Agent skill

Security Review

by jewbetcha in jewbetcha/opentrace

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

MITAuto-check: notesSecurity

Install Security Review

skills CLI
$ npx skills add jewbetcha/opentrace --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jewbetcha/opentrace security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
116
Used in
18 other repos
Token cost
~3.1k tokens
SKILL.md length
495 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

  • Works in 10 steps: Secrets Management → Input Validation → SQL Injection Prevention → …
  • Adding authentication
  • SKILL.md covers When to Activate, Security Checklist, Security Testing and Pre-Deployment Security…, plus 1 more section
  • Calls npm and git; needs OPENAI_API_KEY

What it does

Security Review is an agent skill from jewbetcha/opentrace. Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Web application vulnerabilities and REST APIs. It works with Supabase. The licence is MIT.

When your agent uses it

  • Adding authentication
  • Handling user input
  • Working with secrets
  • Creating API endpoints

Example prompts

  • “/security-review”

Requirements

  • Node.js
  • A credential in OPENAI_API_KEY

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Secrets Management
  2. Input Validation
  3. SQL Injection Prevention
  4. Authentication & Authorization
  5. XSS Prevention
  6. CSRF Protection
  7. Rate Limiting
  8. Sensitive Data Exposure
  9. Blockchain Security (Solana)
  10. Dependency Security

What it can do on your machine

Read from SKILL.md and the folder at commit 3211e35. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • nextjs.org
    • supabase.com
    • portswigger.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 3.1k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 495 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:46
    - [ ] `.env.local` in .gitignore

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jewbetcha/opentrace at commit 3211e35, republished under its MIT licence (© jewbetcha). 495 words, ~3,054 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder).
name
security-review
description
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
author
affaan-m
version
1.0

Security Review Skill

This skill ensures all code follows security best practices and identifies potential vulnerabilities.

When to Activate

  • Implementing authentication or authorization
  • Handling user input or file uploads
  • Creating new API endpoints
  • Working with secrets or credentials
  • Implementing payment features
  • Storing or transmitting sensitive data
  • Integrating third-party APIs

Security Checklist

1. Secrets Management
❌ NEVER Do This
typescript
const apiKey = "sk-proj-xxxxx"  // Hardcoded secret
const dbPassword = "password123" // In source code
✅ ALWAYS Do This
typescript
const apiKey = process.env.OPENAI_API_KEY
const dbUrl = process.env.DATABASE_URL

// Verify secrets exist
if (!apiKey) {
  throw new Error('OPENAI_API_KEY not configured')
}
Verification Steps
  • No hardcoded API keys, tokens, or passwords
  • All secrets in environment variables
  • .env.local in .gitignore
  • No secrets in git history
  • Production secrets in hosting platform (Vercel, Railway)
2. Input Validation
Always Validate User Input
typescript
import { z } from 'zod'

// Define validation schema
const CreateUserSchema = z.object({
  email: z.string().email(),
  name: z.string().min(1).max(100),
  age: z.number().int().min(0).max(150)
})

// Validate before processing
export async function createUser(input: unknown) {
  try {
    const validated = CreateUserSchema.parse(input)
    return await db.users.create(validated)
  } catch (error) {
    if (error instanceof z.ZodError) {
      return { success: false, errors: error.errors }
    }
    throw error
  }
}
File Upload Validation
typescript
function validateFileUpload(file: File) {
  // Size check (5MB max)
  const maxSize = 5 * 1024 * 1024
  if (file.size > maxSize) {
    throw new Error('File too large (max 5MB)')
  }

  // Type check
  const allowedTypes = ['image/jpeg', 'image/png', 'image/gif']
  if (!allowedTypes.includes(file.type)) {
    throw new Error('Invalid file type')
  }

