- Home
- Skills
- Code Quality & Review
- Code Sentinel
Code Sentinel
Disciplined code auditing for bugs, security risks, and performance issues with severity-ranked fixes.
$6.99
Works with the AI tools you already use
Code Sentinel
Example session with this skill installed
Review this Python snippet for a new API endpoint:
def get_user(request):
user_id = request.GET.get('id')
user = db.execute("SELECT * FROM users WHERE id = " + user_id)
return user
- Read your context and instructions
- Compiled the code sentinel
I have completed a static review of the provided Python snippet. The analysis identified a critical security vulnerability regarding SQL injection and a potential runtime crash.
Review Summary
The code lacks input validation and uses unsafe string concatenation for database queries. This exposes the application to unauthorized data access.
Findings
| ID | Severity | Confidence | Location | Finding |
|---|---|---|---|---|
| CR-01 | Critical | High | db.execute(...) | SQL Injection vulnerability via unsanitized input. |
| CR-02 | High | High | request.GET.get('id') | Potential NoneType error if 'id' parameter is missing. |
| CR-03 | Low | Medium | SELECT * | Inefficient data retrieval; fetches unnecessary columns. |
CR-01: SQL Injection
- Evidence: The code directly concatenates
user_idfrom the request into the SQL string. - Impact: An attacker can pass
1 OR 1=1to dump the entire users table or1; DROP TABLE usersto delete data. - Fix: Use parameterized queries.
# Fix
user = db.execute("SELECT * FROM users WHERE id = %s", (user_id,))
CR-02: Missing Input Validation
- Evidence:
request.GET.get('id')returnsNoneif the key is missing. The subsequent concatenation will fail. - Impact: The application will throw a
TypeErrorand return a 500 status code to the user. - Fix: Add a check for the existence of
user_id.
# Fix
user_id = request.GET.get('id')
if not user_id:
return "Missing ID", 400
Recommended Verification
- Attempt to access the endpoint without an
idparameter to confirm 400 error handling. - Test the endpoint with a non-numeric string to ensure the database driver handles type mismatches in parameterized queries.
Next steps
- Replace all string-concatenated queries in the module with the parameterized pattern shown in CR-01.
- Implement a global middleware or utility function for standardizing API error responses.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Manual code reviews are slow and often miss edge cases under pressure. This skill provides a disciplined, first-pass static analysis to identify correctness bugs, security risks, and performance bottlenecks before they hit production.
What it does
- Severity-ranked auditing classifies issues from Critical to Suggestion so you know what to fix first.
- Evidence-based findings link every reported issue to specific code locations with concrete impact analysis.
- Logic and security vetting checks for race conditions, data integrity, and common vulnerabilities without inventing false positives.
- Actionable remediation provides specific code fixes for every identified problem.
How it works
- Analyze scope by ingesting your provided source code, diffs, or pull request content.
- Scan categories including correctness, security, error handling, performance, and maintainability.
- Generate findings structured in a standardized table with confidence ratings.
- Detail fixes for each issue, providing the "why" behind the recommendation.
Frameworks & tools
This skill works with any programming language or framework including JavaScript, Python, Go, Rust, and Java. It integrates with existing shell or git tools if available to verify file paths and diff context.
Why this beats prompting it yourself
Generic prompts often result in vague "make it cleaner" advice or hallucinated line numbers. This skill enforces a structured severity-based framework that prevents the agent from inventing files or vulnerabilities while ensuring high-impact bugs are never buried in style suggestions.
Use cases
- Pull request audits to catch logic flaws before merging into the main branch.
- Security pre-screening to find hardcoded secrets or unsafe data handling.
- Performance tuning to identify O(n^2) operations or memory leaks in new features.
- Legacy refactoring to assess technical debt in inherited codebases.
Known limitations
Does not perform runtime execution or dynamic analysis unless external test tools are explicitly provided. Requires provided code context to be accurate.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 8 days ago
- Passed all security checks, Safe to install