Install
$ agentstack add skill-kannandreams-tuff-security-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Security Review Skill
When to invoke this skill
Review a codebase or change for security issues — exposed secrets, injection vectors, insecure defaults, dependency vulnerabilities, and missing access controls. Use this before merging sensitive changes, when integrating a new third-party dependency, or as a pre-release gate.
Do NOT use this for general code quality or style review — code-review handles that. Do NOT use this for compliance audits (SOC 2, HIPAA) or penetration testing — those require specialized tooling and scope beyond a code-level review.
Inputs
- code or config change to review
- authentication and authorization model
- data classification (PII, secrets, public)
- dependency manifest
- deployment environment context
- known threat model or attack surface notes
Outputs
- vulnerability findings ordered by severity
- exposed secrets or credentials
- insecure configuration patterns
- dependency risk notes
- recommended fixes with concrete locations
- residual risk assessment
Rules
- Prioritize issues that expose data, credentials, or allow unauthorized
access.
- Ground findings in concrete file and line references.
- Distinguish between confirmed vulnerabilities and hardening suggestions.
- Never log or echo secrets found during review.
- Check configuration files, CI/CD pipeline configs, and documentation for
secrets — not just source code.
- Treat third-party dependency changes as elevated risk.
Example Workflow
- Read the change summary and scope.
- Scan for secrets and credentials in source, config, and CI files.
- Review authentication and authorization paths affected by the change.
- Check for injection vectors (SQL, command, template) in new or modified
input handling.
- Review dependency changes for known vulnerabilities.
- Check error handling for information leakage.
- Write findings in severity order with concrete fix recommendations.
Security Review Checklist
- [ ] No secrets or credentials in source, config, or CI files
- [ ] No user input reaches SQL, shell, or templating engines unsanitized
- [ ] Authentication checks exist on all protected routes or endpoints
- [ ] Authorization boundaries are enforced, not just checked on the client
- [ ] Error messages do not leak stack traces, paths, or internal state
- [ ] New dependencies have acceptable vulnerability profiles
- [ ] Environment-specific configuration does not weaken security in prod
Acceptance Criteria
The review is complete when it:
- documents the files, configs, and manifests inspected
- reports any exposed secret or credential found without repeating the secret value
- checks injection paths introduced or changed in scope
- checks authentication and authorization paths affected by the change
- flags dependency risks with specific version or CVE references
- provides actionable fix recommendations for each finding
- documents residual risk where a fix is deferred
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kannandreams
- Source: kannandreams/tuff
- License: MIT
- Homepage: https://tuffcli.dev
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.