agentleFS
Sign inSign up

security-audit

sergeeey/Claude-cod-top-2026/skills/extensions/security-audit/SKILL.md

Skill9 starsChanged 5 months ago
  • Reads credentials
<!-- BSV — Brief Skill View | поиск: BSV
Скил   : security-audit
TL;DR  : Аудит безопасности: PII, SQL injection, секреты
Вызов  : 'аудит', 'проверь безопасность', `security:`
НЕ для : Code review без security-фокуса
-->

---
name: security-audit
description: >
  [STATUS: review] [CONFIDENCE: high] [REVIEWED: 2026-03-13]
  MUST CHECK before any commit touching auth, payments, PII, user data, SQL, .env.
  USE for financial applications, compliance, fraud detection.
  Triggers: security, audit, fraud, injection,
  XSS, PII, compliance, auth, payment, vulnerability, PCI.
  ESPECIALLY when tempted to skip security review for "internal" code.
  Do NOT use for general security questions or code review without auth/PII/payments
  context — use the reviewer agent instead.
paths: "**/*auth*,**/*payment*,**/*crypto*,**/*.env*,**/*secret*"
effort: max
---

# Security Audit Skill

## Domain
Financial organizations, regulatory compliance, fraud detection.
Adapt the checklists below to your region's regulations and PII formats.

## Security Checklist (before production deploy)

### 1. PII Protection
- [ ] National ID — NEVER in logs as plain text (logs are often stored unencrypted, indexed by ELK, accessible to support staff — exposure violates GDPR/local PII law)
- [ ] Legal entity ID — mask in output
- [ ] Bank account details — only last 4 digits in UI
- [ ] Email/phone — mask in logs (ivan@*****.com, +X XXX *** **12)

### 2. Authentication & Authorization
- [ ] JWT tokens: refresh rotation, short-lived access (15 min)
- [ ] Rate limiting on auth endpoints (5 attempts / 15 min)
- [ ] IP whitelisting for admin endpoints
- [ ] 2FA for operations above threshold (configurable)

### 3. Data Layer
- [ ] SQL: ONLY parameterized queries (SQLAlchemy ORM or text() with bindparams)
- [ ] NoSQL: input data — Pydantic validation BEFORE writing
- [ ] Encryption at rest for PII fields (AES-256)
- [ ] Audit log for all CRUD operations involving PII

### 4. Regulatory Compliance (adapt to your jurisdiction)
- [ ] Data storage — comply with data residency requirements
- [ ] PII retention period — per local personal data law
- [ ] Processing consent — tracked in DB with timestamp
- [ ] Right to erasure — data erasure endpoint implemented

### 5. Fraud Detection Patterns
- **Velocity check:** > 3 applications from one IP per hour → flag
- **ID deduplication:** one national ID = one client, cross-check across all products
- **Device fingerprint:** fingerprint collision + different IDs → high risk
- **Geo-anomaly:** application from unexpected region → medium risk

### 6. Secrets & credentials
- [ ] No hardcoded passwords, API keys, access tokens, private keys, or credentials.
- [ ] Environment/config lookups must not contain real-secret fallback defaults.
- [ ] Check test fixtures, examples, logs and committed config files for leaked credentials.

### 7. Transaction integrity
- [ ] Monetary amounts must be validated server-side for sign, allowed range,
      currency precision and numeric validity before any balance mutation.
- [ ] Reject zero/negative amounts where the operation semantics require a positive transfer.
- [ ] Guard against NaN/Infinity, overflow and precision/rounding abuse where applicable.

## Tools
- `reviewer` agent — code review before commit
- `redact.py` hook — auto-cleanup of PII before external MCP
- `ruff` — static analysis of Python code

## Gotchas
- Run BEFORE commit, not after — post-commit security is post-mortem security
- IIN/BIN patterns are KZ-specific — adapt regex for other jurisdictions

Discussion

Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.

Posts are public.Sign in to post

No one has posted yet. Be the first.