security-review is agent-read markdown (skill) from kunanonj/ai-skills-hub: Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Security Review Skill
This skill ensures all code follows security best practices and identifies potential vulnerabilities.
## When to Activate
- Implementing authentication or authorization
- Handling user input or file uploads
- Creating new API endpoints
- Working with secrets or credentials
- Implementing payment features
- Storing or transmitting sensitive data
- Integrating third-party APIs
## Security Checklist
### 1. Secrets Management
#### FAIL: NEVER Do This
```typescript
const apiKey = "sk-proj-xxxxx" // Hardcoded secret
const dbPassword = "password123" // In source code
```
#### PASS: ALWAYS Do This
```typescript
const apiKey = process.env.OPENAI_API_KEY
const dbUrl = process.env.DATABASE_URL
// Verify secrets exist
if (!apiKey) {
throw new Error('OPENAI_API_KEY not configured')
}
```
#### Verification Steps
- [ ] No hardcoded API keys, tokens, or passwords
- [ ] All secrets in environment variables
- [ ] `.env.local` in .gitignore
- [ ] No secrets in git history
- [ ] Production secrets in hosting platform (Vercel, Railway)
### 2. Input Validation
#### Always Validate User Input
```typescript
import { z } from 'zod'
// Define validation schema
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
GET https://markdownregistry.com/api/v1/artifacts/art_7kp4fm2mpklwtrow
GET https://markdownregistry.com/api/v1/resolve?ref=kunanonj/ai-skills-hub/security-review
GET https://markdownregistry.com/api/v1/blob/e60a179eac26386cfc72d4bdebbe280f94a2d94ed889d6e221edbf1939f944d4
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
kunanonj/ai-skills-hub · .agents/skills/analyze-codebase-for-mcp/SKILL.md · Analyze an arbitrary codebase to identify functions, APIs, and data sources suitable for exposure as MCP tools…
kunanonj/ai-skills-hub · .agents/skills/api-analyzer/SKILL.md · Validates whether an API request is correct based on provided inputs (method, URL, headers, body, auth, query params)…
kunanonj/ai-skills-hub · .agents/skills/api-design-principles/SKILL.md · Master REST and GraphQL API design principles to build intuitive, scalable, and maintainable APIs that delight…
kunanonj/ai-skills-hub · .agents/skills/architecture-decision-records/SKILL.md · Comprehensive patterns for creating, maintaining, and managing Architecture Decision Records (ADRs) that capture the…
kunanonj/ai-skills-hub · .agents/skills/backend-api-design/SKILL.md · Design RPC-style APIs with layered architecture (Controller → Manager → Repository). Use when creating new API…
kunanonj/ai-skills-hub · .agents/skills/backend-dev-guidelines/SKILL.md · You are a senior backend engineer operating production-grade services under strict architectural and reliability…
kunanonj/ai-skills-hub · .agents/skills/backend-security-coder/SKILL.md · Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use…
kunanonj/ai-skills-hub · .agents/skills/browser-screenshot-diff/SKILL.md · Visual + DOM diff between two recorded sessions at matching trajectory step ids; used for visual regression and replay…
kunanonj/ai-skills-hub · .agents/skills/browser-testing-with-devtools/SKILL.md · Tests in real browsers via Chrome DevTools MCP. Use when building or debugging anything that runs in a browser. Use…
affaan-m/ecc · .agents/skills/security-review/SKILL.md · Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or…
affaan-m/ecc · .kiro/skills/security-review/SKILL.md · Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or…
affaan-m/ecc · docs/es/skills/security-review/SKILL.md · Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o…
microsoft/power-platform-skills · plugins/power-pages/skills/security-review/SKILL.md · Runs a guided, end-to-end security review of a Power Pages site and consolidates every finding into one HTML report…