Developer Security Pack
A focused developer security pack for finding code-level risks before they become production problems. Includes structured security auditing, pull request quality checks, and code review for bugs, vulnerabilities, edge cases, and maintainability issues. Built for evidence-based findings with clear severity, impact, and practical remediation steps — without inventing vulnerabilities, repository facts, or test results
Works with every agent that reads SKILL.md — Claude Code, Cursor, Codex CLI, Gemini CLI, GitHub Copilot, Windsurf, OpenClaw, and more.
One payment, lifetime access. 3 skills unlock instantly in your library.
30-day refund guarantee
Instant unlock in your library
Free updates from the creator
What's included
3 skillsDisciplined code auditing for bugs, security risks, and performance issues with severity-ranked fixes.
A systematic pre-merge audit gate for Git diffs that flags security risks, migration locks, and test gaps.
Perform evidence-based static security audits for application code, cloud configs, and infrastructure manifests.
See it in action
Code Sentinel
Example session with this skill installed
Review this Python snippet for a new API endpoint:
def get_user(request):
user_id = request.GET.get('id')
user = db.execute("SELECT * FROM users WHERE id = " + user_id)
return user
- Read your context and instructions
- Compiled the code sentinel
I have completed a static review of the provided Python snippet. The analysis identified a critical security vulnerability regarding SQL injection and a potential runtime crash.
Review Summary
The code lacks input validation and uses unsafe string concatenation for database queries. This exposes the application to unauthorized data access.
Findings
| ID | Severity | Confidence | Location | Finding |
|---|---|---|---|---|
| CR-01 | Critical | High | db.execute(...) | SQL Injection vulnerability via unsanitized input. |
| CR-02 | High | High | request.GET.get('id') | Potential NoneType error if 'id' parameter is missing. |
| CR-03 | Low | Medium | SELECT * | Inefficient data retrieval; fetches unnecessary columns. |
CR-01: SQL Injection
- Evidence: The code directly concatenates
user_idfrom the request into the SQL string. - Impact: An attacker can pass
1 OR 1=1to dump the entire users table or1; DROP TABLE usersto delete data. - Fix: Use parameterized queries.
# Fix
user = db.execute("SELECT * FROM users WHERE id = %s", (user_id,))
CR-02: Missing Input Validation
- Evidence:
request.GET.get('id')returnsNoneif the key is missing. The subsequent concatenation will fail. - Impact: The application will throw a
TypeErrorand return a 500 status code to the user. - Fix: Add a check for the existence of
user_id.
# Fix
user_id = request.GET.get('id')
if not user_id:
return "Missing ID", 400
Recommended Verification
- Attempt to access the endpoint without an
idparameter to confirm 400 error handling. - Test the endpoint with a non-numeric string to ensure the database driver handles type mismatches in parameterized queries.
Next steps
- Replace all string-concatenated queries in the module with the parameterized pattern shown in CR-01.
- Implement a global middleware or utility function for standardizing API error responses.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every skill in this bundle passes our trust checks.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back