  // Extension check
  const allowedExtensions = ['.jpg', '.jpeg', '.png', '.gif']
  const extension = file.name.toLowerCase().match(/\.[^.]+$/)?.[0]
  if (!extension || !allowedExtensions.includes(extension)) {
    throw new Error('Invalid file extension')
  }

  return true
}
Verification Steps
  • All user inputs validated with schemas
  • File uploads restricted (size, type, extension)
  • No direct use of user input in queries
  • Whitelist validation (not blacklist)
  • Error messages don't leak sensitive info
3. SQL Injection Prevention
❌ NEVER Concatenate SQL
typescript
// DANGEROUS - SQL Injection vulnerability
const query = `SELECT * FROM users WHERE email = '${userEmail}'`
await db.query(query)
✅ ALWAYS Use Parameterized Queries
typescript
// Safe - parameterized query
const { data } = await supabase
  .from('users')
  .select('*')
  .eq('email', userEmail)

// Or with raw SQL
await db.query(
  'SELECT * FROM users WHERE email = $1',
  [userEmail]
)
Verification Steps
  • All database queries use parameterized queries
  • No string concatenation in SQL
  • ORM/query builder used correctly
  • Supabase queries properly sanitized
4. Authentication & Authorization
JWT Token Handling
typescript
// ❌ WRONG: localStorage (vulnerable to XSS)
localStorage.setItem('token', token)

// ✅ CORRECT: httpOnly cookies
res.setHeader('Set-Cookie',
  `token=${token}; HttpOnly; Secure; SameSite=Strict; Max-Age=3600`)
Authorization Checks
typescript
export async function deleteUser(userId: string, requesterId: string) {
  // ALWAYS verify authorization first
  const requester = await db.users.findUnique({
    where: { id: requesterId }
  })

  if (requester.role !== 'admin') {
    return NextResponse.json(
      { error: 'Unauthorized' },
      { status: 403 }
    )
  }

  // Proceed with deletion
  await db.users.delete({ where: { id: userId } })
}
Row Level Security (Supabase)
sql
-- Enable RLS on all tables
ALTER TABLE users ENABLE ROW LEVEL SECURITY;

-- Users can only view their own data
CREATE POLICY "Users view own data"
  ON users FOR SELECT
  USING (auth.uid() = id);

-- Users can only update their own data
CREATE POLICY "Users update own data"
  ON users FOR UPDATE
  USING (auth.uid() = id);
Verification Steps
  • Tokens stored in httpOnly cookies (not localStorage)
  • Authorization checks before sensitive operations
  • Row Level Security enabled in Supabase
  • Role-based access control implemented
  • Session management secure
5. XSS Prevention
Sanitize HTML
typescript
import DOMPurify from 'isomorphic-dompurify'

// ALWAYS sanitize user-provided HTML
function renderUserContent(html: string) {
  const clean = DOMPurify.sanitize(html, {
    ALLOWED_TAGS: ['b', 'i', 'em', 'strong', 'p'],
    ALLOWED_ATTR: []
  })
  return <div dangerouslySetInnerHTML={{ __html: clean }} />
}
Content Security Policy
typescript
// next.config.js
const securityHeaders = [
  {
    key: 'Content-Security-Policy',
    value: `
      default-src 'self';
      script-src 'self' 'unsafe-eval' 'unsafe-inline';
      style-src 'self' 'unsafe-inline';
      img-src 'self' data: https:;
      font-src 'self';
      connect-src 'self' https://api.example.com;
    `.replace(/\s{2,}/g, ' ').trim()
  }
]
Verification Steps
  • User-provided HTML sanitized
  • CSP headers configured
  • No unvalidated dynamic content rendering
  • React's built-in XSS protection used
6. CSRF Protection
CSRF Tokens
typescript
import { csrf } from '@/lib/csrf'

export async function POST(request: Request) {
  const token = request.headers.get('X-CSRF-Token')

  if (!csrf.verify(token)) {
    return NextResponse.json(
      { error: 'Invalid CSRF token' },
      { status: 403 }
    )
  }

  // Process request
}
SameSite Cookies
typescript
res.setHeader('Set-Cookie',
  `session=${sessionId}; HttpOnly; Secure; SameSite=Strict`)
Verification Steps
  • CSRF tokens on state-changing operations
  • SameSite=Strict on all cookies
  • Double-submit cookie pattern implemented
7. Rate Limiting
API Rate Limiting
typescript
import rateLimit from 'express-rate-limit'

const limiter = rateLimit({
  windowMs: 15 * 60 * 1000, // 15 minutes
  max: 100, // 100 requests per window
  message: 'Too many requests'
})

