More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    ai security review agent

    2

    Perform evidence-based security reviews of code, infrastructure, and AI tool-calling workflows to identify attack paths.

    Free

    1 installSecurity scanned
    ai security review agent

    ai security review agent

    Example session with this skill installed

    Review this Node.js API handler for security risks:

    app.get('/api/user/data', async (req, res) => {
      const user = await db.users.findOne({ id: req.query.userId });
      res.json(user);
    });
    
    • Read your context and instructions
    • Compiled the ai security review

    Security Review Summary

    Scope: Node.js API handler (/api/user/data)
    Review status: Completed
    Release decision: BLOCK

    1. Executive Findings

    HIGH: Broken Object Level Authorization (BOLA) - Confirmed. The handler fetches user data based on a client-supplied ID without verifying ownership.

    2. Attack Surface and Trust Boundaries

    • Input: req.query.userId (Untrusted)
    • Trust Boundary: API Endpoint -> Database Query
    • Privileged Operation: Reading sensitive user records from db.users.

    3. Findings

    [SEC-001] Missing Authorization Check on User Data Access
    Severity: HIGH
    Confidence: Confirmed
    Location: app.get('/api/user/data', ...)
    Evidence: The code uses req.query.userId directly in a database lookup and returns the result without checking if the authenticated requester has permission to view that specific ID.
    Attack Path: Authenticated Attacker -> Provide victim's userId in query string -> Server fetches victim's data -> Data returned to attacker.
    Impact: Unauthorized disclosure of sensitive user information across the entire user base.
    Remediation: Validate that the userId in the query matches the id of the currently authenticated session user.
    Verification:

    1. Attempt to access /api/user/data?userId=[VICTIM_ID] using an attacker's session; confirm 403 Forbidden.
    2. Access /api/user/data?userId=[MY_ID] using own session; confirm 200 OK.

    4. Security Gaps / UNKNOWNs

    Authentication Middleware: The provided snippet does not show how req.user is populated or if an auth middleware is present.

    5. Verification Plan

    • Test Case 1: IDOR/BOLA attempt using mismatched session and query IDs.
    • Test Case 2: Success path for legitimate owner access.

    6. Release Gate

    BLOCK
    The BOLA vulnerability is confirmed and allows unauthorized data access. The code must not be deployed until ownership verification is implemented.

    Next steps

    • Implement ownership validation using the authenticated session context.
    • Provide the authentication middleware code for a follow-up review.
    • Run the suggested verification tests in the staging environment.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The problem

    Code reviews often miss subtle authorization gaps, injection vectors, or insecure AI tool-calling logic. Developers frequently rely on generic linters that lack the context to trace untrusted data across trust boundaries.

    What it does

    • Analyzes pull requests, infrastructure diffs, and dependency manifests for evidence-based security weaknesses.
    • Traces controllable inputs from entry points like API handlers to privileged operations or database queries.
    • Audits AI-specific risks including prompt injection, instruction confusion, and excessive tool permissions.
    • Classifies findings by severity (Critical to Info) and confidence level, distinguishing confirmed bugs from hypotheses.
    • Generates targeted remediation advice and specific verification tests to block abuse paths.

    Why this beats prompting it yourself

    Generic prompts often hallucinate vulnerabilities or miss complex attack paths like SSRF and insecure deserialization. This skill enforces a strict evidence-based review procedure that separates confirmed facts from assumptions, ensuring you don't waste time on false positives.

    Use cases

    • Reviewing PRs for Broken Object Level Authorization (BOLA) and injection risks.
    • Auditing LLM-integrated applications for prompt injection and unsafe tool execution.
    • Checking infrastructure-as-code and dependency changes for misconfigurations or leaked secrets.
    • Providing a formal security release gate for compliance or internal audit trails.

    Known limitations

    Read-only analysis based strictly on provided material. It cannot verify runtime behavior, external services, or infrastructure not explicitly defined in the input files.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    1 install

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 11 days ago

    • Free to download with an account

    Listed11 days ago
    Updated4 days ago

    What's inside

    Frequently Asked Questions