security-pass
bt2go/claude-skills/skills/security-pass/SKILL.md
Use when the user wants a security check of a diff, an endpoint, or code handling input, auth or secrets.
Skill0 starsChanged 2 months ago
--- name: security-pass description: Use when the user wants a security check of a diff, an endpoint, or code handling input, auth or secrets. --- # Security pass Look for exploitable defects, not a compliance checklist. ## Procedure 1. Map the untrusted input: request bodies, query strings, headers, file uploads, webhooks, third party responses. 2. Follow each input to where it reaches a sink: a database driver, a shell, a file path, a template, a redirect, a deserialiser. 3. Check injection at every sink: string built SQL, `exec` with interpolation, path traversal via `..`, unescaped HTML. 4. Check authorisation on every handler, not just authentication. Ask whether user A can pass user B's object id. 5. Check secrets: hardcoded keys, secrets in logs, secrets in error messages returned to the client. 6. Check the crypto: weak hashes for passwords, hand rolled token comparison, predictable random for tokens. 7. Check dependencies added in the diff for known advisories. 8. For each finding, write the attacker's exact steps. If you cannot, downgrade it to a note. ## Rules - No generic advice like "validate all input". - No findings without a reachable path from untrusted input. - Report severity as critical, high, medium or low with a one line justification. ## Output format ``` [severity] path/to/file:line - <title> Attack: <numbered steps an attacker takes> Impact: <what they get> Fix: <specific change> ```
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

