review-security skillA
review-security is agent-read markdown (skill) from phelan164/codex-howto: Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. Use for security reviews, threat-focused PR reviews, authentication or authorization changes, input handling, secrets, dependencies, and infrastructure permissions; do not use to exploit live systems or modify code unless separately requested..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Review Security ## Workflow 1. Establish the review target, intended behavior, and relevant threat model. 2. Identify assets, trust boundaries, actors, entry points, and sensitive operations. 3. Trace attacker-controlled data to security-relevant sinks. 4. Inspect authentication, authorization, tenant isolation, and privilege changes. 5. Evaluate realistic exploitability and existing controls. 6. Validate suspected findings safely with read-only analysis or sandboxed tests when authorized. 7. Return prioritized findings with evidence, impact, prerequisites, and remediation direction. ## Guardrails - Work read-only by default. - Do not access production systems, real customer data, or private credentials. - Do not publish weaponized exploit details or active secrets. - Avoid checklist-only findings without a reachable attack path. - Distinguish a missing defense-in-depth measure from an exploitable vulnerability. - Treat dependency scanner output as leads requiring context. - Keep proof-of-concept activity scoped, reversible, and authorized. ## Threat checklist …
Read the whole file at its exact version.
How to install
mdr add phelan164/codex-howto/review-security@git:20260724.a8a7148mdr add phelan164/codex-howto/review-security@sha256:4eb555141d87b46aPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_tullrvmquv7slmsf)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (2404 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
phelan164/codex-howto · 9 stars · license MIT · pushed 2026-09-21 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_tullrvmquv7slmsf GET https://markdownregistry.com/api/v1/resolve?ref=phelan164/codex-howto/review-security GET https://markdownregistry.com/api/v1/blob/4eb555141d87b46a2bc3adbdc2492d540f3d8defc4909876e9baa01b09d2ee51
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from phelan164/codex-howto
Every file in phelan164/codex-howto