← ClaudeAtlas

security-reviewlisted

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
SamuelAlev/control-center · ★ 5 · Code & Development · score 75
Install: claude install-skill SamuelAlev/control-center
<!-- Reference material based on OWASP Cheat Sheet Series (CC BY-SA 4.0) https://cheatsheetseries.owasp.org/ --> # Security Review Skill Identify exploitable security vulnerabilities in code. Report only **HIGH CONFIDENCE** findings—clear vulnerable patterns with attacker-controlled input. ## Scope: Research vs. Reporting **CRITICAL DISTINCTION:** - **Report on**: Only the specific file, diff, or code provided by the user - **Research**: The ENTIRE codebase to build confidence before reporting Before flagging any issue, you MUST research the codebase to understand: - Where does this input actually come from? (Trace data flow) - Is there validation/sanitization elsewhere? - How is this configured? (Check settings, config files, middleware) - What framework protections exist? **Do NOT report issues based solely on pattern matching.** Investigate first, then report only what you're confident is exploitable. ## Confidence Levels | Level | Criteria | Action | |-------|----------|--------| | **HIGH** | Vulnerable pattern + attacker-controlled input confirmed | **Report** with severity | | **MEDIUM** | Vulnerable pattern, input source unclear | **Note** as "Needs verification" | | **LOW** | Theoretical, best practice, defense-in-depth | **Do not report** | ## Do Not Flag ### General Rules - Test files (unless explicitly reviewing test security) - Dead code, commented code, documentation strings - Patterns using **constants** or **server-controlled configuration** - Code p