SKILL_DIR}/references/README.md` -- bundled reference materials
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (5)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
assets/example_code_vulnerable.py:147
obj = pickle.loads(decoded_data)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
assets/example_code_secure.py:234
print(f"Secure random token: {token}")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
assets/example_code_secure.py:60
salt = bytes.fromhex(salt_hex)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
assets/example_code_secure.py:61
stored_hash = bytes.fromhex(hash_hex)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
assets/example_code_vulnerable.py:146
decoded_data = base64.b64decode(serialized_data)

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__performing-security-code-review.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aBLOCKD69first audit
06

Questions

What does the Performing Security Code Review skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Performing Security Code Review safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Performing Security Code Review access on my machine?

The audit observed that it runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Performing Security Code Review work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement