secure-code-review
Security review for code changes or a whole repository — finds hard-coded secrets, OWASP Top 10 / CWE-mapped vulnerabilities (SQL injection, XSS, command injection, weak crypto, TLS bypass, permissive CORS), and supply-chain risks, then proposes minimal fixes. Use when the user asks for a security review, vulnerability scan, "is this safe to ship?", secure coding guidance, or before merging/releasing.
- Version
- 1.0.0
- License
- MIT
Pinned to revision 2700fd98b60f, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/secure-code-review/SKILL.md
- skills/secure-code-review/references/owasp-checklist.md
- skills/secure-code-review/references/report-template.md
- skills/secure-code-review/scripts/scan.mjs
Every link opens the file at its source, pinned to the revision this page describes.