Install
$ agentstack add skill-jakesterns-agent-skills-security-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Security Review
Use this skill when reviewing code, diffs, pull requests, configuration, or deployment changes for security risk.
Inputs
- Target diff, files, pull request, or codebase area
- Runtime context such as framework, language, cloud provider, auth model, or data sensitivity
- Any known threat model, compliance requirement, or recent incident context
Steps
- Identify trust boundaries: user input, network calls, database access, file access, credentials, external services, and privileged operations.
- Review authentication and authorization paths for missing checks, confused deputy risks, privilege escalation, insecure session handling, and tenant isolation bugs.
- Inspect input handling for injection, path traversal, deserialization, unsafe redirects, SSRF, XSS, command execution, and parser edge cases.
- Check secret handling: hardcoded keys, logs that expose tokens, unsafe environment variable use, weak rotation assumptions, and accidental credential persistence.
- Review data protection: encryption, PII handling, access logging, retention, masking, backup exposure, and cross-environment data leakage.
- Inspect dependency and configuration risk: insecure defaults, broad CORS, debug flags, weak TLS, overbroad IAM, unpinned tools, and supply-chain exposure.
- Validate error handling and observability: avoid leaking sensitive details while preserving useful audit trails.
- Prioritize findings by exploitability and impact.
Output
Return:
- Security posture summary
- Findings ordered by severity: Critical, High, Medium, Low
- File and line references where possible
- Exploit scenario in one or two sentences for each significant finding
- Concrete remediation steps
- Residual risk or assumptions
Guidelines
- Do not invent vulnerabilities. If a risk depends on an assumption, say so.
- Prefer specific fixes over generic advice.
- Treat missing tests for security-sensitive behavior as a finding.
- Call out strong security decisions when they reduce risk.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jakesterns
- Source: jakesterns/agent-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.