Self-review security discipline applied while writing — walk the threat model of the change (untrusted input, authz, secrets, crypto, dependencies) before handing it off. Invoke before declaring security-relevant code complete or committing it. The in-conversation companion to the security-reviewer agent; for a focused pass on a large diff in fresh context, delegate to that agent.
Run security scans with the ASH (Automated Security Helper) MCP server. Use this skill whenever the user asks to scan for vulnerabilities, run a security check, find CVEs, audit dependencies, check for secrets, run SAST or SCA, scan IaC (Terraform/CloudFormation/Kubernetes), check for hardcoded credentials, or mentions ASH, Bandit, Semgrep, Checkov, Grype, Syft, or detect-secrets. Also trigger when the user wants to find security issues, harden a codebase, or asks "is my code secure". Do NOT trigger for code review without security context, performance audits, or test writing.
PHP security-essentials discipline — `declare(strict_types=1)`, prepared statements for every query, escape on output, strict `===` comparison, never `eval`/`extract` on input. Apply when working in any PHP file. Skip for a throwaway CLI spike with no untrusted input.
Dependency and supply-chain threat discipline — pin and lock, audit for advisories, vet a new dependency before adding it, and treat install scripts and typosquats as attack surface. Invoke before adding or upgrading a dependency, or when hardening a project's build against a compromised package. Complements the security-review skill, which covers your own code's threat model.
Single source of truth for security review criteria across the Edho Ferdian ecosystem — general OWASP-style checklist (SEC-01..19), plus stack-specific and domain-specific security items (see the reference list at the bottom of this file for the full stack/domain coverage). Runs STANDALONE for a security-only pass (\"cek keamanan kode ini\", \"security audit\", \"find vulnerabilities\") OR as the delegated depth layer for Domain 2 (SEC) of code-review-edho-ferdian's full review. Every other skill in this ecosystem that touches security cross-references this skill instead of holding its own copy — this is the only place security criteria are defined, to remove drift risk from duplication.
Senior-engineer code review across five domains — Code Quality, Security, Performance, Blueprint/Spec Consistency, and Test Quality — plus conditional lenses auto-detected from scope (database, accessibility, RAG, ML, healthcare, agent/LLM — see Phase 0 below for the full list). Produces an evidence-backed findings report with confidence-labeled severities and an adaptive fix. Use whenever the user wants code reviewed, audited, or checked before merge/deploy: \"review this\", \"audit\", \"cek kode\", \"review PR\", \"is this production-ready\", \"find bugs/security issues\" — even without the word \"review\". Includes Reflection and a Critique-Correction Loop to suppress false positives. If the request is entirely about security (\"security audit\", \"cek keamanan kode ini\"), route to `security-review-edho-ferdian` instead — that skill is the single source of truth for security review criteria.
Backend security review and secure-by-default coding for Django and DRF, on an OWASP Top 10:2025, API Security Top 10:2023, and ASVS 5.0 foundation. Apply when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control, IDOR, SSRF, path traversal, open redirect, impersonation, SQL/command/template injection, LDAP, row-level security, encrypted columns, NoSQL, Redis, file uploads, S3, serializers, rate limiting, CSRF/CORS, OpenAPI schema, GraphQL, Django Ninja, gRPC, AI agents, MCP tools, secrets, payments, webhooks, Celery, Django tasks, race conditions, ReDoS, caching, deserialization, async/ASGI, WebSockets, audit logging, erasure, retention, personal data, migrations, JWKS, mutual TLS, SECRET_KEY, SBOM, X-Forwarded-For, SPF/DKIM/DMARC, or deployment config, even if "security" is never used. Canonical instructions live in SKILL.md and references/.
Advanced Offensive Security & Pentesting Specialist. Use this agent for red teaming, penetration testing, and identifying complex security flaws. It leverages specialized security tools for XSS, SQLi, JWT, OAuth2, and network-level vulnerability testing.
Security vulnerability detection and remediation specialist. Audits code for OWASP Top 10, IDOR, SSRF, and injection. Enforces zero trust and secure data handling for financial and AI platforms. Contains full knowledge of security reviewer and audit checklists.
Use when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps. Covers AWS, Azure, and GCP posture assessment with MITRE ATT&CK mapping.