Commit Security Scan

codexstar69/bug-hunter/skills/commit-security-scan

by codexstar693be69733a27aa04d4f5620df203c05350d162067No license519 starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 7 weeks ago

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Use whenever the user asks for PR security review, commit-diff scanning, staged-change security checks, branch-comparison security review, or pre-merge security analysis of changed code.

Instructions onlySecurity
AI-generated overview

Reviews changed code for security vulnerabilities using STRIDE analysis and Bug Hunter artifacts.

What it does
Scans changed code only — pull requests, staged diffs, branch diffs, or commit ranges — for security issues. It resolves the changed-file scope, reads the full contents of those files, and analyzes them against STRIDE categories such as spoofing, tampering, information disclosure, and elevation of privilege. Findings are produced with STRIDE and CWE labels and confidence scores, written to Bug Hunter-native artifacts such as a findings JSON file or a rendered report.
When to use it
Use it when the user asks for a security review of a pull request, staged changes, a branch comparison, or a commit range before merging. It is intended as a lightweight, diff-scoped fast path rather than a full-repository audit.
Requirements
Instructions only; no scripts ship with the skill. It expects threat-model context in Bug Hunter artifact paths and relies on git diff commands to resolve scope. It references bundled companion skills for threat-model generation and vulnerability validation, and writes findings into Bug Hunter artifact files.

Commit Security Scan

This is a bundled local Bug Hunter companion skill. It is portable and self-contained: use .bug-hunter/* artifacts, never .factory/* paths.

Purpose

Review changed code for security issues only. This skill is optimized for:

  • PR review
  • staged diff review
  • branch diff review
  • commit / commit-range security scanning

Inputs

Resolve the scan scope from the user request:

  • PR review → use scripts/pr-scope.cjs
  • staged review → use git diff --cached --name-only
  • branch diff → use git diff --name-only <base>...<head>
  • commit range → use git diff --name-only <base>..<head>

Workflow

  1. Ensure threat-model context exists.

    • Preferred artifacts:
      • .bug-hunter/threat-model.md
      • .bug-hunter/security-config.json
    • If missing, run the bundled threat-model-generation skill first.
  2. Resolve the changed-file scope.

  3. Read the full contents of the changed source files, not just the patch.

  4. Focus on STRIDE-oriented issues in changed code:

    • Spoofing: auth/session/token mistakes
    • Tampering: SQLi, XSS, path traversal, command injection, mass assignment
    • Repudiation: security-sensitive actions with no auditability
    • Information Disclosure: IDOR, secret exposure, verbose errors
    • DoS: unbounded input, missing limits, expensive regex/queries
    • Elevation of Privilege: missing authorization, role bypass, privilege escalation
  5. Reuse Bug Hunter-native security conventions:

    • findings should be compatible with .bug-hunter/hunter-findings.json
    • use STRIDE + CWE labels
    • include confidence scores
  6. If the user wants only a focused security diff review, stop after the findings report. If the user wants deeper validation, hand off to the bundled vulnerability-validation skill.

Output

Preferred outputs:

  • .bug-hunter/hunter-findings.json when integrating with the main Bug Hunter pipeline
  • .bug-hunter/report.md as a rendered companion if needed

Notes

  • This skill is intentionally diff-scoped; it does not replace full-repository audits.
  • Use it as the lightweight security fast-path before invoking the broader security-review flow.

Source and attribution

Source:codexstar69/bug-hunterinskills/commit-security-scanat commit3be6973

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal