# Secure Code Review

> Apply OWASP Top 10 and CWE Top 25 patterns during code generation and review — Applies to: when generating new code; when reviewing pull requests; when refactoring security-sensitive paths (auth, input handling, file I/O); when adding new HTTP handlers or endpoints

- **Type:** Skill
- **Install:** `agentstack add skill-shieldnet-360-secure-vibe-secure-code-review`
- **Verified:** Pending review
- **Seller:** [ShieldNet-360](https://agentstack.voostack.com/s/shieldnet-360)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [ShieldNet-360](https://github.com/ShieldNet-360)
- **Source:** https://github.com/ShieldNet-360/secure-vibe/tree/main/dist/agent-skills/.agents/skills/secure-code-review

## Install

```sh
agentstack add skill-shieldnet-360-secure-vibe-secure-code-review
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Secure Code Review

Apply OWASP Top 10 and CWE Top 25 patterns during code generation and review

## ALWAYS

- Use parameterized queries / prepared statements for all database access. Never build SQL by string concatenation, even for "trusted" inputs.
- Validate input at the trust boundary — type, length, allowed characters, allowed range — and reject before processing.
- Encode output for the rendering context (HTML escape for HTML, URL encode for query params, JSON encode for JSON output).
- Use the language's built-in cryptography library, never custom-rolled crypto. Prefer AES-GCM for symmetric encryption, Ed25519 / RSA-PSS for signatures, Argon2id / bcrypt for password hashing.
- Use `crypto/rand` (Go), `secrets` module (Python), `crypto.randomBytes` (Node.js), or the platform CSPRNG for any random value involved in security (tokens, IDs, session keys).
- Set explicit security headers on HTTP responses: `Content-Security-Policy`, `Strict-Transport-Security`, `X-Content-Type-Options: nosniff`, `Referrer-Policy`.
- Use the principle of least privilege for file paths, database users, IAM policies, and process privileges.

## NEVER

- Build SQL/NoSQL queries by string concatenation with user input.
- Pass user input directly to `exec`, `system`, `eval`, `Function()`, `child_process`, `subprocess.run(shell=True)`, or any other command-execution path.
- Trust client-side validation. Always re-validate server-side.
- Use `MD5` or `SHA1` for any new security-sensitive purpose (passwords, signatures, HMAC). Use SHA-256 / SHA-3 / BLAKE2 / Argon2id instead.
- Use ECB mode for any encryption, ever. Prefer GCM, CCM, or ChaCha20-Poly1305.
- Use `==` for password comparison — use a constant-time comparison (`hmac.compare_digest`, `crypto.timingSafeEqual`, `subtle.ConstantTimeCompare`).
- Allow user input to determine file paths without canonicalization and allowlist checks (defends against `../../../etc/passwd` style path traversal).
- Disable TLS certificate verification in production code — `verify=False`, `InsecureSkipVerify: true`, `rejectUnauthorized: false`.

## KNOWN FALSE POSITIVES

- Internal admin tools intentionally executing shell commands against trusted, fixed arguments are acceptable when documented and code-reviewed.
- Cryptographic test vectors using `MD5` / `SHA1` for compatibility with documented protocols (e.g. legacy interop tests) are acceptable.
- Constant-time comparison is overkill for non-secret comparisons (string equality in logs, tag matching).

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ShieldNet-360](https://github.com/ShieldNet-360)
- **Source:** [ShieldNet-360/secure-vibe](https://github.com/ShieldNet-360/secure-vibe)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** yes
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: flagged — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-shieldnet-360-secure-vibe-secure-code-review
- Seller: https://agentstack.voostack.com/s/shieldnet-360
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
