Security Code Review
Automated security code reviewer that finds logic-level vulnerabilities and provides severity-rated fixes.
Free
Works with the AI tools you already use
Security Code Review
Example session with this skill installed
Review the security of this diff: app.get('/api/report/:id', (req, res) => { const query = "SELECT * FROM reports WHERE id = " + req.params.id; db.execute(query, (err, row) => { res.send(row); }); });
- Read your context and instructions
- Compiled the security code review
- Generated the document
The security review is complete. I found two high-severity issues in the provided diff.
Security Review Results
| Severity | Category | CWE | Location | Finding | Fix |
|---|---|---|---|---|---|
| Critical | Injection | CWE-89 | Line 2 | Direct string concatenation of req.params.id into a SQL query allows for SQL injection. | Use parameterized queries: db.execute("SELECT * FROM reports WHERE id = ?", [req.params.id], ...) |
| High | Broken Access Control | CWE-639 | Line 2 | IDOR: The endpoint fetches a report by ID without verifying if the authenticated user has permission to view that specific report. | Add an ownership check: WHERE id = ? AND owner_id = ? using the session user ID. |
Verified Categories
- SSRF: Checked; no external fetches performed in this hunk.
- Path Traversal: Checked; no file system operations identified.
- Insecure Deserialization: Checked; input is treated as a string/integer, not an object.
Verdict: Request Changes
The SQL injection vulnerability is directly exploitable. Please implement parameterization and add authorization checks before merging.
Next steps
- Refactor the database call to use the driver's parameterization syntax.
- Implement a middleware check to validate user ownership of the requested
:id. - Run a full-repo secret scan if these credentials were ever committed to a public branch.
security-code-review.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
The problem
Static analysis tools often miss logic-level vulnerabilities like broken authorization or business-logic bypasses. Developers often merge PRs with hidden security flaws because they lack the time for a deep, adversarial review of every change.
What it does
- Analyzes diffs and pull requests for OWASP Top 10 and CWE Top 25 vulnerabilities.
- Identifies logic-level flaws such as IDOR, SSRF, and unsafe trust boundary crossings.
- Maps every finding to a specific CWE and provides a concrete, language-specific code fix.
- Assigns severity ratings based on exploitability to reduce false-positive fatigue.
- Delivers a final verdict (Approve/Request Changes) suitable for CI/CD integration.
Frameworks & tools
Supports JS/TS, Python, Go, Java, PHP, Ruby, and Rust. Compatible with git environments for diff and context analysis.
Why this beats prompting it yourself
This skill establishes trust boundaries before scanning, preventing the "hallucination fatigue" of generic AI reviews. It follows a systematic checklist across vulnerability classes and mandates a specific severity rubric, ensuring your security standards remain consistent across the entire codebase.
Use cases
- Reviewing a pull request for vulnerabilities before merging into main.
- Automating security gates in CI/CD pipelines to block high-severity flaws.
- Auditing a specific file or endpoint for exploitable logic bugs.
- Validating a fix for a previously identified security issue.
Known limitations
Does not replace dedicated dependency/CVE scanners or secret-scanning tools. It performs static review and does not execute code for dynamic testing.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
2 people have installed this skill.
Trust & safety
Security scanned
Verified clean 16 days ago
- Free to download with an account