skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
nishilbhave/codeprobe140 installs

codeprobe-security

Scans code for security vulnerabilities — injection flaws, authentication gaps, XSS vectors, mass assignment, CSRF, insecure deserialization, sensitive data exposure, broken access control, and misconfigurations. Generates severity-scored findings with copy-pasteable fix prompts. Trigger phrases: "security scan", "security audit", "vulnerability check", "find security issues".

How do I install this agent skill?

npx skills add https://github.com/nishilbhave/codeprobe --skill codeprobe-security
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill is a security vulnerability scanner that processes source code files. It presents an indirect prompt injection surface because it parses untrusted third-party code while holding powerful execution capabilities like Bash, without employing distinct boundary delimiters or sanitization steps.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Standalone Mode

If invoked directly (not via the orchestrator), you must first:

  1. Read ../codeprobe/shared-preamble.md (resolve relative to this SKILL.md's location — the sibling codeprobe skill directory — not the user's project) for the output contract, execution modes, and constraints.
  2. Load applicable reference files from ../codeprobe/references/ (same resolution) based on the project's tech stack.
  3. Default to full mode unless the user specifies otherwise.

Security Vulnerability Scanner

Domain Scope

This sub-skill detects security vulnerabilities across these categories:

  1. Injection — SQL injection, command injection, LDAP/NoSQL injection
  2. Authentication & Authorization — Missing auth, weak credentials, hardcoded secrets, JWT issues
  3. Cross-Site Scripting (XSS) — Unescaped output, dangerous HTML rendering
  4. Mass Assignment — Unprotected model attribute assignment
  5. Cross-Site Request Forgery (CSRF) — Missing tokens, unprotected state-changing routes
  6. Insecure Deserialization — Unsafe deserialization of untrusted data
  7. Sensitive Data Exposure — Secrets in logs, committed .env files, leaked stack traces
  8. Broken Access Control — IDOR, missing policy/gate checks
  9. Security Misconfiguration — Debug mode in production, permissive CORS, default credentials

What It Does NOT Flag

  • Internal admin tools with IP-restricted access — these have a different threat model and the restriction may be intentional.
  • Test files using hardcoded values — test fixtures with fake credentials, tokens, and API keys are expected and appropriate.
  • Development-only configuration files clearly marked as such (e.g., .env.example, docker-compose.dev.yml, files in tests/fixtures/).
  • Dependencies with known CVEs — this sub-skill analyzes source code, not dependency manifests. Use dedicated tools (e.g., npm audit, composer audit) for dependency scanning.

Detection Instructions

Injection

ID PrefixWhat to DetectHow to DetectSeverity
SECRaw SQL with string concatenation/interpolationSearch for SQL keywords (SELECT, INSERT, UPDATE, DELETE, WHERE) combined with string concatenation (., +, f", ${}, "${), template literals, or variable interpolation. Check that user input flows into the query string without parameterization.Critical
SECDB::raw() / raw queries with user inputSearch for DB::raw(), DB::select(DB::raw(, knex.raw(), sequelize.literal(), cursor.execute(f" and similar raw query methods. Flag when the argument contains variables that could originate from user input (request params, form data, query strings).Critical
SECShell command construction with unsanitized inputSearch for exec(), system(), shell_exec(), popen(), subprocess.call(), subprocess.run(), child_process.exec(), backtick operators. Flag when the command string includes variables from user input without escaping or allowlist validation.Critical
SECLDAP/NoSQL injection vectorsSearch for LDAP filter construction with string concatenation, MongoDB query construction with user input in $where, $regex, or other operators that accept arbitrary expressions.Critical

Authentication & Authorization

ID PrefixWhat to DetectHow to DetectSeverity
SECMissing auth middleware on routes that modify dataScan route definitions (e.g., Route::post(), router.post(), @app.post()) for POST/PUT/PATCH/DELETE endpoints. Check whether auth middleware is applied. Flag routes that modify data without any authentication layer.Critical
SECRole checks done in view/frontend but not backendSearch for role/permission checks in frontend templates or JavaScript (e.g., v-if="user.isAdmin", {user.role === 'admin' && ...}) and verify that the corresponding backend endpoint also enforces the check. If backend lacks it, flag.Major
SECHardcoded secrets/API keys in source codeSearch for patterns: api_key = "...", secret = '...', password = "...", token = '...', AWS_SECRET, STRIPE_KEY, bearer tokens, and similar. Exclude .env.example files and test fixtures. Check for high-entropy strings assigned to variables with secret-like names.Critical
SECWeak password policyLook for user registration/password-change logic. Check whether password validation enforces minimum length (8+ chars), complexity, or uses a validation library. Flag if passwords are accepted without any validation rules.Major
SECJWT without expirationSearch for JWT creation/signing code. Check whether the payload includes an exp (expiration) claim. Flag JWTs created without expiration or with excessively long expiration (> 24 hours for access tokens).Major

Cross-Site Scripting (XSS)

ID PrefixWhat to DetectHow to DetectSeverity
SEC{!! !!} (unescaped output) in Laravel Blade with user dataSearch for {!! ... !!} in .blade.php files. Check whether the content inside originates from user input, database fields that store user-provided HTML, or request data. Exclude static content and trusted admin-only fields.Major
SECdangerouslySetInnerHTML in React with untrusted dataSearch for dangerouslySetInnerHTML in .jsx/.tsx files. Check whether the __html value comes from user input, API responses without sanitization, or any source not explicitly sanitized with DOMPurify or equivalent.Major
SECv-html in Vue with untrusted dataSearch for v-html directives in .vue files. Same analysis as above — flag when the bound value could contain unsanitized user input.Major
SECMissing Content-Security-PolicyCheck for CSP headers in middleware, web server config, or meta tags. If no CSP is configured anywhere in the project, flag as a defense-in-depth gap.Minor

Mass Assignment

ID PrefixWhat to DetectHow to DetectSeverity
SECLaravel model without $fillable or $guardedSearch for Eloquent model classes (extending Model). Check whether each model defines either $fillable (allowlist) or $guarded (blocklist) property. Flag models that define neither.Major
SECAccepting $request->all() into create/updateSearch for $request->all(), request.body (without destructuring), **request.data passed directly into Model::create(), Model::update(), Model::fill(), or ORM create/update methods. Flag as mass assignment vector.Critical

Cross-Site Request Forgery (CSRF)

ID PrefixWhat to DetectHow to DetectSeverity
SECForms without CSRF tokensSearch for <form tags with method="POST" (or PUT/PATCH/DELETE). Check whether the form includes a CSRF token field (@csrf, csrf_token(), csrfmiddlewaretoken, _token). Flag forms missing tokens.Major
SECAPI routes without proper auth that modify stateCheck API routes (POST/PUT/PATCH/DELETE) that lack both CSRF protection AND authentication middleware. Stateless APIs with token auth are fine; session-based APIs without CSRF tokens are not.Major

Insecure Deserialization

ID PrefixWhat to DetectHow to DetectSeverity
SECunserialize() on user inputSearch for unserialize() (PHP), pickle.loads() (Python), ObjectInputStream (Java), Marshal.load (Ruby). Flag when the input source is user-controlled (request body, cookies, query params, uploaded files).Critical
SECJSON.parse() without validation used in eval-like contextSearch for JSON.parse() of external data where the parsed result is passed to eval(), Function(), setTimeout(string), or used to construct code dynamically. Flag the eval-like usage, not JSON.parse itself.Major

Sensitive Data Exposure

ID PrefixWhat to DetectHow to DetectSeverity
SECPasswords/tokens in log statementsSearch for logging calls (Log::, logger., console.log, print, logging.) that include variables named password, token, secret, key, credential, auth, or similar. Flag when sensitive data is written to logs.Critical
SEC.env committed to gitCheck whether .gitignore includes .env. If .env exists in the repository and is not gitignored, flag as critical. Also check for .env.production, .env.staging committed.Critical
SECSecrets in config files vs environment variablesSearch config files for hardcoded credentials, API keys, database passwords. Flag values that should come from environment variables but are instead hardcoded in tracked config files.Major
SECError messages leaking stack traces in production configCheck error/exception handling configuration. Look for APP_DEBUG=true, DEBUG=True, display_errors=On, or custom error handlers that expose stack traces, file paths, or SQL queries in responses. Flag when this is in production config.Major

Broken Access Control

ID PrefixWhat to DetectHow to DetectSeverity
SECIDOR — using user-supplied ID without ownership checkSearch for route parameters or request params (e.g., $request->id, params.id, request.args.get('id')) used to fetch resources without verifying the authenticated user owns the resource. Look for Model::find($id) without a where('user_id', auth()->id()) or policy check.Critical
SECMissing policy/gate checks on resource accessIn frameworks with authorization systems (Laravel policies, Django permissions, Express middleware), check whether CRUD operations on user-owned resources include authorization checks. Flag controller actions that read/modify resources without policy or permission verification.Major

Security Misconfiguration

ID PrefixWhat to DetectHow to DetectSeverity
SECAPP_DEBUG=true in production configsSearch for APP_DEBUG=true, DEBUG=True, debug: true in configuration files that appear to be production configs (not .env.example or .env.local).Major
SECPermissive CORSSearch for CORS configuration. Flag Access-Control-Allow-Origin: * or allowed_origins: ['*'] in non-public-API contexts. Also flag Access-Control-Allow-Credentials: true combined with wildcard origins.Major
SECDefault credentials in configurationSearch for usernames like admin, root, test paired with passwords like password, 123456, admin, secret, changeme in config files, seeders, or initialization code. Exclude test fixtures.Critical

ID Prefix & Fix Prompt Examples

All findings use the SEC- prefix, numbered sequentially: SEC-001, SEC-002, etc.

Fix Prompt Examples

  • "In UserController@update (line 34), replace $request->all() with $request->only(['name', 'email']) to prevent mass assignment on the is_admin field. Also add $fillable = ['name', 'email'] to the User model if not already present."
  • "Wrap the user input at line 55 of app/Services/SearchService.php in a parameterized query: change DB::select(\"SELECT * FROM products WHERE name LIKE '%$search%'\") to DB::select('SELECT * FROM products WHERE name LIKE ?', [\"%{$search}%\"])."
  • "In routes/api.php, add auth middleware to the POST /api/orders route at line 22: change Route::post('/orders', [OrderController::class, 'store']) to Route::post('/orders', [OrderController::class, 'store'])->middleware('auth:sanctum')."
  • "Move the hardcoded API key at line 15 of config/services.php to an environment variable: replace 'key' => 'sk-live-abc123...' with 'key' => env('STRIPE_SECRET_KEY') and add STRIPE_SECRET_KEY= to .env.example."

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/nishilbhave/codeprobe/codeprobe-security">View codeprobe-security on skillZs</a>