Secure Code Review

securityskills/skills/secure-code-review/secure-code-review

作者 securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450a无许可证收录于 2026年10月9日更新于 2026年10月9日

Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.

仅含说明Security
AI 生成的概览

指导以安全为核心的代码审查,梳理信任边界并审计输入、认证、密钥与竞态问题。

功能
该技能提供一套结构化流程,用于系统性地审查代码漏洞,而不是逐行浏览。它涵盖:识别入口点与信任边界;将不可信数据追踪到 SQL、命令执行、渲染、文件路径、反序列化、重定向和动态代码等汇聚点;审计认证、访问控制、密钥、配置以及竞态条件。它还规定了如何报告发现的问题,包括严重程度、具体代码路径、利用思路和建议修复方案,并区分必须修复与后续加固。
适用场景
适用于具有安全影响的拉取请求或代码库,尤其是改动涉及认证、解析、文件处理或加密时。适合希望按清单审计输入路径、授权、密钥和并发问题,而非无结构通读的审查者。
运行要求
无需脚本或特殊工具;这是仅含说明的技能,需要能够访问待审查的代码。

Secure Code Review

Review code for vulnerabilities systematically, not line-by-line.

1. Orient

  • What does this code do? Identify: entry points, trust boundaries, data stores, privileged operations
  • Read the tests — what invariants do they reveal?
  • Check the diff's blast radius: auth logic? parsing? file handling? crypto?

2. Trace Untrusted Data

Follow each input from entry point to sink:

Sink ClassWhat to Verify
SQL/NoSQLParameterized; no string-built queries; identifiers whitelisted
Command execNo user data in shell strings; argv-array APIs; no shell=True
HTML/renderingContextual auto-escaping; raw/unsafe HTML flags justified
File pathsBasename/allowlist; canonicalize + prefix check; no user paths in includes
DeserializationTyped formats (JSON) over object serializers; validation post-parse
RedirectsRelative-only or allowlisted targets
Eval/dynamic codeJustified and input-free, or rejected

3. Audit Auth and Access Control

  • Every endpoint enforces authz server-side; role checks at the resource, not the controller only
  • Object-level checks (IDOR): does the query filter by the caller's tenant/user ID?
  • Session management: rotation, invalidation, secure cookie flags
  • Password reset flows: token entropy, expiry, single-use, no account enumeration

4. Audit Secrets and Config

  • No hardcoded credentials/keys/API tokens; no secrets in logs or error messages
  • Crypto: approved algorithms, library primitives (not hand-rolled), correct modes, random from CSPRNG

5. Race and State

  • TOCTOU on file checks, check-then-use on quotas/credits
  • Concurrency on mutable shared state; missing transactions on multi-step writes

Communication

Report findings with severity, the specific code path, an exploit sketch, and a suggested fix. Distinguish "must fix" from "harden later."

来源与署名

来源:securityskills/skills位于secure-code-review/secure-code-review提交b2b6b52

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架