Home / phelan164 / codex-howto · skills/review-security/SKILL.md · GitHub

review-security skillA

review-security is agent-read markdown (skill) from phelan164/codex-howto: Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. Use for security reviews, threat-focused PR reviews, authentication or authorization changes, input handling, secrets, dependencies, and infrastructure permissions; do not use to exploit live systems or modify code unless separately requested..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Review Security

## Workflow

1. Establish the review target, intended behavior, and relevant threat model.
2. Identify assets, trust boundaries, actors, entry points, and sensitive operations.
3. Trace attacker-controlled data to security-relevant sinks.
4. Inspect authentication, authorization, tenant isolation, and privilege changes.
5. Evaluate realistic exploitability and existing controls.
6. Validate suspected findings safely with read-only analysis or sandboxed tests when authorized.
7. Return prioritized findings with evidence, impact, prerequisites, and remediation direction.

## Guardrails

- Work read-only by default.
- Do not access production systems, real customer data, or private credentials.
- Do not publish weaponized exploit details or active secrets.
- Avoid checklist-only findings without a reachable attack path.
- Distinguish a missing defense-in-depth measure from an exploitable vulnerability.
- Treat dependency scanner output as leads requiring context.
- Keep proof-of-concept activity scoped, reversible, and authorized.

## Threat checklist
…

Read the whole file at its exact version.

How to install

Latest version
mdr add phelan164/codex-howto/review-security@git:20260724.a8a7148
Exact content
mdr add phelan164/codex-howto/review-security@sha256:4eb555141d87b46a

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_tullrvmquv7slmsf.svg)](https://markdownregistry.com/a/art_tullrvmquv7slmsf)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260724.a8a7148 latest2026-07-24 a8a7148 2,404 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (2404 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

phelan164/codex-howto · 9 stars · license MIT · pushed 2026-09-21 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_tullrvmquv7slmsf
GET https://markdownregistry.com/api/v1/resolve?ref=phelan164/codex-howto/review-security
GET https://markdownregistry.com/api/v1/blob/4eb555141d87b46a2bc3adbdc2492d540f3d8defc4909876e9baa01b09d2ee51

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from phelan164/codex-howto

AGENTS.md agents
phelan164/codex-howto · AGENTS.md
git:20260915.dd80dad · audit A · 9 stars
AGENTS.md@examples agents
phelan164/codex-howto · examples/AGENTS.md
git:20260724.a8a7148 · audit A · 9 stars
evidence-review skill
phelan164/codex-howto · examples/plugin-marketplace/plugins/engineering-review/skills/evidence-review/SKILL.md · Review a small code or documentation change and return only evidence-backed correctness findings. Use in the Codex How…
git:20260724.a8a7148 · audit A · 9 stars
choose-engineering-flow skill
phelan164/codex-howto · examples/skills/choose-engineering-flow/SKILL.md · Select the smallest useful Codex engineering workflow from this repository's existing skills. Use when a task spans…
git:20260731.42e092c · audit A · 9 stars
AGENTS.md@labs/2048-game-benchmark agents
phelan164/codex-howto · labs/2048-game-benchmark/AGENTS.md
git:20260801.7da7a8e · audit A · 9 stars
AGENTS.md@labs/engineering-playground agents
phelan164/codex-howto · labs/engineering-playground/AGENTS.md
git:20260724.a8a7148 · audit A · 9 stars
AGENTS.md@labs/incident-response-benchmark agents
phelan164/codex-howto · labs/incident-response-benchmark/AGENTS.md
git:20260811.78209a9 · audit A · 9 stars
build-backend skill
phelan164/codex-howto · skills/build-backend/SKILL.md · Build or modify backend APIs, services, jobs, persistence, and integrations while preserving contracts, authorization…
git:20260731.42e092c · audit A · 9 stars
build-frontend skill
phelan164/codex-howto · skills/build-frontend/SKILL.md · Build or modify frontend interfaces using repository-native components while preserving accessibility, responsive…
git:20260731.42e092c · audit A · 9 stars
engineering-loop skill
phelan164/codex-howto · skills/engineering-loop/SKILL.md · Drive an authorized repository change through a verified local loop: baseline, reproduce, implement, test, review, and…
git:20260915.dd80dad · audit A · 9 stars
maintain-codex-wiki skill
phelan164/codex-howto · skills/maintain-codex-wiki/SKILL.md · Maintain a review-first Markdown knowledge base for Codex practices with source provenance, engineering capture…
git:20260731.47f36fd · audit A · 9 stars
operate-devops skill
phelan164/codex-howto · skills/operate-devops/SKILL.md · Plan and implement infrastructure, CI/CD, container, deployment, observability, and operational configuration changes…
git:20260724.a8a7148 · audit A · 9 stars

Every file in phelan164/codex-howto

Other files named review-security

review-security skill
gtrabanco/agentic-workflow · skills/review-security/SKILL.md · Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and…
v1.1.0 · audit A · 21 stars
review-security skill
coalesce-labs/catalyst · plugins/dev/skills/review-security/SKILL.md · Security review of a branch's diff against its base for HIGH-CONFIDENCE, exploitable vulnerabilities the change…
git:20260915.10999f5 · audit A · 20 stars
review-security skill
mgiovani/cc-arsenal · skills/review-security/SKILL.md · Perform an OWASP Top 10-focused static security review of a PR, commit, or
v1.1.0 · audit B · 8 stars

Browse by kind, by grade A, or by owner.