Secure Code Review

securityskills/skills/secure-code-review/secure-code-review

作者 securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450a無授權條款收錄於 2026年10月9日更新於 2026年10月9日

Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.

僅含說明Security
AI 產生的概覽

指導以安全為核心的程式碼審查,梳理信任邊界並稽核輸入、驗證、密鑰與競態問題。

功能
此技能提供一套結構化流程,用於系統性地審查程式碼漏洞,而非逐行瀏覽。內容涵蓋:辨識進入點與信任邊界;將不受信任的資料追蹤至 SQL、命令執行、渲染、檔案路徑、反序列化、重新導向與動態程式碼等匯聚點;稽核驗證、存取控制、密鑰、設定以及競態條件。它也規定如何報告發現的問題,包括嚴重程度、具體程式碼路徑、利用思路與建議修正方式,並區分必須修正與後續強化。
適用情境
適用於具有安全影響的拉取請求或程式碼庫,尤其是變更涉及驗證、解析、檔案處理或加密時。適合希望依清單稽核輸入路徑、授權、密鑰與並行問題,而非無結構通讀的審查者。
執行需求
無需指令碼或特殊工具;這是僅含說明的技能,需要能夠存取待審查的程式碼。

Secure Code Review

Review code for vulnerabilities systematically, not line-by-line.

1. Orient

  • What does this code do? Identify: entry points, trust boundaries, data stores, privileged operations
  • Read the tests — what invariants do they reveal?
  • Check the diff's blast radius: auth logic? parsing? file handling? crypto?

2. Trace Untrusted Data

Follow each input from entry point to sink:

Sink ClassWhat to Verify
SQL/NoSQLParameterized; no string-built queries; identifiers whitelisted
Command execNo user data in shell strings; argv-array APIs; no shell=True
HTML/renderingContextual auto-escaping; raw/unsafe HTML flags justified
File pathsBasename/allowlist; canonicalize + prefix check; no user paths in includes
DeserializationTyped formats (JSON) over object serializers; validation post-parse
RedirectsRelative-only or allowlisted targets
Eval/dynamic codeJustified and input-free, or rejected

3. Audit Auth and Access Control

  • Every endpoint enforces authz server-side; role checks at the resource, not the controller only
  • Object-level checks (IDOR): does the query filter by the caller's tenant/user ID?
  • Session management: rotation, invalidation, secure cookie flags
  • Password reset flows: token entropy, expiry, single-use, no account enumeration

4. Audit Secrets and Config

  • No hardcoded credentials/keys/API tokens; no secrets in logs or error messages
  • Crypto: approved algorithms, library primitives (not hand-rolled), correct modes, random from CSPRNG

5. Race and State

  • TOCTOU on file checks, check-then-use on quotas/credits
  • Concurrency on mutable shared state; missing transactions on multi-step writes

Communication

Report findings with severity, the specific code path, an exploit sketch, and a suggested fix. Distinguish "must fix" from "harden later."

來源與署名

來源:securityskills/skills位於secure-code-review/secure-code-review提交b2b6b52

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架