dralgorhythm/claude-agentic-framework98 installs
security-review
Conduct security code reviews. Use when reviewing code for vulnerabilities, assessing security posture, or auditing applications. Covers security review checklist.
How do I install this agent skill?
npx skills add https://github.com/dralgorhythm/claude-agentic-framework --skill security-reviewIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill is a security review assistant providing checklists and vulnerable code patterns for auditing. It uses read-only tools and contains no malicious behavior or data exfiltration risks.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- Runlayerpass
1 file scanned · No issues
What does this agent skill do?
Security Review
Review Checklist
Authentication
- Strong password requirements enforced
- MFA implemented for sensitive operations
- Session tokens are cryptographically secure
- Session timeout is appropriate
- Logout properly invalidates session
Authorization
- Access controls checked server-side
- Least privilege principle applied
- Role-based access properly implemented
- Direct object references validated
Input Validation
- All input validated server-side
- Input type and length checked
- Special characters properly handled
- File uploads validated and restricted
Output Encoding
- HTML output properly encoded
- JSON responses use proper content type
- Error messages don't leak information
Cryptography
- Strong algorithms used (AES-256, RSA-2048+)
- No custom crypto implementations
- Keys properly managed
- TLS 1.2+ enforced
Error Handling
- Exceptions handled gracefully
- Error messages don't expose internals
- Failed operations logged
Logging
- Security events logged
- Sensitive data not logged
- Logs protected from tampering
Code Patterns to Flag
SQL Injection
// DANGER
db.query(`SELECT * FROM users WHERE id = ${id}`);
XSS
// DANGER
element.innerHTML = userInput;
Hardcoded Secrets
// DANGER
const API_KEY = "sk-abc123...";
Insecure Random
// DANGER
Math.random(); // For security purposes
Security Review Report
## Security Review: [Component]
### Summary
- Critical: [X]
- High: [X]
- Medium: [X]
- Low: [X]
### Findings
#### [CRITICAL] SQL Injection in UserService
**Location**: src/services/user.ts:47
**Description**: User input concatenated into SQL query
**Remediation**: Use parameterized queries
**Code**:
```typescript
// Current (vulnerable)
// Recommended fix
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/dralgorhythm/claude-agentic-framework/security-review">View security-review on skillZs</a>