Secure Code Review

securityskills/skills/secure-code-review/secure-code-review

by securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450aNo licenseListed Oct 9, 2026Updated Oct 9, 2026

Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.

Instructions onlySecurity
AI-generated overview

Guides a security-focused code review that maps trust boundaries and audits input, auth, secrets, and race conditions.

What it does
This skill provides a structured procedure for reviewing code for vulnerabilities rather than skimming line by line. It walks through orienting on entry points and trust boundaries, tracing untrusted data to sinks such as SQL, command execution, rendering, file paths, deserialization, redirects, and dynamic code, and auditing authentication, access control, secrets, configuration, and race conditions. It also specifies how to report findings with severity, code path, exploit sketch, and suggested fix, separating must-fix items from later hardening.
When to use it
Use it on a pull request or codebase with security implications, especially when changes touch authentication, parsing, file handling, or cryptography. It fits reviewers who want a checklist-driven audit of input paths, authorization, secrets, and concurrency instead of an unstructured read-through.
Requirements
No scripts or special tooling are required; it is an instructions-only skill that needs access to the code under review.

Secure Code Review

Review code for vulnerabilities systematically, not line-by-line.

1. Orient

  • What does this code do? Identify: entry points, trust boundaries, data stores, privileged operations
  • Read the tests — what invariants do they reveal?
  • Check the diff's blast radius: auth logic? parsing? file handling? crypto?

2. Trace Untrusted Data

Follow each input from entry point to sink:

Sink ClassWhat to Verify
SQL/NoSQLParameterized; no string-built queries; identifiers whitelisted
Command execNo user data in shell strings; argv-array APIs; no shell=True
HTML/renderingContextual auto-escaping; raw/unsafe HTML flags justified
File pathsBasename/allowlist; canonicalize + prefix check; no user paths in includes
DeserializationTyped formats (JSON) over object serializers; validation post-parse
RedirectsRelative-only or allowlisted targets
Eval/dynamic codeJustified and input-free, or rejected

3. Audit Auth and Access Control

  • Every endpoint enforces authz server-side; role checks at the resource, not the controller only
  • Object-level checks (IDOR): does the query filter by the caller's tenant/user ID?
  • Session management: rotation, invalidation, secure cookie flags
  • Password reset flows: token entropy, expiry, single-use, no account enumeration

4. Audit Secrets and Config

  • No hardcoded credentials/keys/API tokens; no secrets in logs or error messages
  • Crypto: approved algorithms, library primitives (not hand-rolled), correct modes, random from CSPRNG

5. Race and State

  • TOCTOU on file checks, check-then-use on quotas/credits
  • Concurrency on mutable shared state; missing transactions on multi-step writes

Communication

Report findings with severity, the specific code path, an exploit sketch, and a suggested fix. Distinguish "must fix" from "harden later."

Source and attribution

Source:securityskills/skillsinsecure-code-review/secure-code-reviewat commitb2b6b52

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal