What are you proposing? A new skill (several candidates).
What problem does it solve?
These areas fit a security and code-review collection, but no current skill covers them or only a sub-bullet touches them:
- LLM / agent-integration security: prompt injection through retrieved content, over-privileged tool calls, missing human confirmation on side effects, MCP server configuration, and model output used as code, SQL or shell. Source: OWASP Top 10 for LLM Applications. This is probably the most in-demand gap for a collection aimed at coding-assistant users.
- Secrets: hard-coded credentials, secrets in config/test fixtures/CI, weak secret generation, rotation after exposure, and
.gitignore/.dockerignore gaps. Several skills touch this today with inconsistent severities (see the severity-alignment issue).
- Privacy / PII: data minimisation, PII in analytics and telemetry, retention and deletion paths, cross-border transfer hooks.
- Frontend: XSS sinks by framework (
dangerouslySetInnerHTML, v-html, innerHTML), CSP, postMessage origin checks, token storage in localStorage.
- API authorization: object- and function-level authorization, mass assignment, rate limiting (OWASP API Security Top 10).
security-review's V8 covers part of this.
- Container / Dockerfile: only partly covered by
iac-review today.
Proposed approach
Handle each skill as its own PR: structural template, fetched and cited sources, a golden-diff eval fixture, and ideally a clean-diff fixture (see the eval issues).
What are you proposing? A new skill (several candidates).
What problem does it solve?
These areas fit a security and code-review collection, but no current skill covers them or only a sub-bullet touches them:
.gitignore/.dockerignoregaps. Several skills touch this today with inconsistent severities (see the severity-alignment issue).dangerouslySetInnerHTML,v-html,innerHTML), CSP,postMessageorigin checks, token storage inlocalStorage.security-review's V8 covers part of this.iac-reviewtoday.Proposed approach
Handle each skill as its own PR: structural template, fetched and cited sources, a golden-diff eval fixture, and ideally a clean-diff fixture (see the eval issues).