diff --git a/skills/security-review/SKILL.md b/skills/security-review/SKILL.md index c1195b6..f4bb671 100644 --- a/skills/security-review/SKILL.md +++ b/skills/security-review/SKILL.md @@ -1,6 +1,6 @@ --- name: security-review -description: Perform a security-focused code review of smart contracts, frontends, backends, and mobile apps. Use this skill for a security review, audit, vulnerability scan, or check of code for security issues, including reviewing a pull request, diff, or changed files, or asking "is this safe to merge or ship." Covers Solidity and ErgoScript smart contracts (reentrancy, access control, oracle manipulation, box and register validation); Next.js, Tailwind, and Svelte frontends (XSS, SSRF, exposed secrets, CSRF, insecure API routes); Python and Go backends (injection, unsafe deserialization, unsafe concurrency, weak randomness); and Flutter mobile apps (insecure storage, hardcoded secrets, missing certificate pinning, insecure WebViews). Also covers general classes: injection, auth flaws, cryptography issues, unsafe deserialization, data exposure. Use whenever code touches funds, user data, or authentication, even without the word "security." +description: Perform a security-focused code review of smart contracts, frontends, backends, and mobile apps. Use this skill for a security review, audit, vulnerability scan, or check of code for security issues, including reviewing a pull request, diff, or changed files, or asking "is this safe to merge or ship." Covers Solidity and ErgoScript smart contracts (reentrancy, access control, oracle manipulation, box and register validation); Next.js, Tailwind, and Svelte frontends (XSS, SSRF, exposed secrets, CSRF, insecure API routes); Python and Go backends (injection, unsafe deserialization, unsafe concurrency, weak randomness); and Flutter mobile apps (insecure storage, hardcoded secrets, missing certificate pinning, insecure WebViews). Also covers general classes such as injection, auth flaws, cryptography issues, unsafe deserialization, and data exposure. Use whenever code touches funds, user data, or authentication, even without the word "security." compatibility: Works in any coding agent with file read/write and search access. Git commands are used to scope diffs/PRs and to stamp the report with a commit hash. Saves its report to unremediated-security-reviews/ in the project. metadata: version: "1.0"