Self-review security discipline applied while writing — walk the threat model of the change (untrusted input, authz, secrets, crypto, dependencies) before handing it off. Invoke before declaring security-relevant code complete or committing it. The in-conversation companion to the security-reviewer agent; for a focused pass on a large diff in fresh context, delegate to that agent.
Run security scans with the ASH (Automated Security Helper) MCP server. Use this skill whenever the user asks to scan for vulnerabilities, run a security check, find CVEs, audit dependencies, check for secrets, run SAST or SCA, scan IaC (Terraform/CloudFormation/Kubernetes), check for hardcoded credentials, or mentions ASH, Bandit, Semgrep, Checkov, Grype, Syft, or detect-secrets. Also trigger when the user wants to find security issues, harden a codebase, or asks "is my code secure". Do NOT trigger for code review without security context, performance audits, or test writing.
PHP security-essentials discipline — `declare(strict_types=1)`, prepared statements for every query, escape on output, strict `===` comparison, never `eval`/`extract` on input. Apply when working in any PHP file. Skip for a throwaway CLI spike with no untrusted input.
Dependency and supply-chain threat discipline — pin and lock, audit for advisories, vet a new dependency before adding it, and treat install scripts and typosquats as attack surface. Invoke before adding or upgrading a dependency, or when hardening a project's build against a compromised package. Complements the security-review skill, which covers your own code's threat model.
Senior-engineer code review across five domains — Code Quality, Security, Performance, Blueprint/Spec Consistency, and Test Quality — plus conditional lenses auto-detected from scope (database, accessibility, RAG, ML, healthcare, agent/LLM — see Phase 0 below for the full list). Produces an evidence-backed findings report with confidence-labeled severities and an adaptive fix. Use whenever the user wants code reviewed, audited, or checked before merge/deploy: \"review this\", \"audit\", \"cek kode\", \"review PR\", \"is this production-ready\", \"find bugs/security issues\" — even without the word \"review\". Includes Reflection and a Critique-Correction Loop to suppress false positives. If the request is entirely about security (\"security audit\", \"cek keamanan kode ini\"), route to `security-review-edho-ferdian` instead — that skill is the single source of truth for security review criteria.
Advanced Offensive Security & Pentesting Specialist. Use this agent for red teaming, penetration testing, and identifying complex security flaws. It leverages specialized security tools for XSS, SQLi, JWT, OAuth2, and network-level vulnerability testing.
Use when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps. Covers AWS, Azure, and GCP posture assessment with MITRE ATT&CK mapping.
Security review requiring judgment about exploitability: injection and input handling, authentication and session management, authorization, secret storage and cryptography, and Agentic AI risks, against OWASP Top 10:2025 and ASVS 5.0. Use when user says 'review for security', 'is this secure', 'review this endpoint for injection', 'check for SQL injection or XSS', 'review auth/authorization', 'how are we storing secrets', 'check how we store secrets in this service', 'is this crypto correct', or when writing cryptography, session management, or AI agent code. Judges reachability and impact in this codebase; /clouddrove:appsec owns the deterministic checks a tool can answer (lockfile CVEs, missing headers, wildcard CORS).
This rule enforces best practices and coding standards for Bash scripting to improve code quality, maintainability, and security. It covers naming conventions, formatting, error handling, security, and performance considerations.
This rule file provides comprehensive guidance on Docker best practices, covering Dockerfile construction, image optimization, and security considerations. It aims to improve the efficiency, maintainability, and security of Docker-based projects.
This rule provides comprehensive best practices for Rust development, covering code organization, common patterns, performance, security, testing, pitfalls, and tooling. It aims to guide developers in writing idiomatic, efficient, secure, and maintainable Rust code.