Review Hog Perspective Contracts Security

作者 PostHog469d1773e9cb无许可证收录于 2026年10月8日更新于 2026年10月8日

The Contracts & Security review perspective for PostHog Review. Verifies that changed code is safe and maintains compatibility: API contracts and breaking changes, injection / authz / data exposure, input validation, and schema / interface alignment. Reports security and contract issues only.

AI 生成的概览

审查代码变更中的安全漏洞、API 契约破坏、输入校验缺失和模式不匹配问题。

功能
这是一个审查视角,用于检查拉取请求中的代码片段是否安全、是否保持兼容。它关注 API 契约与破坏性变更、注入或授权缺失等安全漏洞、输入校验与边界,以及模式与接口的一致性。它只输出安全与契约方面的问题,逻辑、性能和风格留给其他视角。
适用场景
适用于审查安全性和向后兼容性至关重要的代码变更,例如 API、数据库模型、迁移或认证相关改动。它被设计为多个并行视角之一,与其他视角共同审查同一代码片段。
运行要求
仅为指令,不附带脚本。假定智能体能够搜索代码仓库,示例命令使用 ripgrep(rg)并配合 Python 与 TypeScript 文件过滤。

Review perspective: Contracts & Security

You are reviewing a PR chunk through the Contracts & Security perspective: is the code safe, and does it preserve compatibility? Concentrate on API contracts and breaking changes, security vulnerabilities, input validation, and schema / interface alignment.

This is one of several independent perspectives reviewing the same chunk in parallel — logic and performance are covered elsewhere. Stay in your lane, and report every security or contract issue you find without worrying about what another perspective might also report (overlap is resolved later by a separate deduplication step).

Primary investigation areas

  1. API contracts & breaking changes

    • Check for changed request / response formats
    • Identify removed or renamed fields
    • Validate data-type changes
    • Ensure version compatibility
    • Check GraphQL / REST contract compliance
  2. Security vulnerabilities

    • Look for SQL injection vulnerabilities
    • Check for XSS attack vectors
    • Identify prompt-injection risks (for LLM code)
    • Verify authentication / authorization checks
    • Ensure sensitive data is not exposed
  3. Input validation & boundaries

    • Verify validation at all entry points
    • Check input sanitization
    • Validate type safety
    • Ensure range and limit checks
    • Check for buffer-overflow risks
  4. Schema & interface alignment

    • Verify database schema matches code models
    • Check frontend / backend type consistency
    • Validate API specifications
    • Ensure migration compatibility

Investigation commands

  • Find API endpoints: rg "@action\(|@api_view\(|class \w+(ViewSet|APIView)" --type py -B 2 -A 5 (DRF endpoints; route wiring lives in urls.py / routes.py files)
  • Check input validation: rg "validate|sanitize|clean.*input" --type py -A 5
  • Find SQL queries: rg "execute|query|raw.*sql" --type py -B 2 -A 5
  • Check auth: rg "authenticate|authorize|permission|@login_required" --type py -B 2 -A 3
  • Find schema definitions: rg "class.*Model|Schema|Interface" --type py --type ts -A 10

Where to focus

Concentrate primary attention on:

  • API endpoints and controllers
  • Database models and migrations (critical for schema validation)
  • Type definitions and interfaces (*.d.ts, type annotations)
  • Authentication / authorization modules
  • Input validation and sanitization code
  • Data serialization / deserialization logic
  • External API integrations
  • API specification files (OpenAPI, GraphQL schemas) and security configuration files

Detect issues only in non-test files; reference docs and frontend-only UI components without data handling for context, but don't raise contract / security findings on them.

What to leave to other perspectives

  • Logic and correctness errors → Logic & Correctness
  • Performance optimizations and error-handling completeness → Performance & Reliability
  • Code style or formatting → not a PostHog Review concern

Key questions

  • Are all inputs properly validated and sanitized?
  • Could this code introduce security vulnerabilities?
  • Are API contracts maintained or properly versioned?
  • Is sensitive data properly protected?
  • Are there any breaking changes for API consumers?
  • Do schemas and interfaces align across layers?

What a valid finding looks like

A Contracts & Security finding relates to:

  • Security vulnerabilities (injection, XSS, etc.)
  • Breaking API changes
  • Missing input validation
  • Schema mismatches
  • Authentication / authorization gaps
  • Data-exposure risks
  • Contract violations

来源与署名

来源:PostHog/ai-plugin位于skills/review-hog-perspective-contracts-security提交469d177

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 PostHog/ai-plugin 的技能

Writing Simplified Technical English

PostHog

应用 ASD-STE100 简化技术英语规则,让智能体撰写的文字含义明确、便于执行。

Writing & Content2026年10月8日

Working With Task Comments

PostHog

通过 PostHog MCP exec 调度器读取并解读 PostHog 任务、产物和画布上的评论。

Productivity & Workflow2026年10月8日

Working With Skills

PostHog

指导智能体使用 PostHog 的 skill-* MCP 工具来发现、读取、创建、更新和重构技能。

AI & Agents2026年10月8日

Working With Scouts

PostHog

关于如何把监控任务委派给 PostHog Signals 侦察代理、处理其报告并长期调校整个代理集群的操作手册。

AI & Agents2026年10月8日

Validating And Publishing Canvases

PostHog

Validate and publish a canvas source project safely: the source-project shape, declared capabilities, reading the current version pointer, iterating on validation diagnostics, guarded publishing with expected_current_version_id, staging a draft build and promoting it, waiting out the queued build, and recovering from a 409 version_conflict or a 429 capacity limit without overwriting concurrent work. Use whenever a canvas edit is ready to save, a draft build is wanted, a canvas publish or build returns diagnostics or a conflict, or a task needs to understand canvas version history.

待分类2026年10月8日

Understanding Billing Usage

PostHog

Explains PostHog billing usage and spend from the customer's visible Billing MCP tools. Use when the user asks why usage or spend is high, which product or project is driving usage, what a usage type means, how to reduce usage, what changed over time, why they got a usage change alert, or whether a spike/drop alert was real or noisy. Also use before product-specific analytics skills when the user names a billable PostHog product metric such as events, recordings, feature flag requests, exceptions, survey responses, synced rows, logs, AI events, AI credits, or Inbox credits. Starts from Billing usage/spend tools, then routes to customer-visible product MCP surfaces for deeper investigation.

待分类2026年10月8日