// Apply to routes
app.use('/api/', limiter)
Expensive Operations
typescript
// Aggressive rate limiting for searches
const searchLimiter = rateLimit({
  windowMs: 60 * 1000, // 1 minute
  max: 10, // 10 requests per minute
  message: 'Too many search requests'
})

app.use('/api/search', searchLimiter)
Verification Steps
  • Rate limiting on all API endpoints
  • Stricter limits on expensive operations
  • IP-based rate limiting
  • User-based rate limiting (authenticated)
8. Sensitive Data Exposure
Logging
typescript
// ❌ WRONG: Logging sensitive data
console.log('User login:', { email, password })
console.log('Payment:', { cardNumber, cvv })

// ✅ CORRECT: Redact sensitive data
console.log('User login:', { email, userId })
console.log('Payment:', { last4: card.last4, userId })
Error Messages
typescript
// ❌ WRONG: Exposing internal details
catch (error) {
  return NextResponse.json(
    { error: error.message, stack: error.stack },
    { status: 500 }
  )
}

// ✅ CORRECT: Generic error messages
catch (error) {
  console.error('Internal error:', error)
  return NextResponse.json(
    { error: 'An error occurred. Please try again.' },
    { status: 500 }
  )
}
Show full SKILL.md (210 more words)Show less
Verification Steps
  • No passwords, tokens, or secrets in logs
  • Error messages generic for users
  • Detailed errors only in server logs
  • No stack traces exposed to users
9. Blockchain Security (Solana)
Wallet Verification
typescript
import { verify } from '@solana/web3.js'

async function verifyWalletOwnership(
  publicKey: string,
  signature: string,
  message: string
) {
  try {
    const isValid = verify(
      Buffer.from(message),
      Buffer.from(signature, 'base64'),
      Buffer.from(publicKey, 'base64')
    )
    return isValid
  } catch (error) {
    return false
  }
}
Transaction Verification
typescript
async function verifyTransaction(transaction: Transaction) {
  // Verify recipient
  if (transaction.to !== expectedRecipient) {
    throw new Error('Invalid recipient')
  }

  // Verify amount
  if (transaction.amount > maxAmount) {
    throw new Error('Amount exceeds limit')
  }

  // Verify user has sufficient balance
  const balance = await getBalance(transaction.from)
  if (balance < transaction.amount) {
    throw new Error('Insufficient balance')
  }

  return true
}
Verification Steps
  • Wallet signatures verified
  • Transaction details validated
  • Balance checks before transactions
  • No blind transaction signing
10. Dependency Security
Regular Updates
bash
# Check for vulnerabilities
npm audit

# Fix automatically fixable issues
npm audit fix

# Update dependencies
npm update

# Check for outdated packages
npm outdated
Lock Files
bash
# ALWAYS commit lock files
git add package-lock.json

# Use in CI/CD for reproducible builds
npm ci  # Instead of npm install
Verification Steps
  • Dependencies up to date
  • No known vulnerabilities (npm audit clean)
  • Lock files committed
  • Dependabot enabled on GitHub
  • Regular security updates

Security Testing

Automated Security Tests
typescript
// Test authentication
test('requires authentication', async () => {
  const response = await fetch('/api/protected')
  expect(response.status).toBe(401)
})

// Test authorization
test('requires admin role', async () => {
  const response = await fetch('/api/admin', {
    headers: { Authorization: `Bearer ${userToken}` }
  })
  expect(response.status).toBe(403)
})

// Test input validation
test('rejects invalid input', async () => {
  const response = await fetch('/api/users', {
    method: 'POST',
    body: JSON.stringify({ email: 'not-an-email' })
  })
  expect(response.status).toBe(400)
})

// Test rate limiting
test('enforces rate limits', async () => {
  const requests = Array(101).fill(null).map(() =>
    fetch('/api/endpoint')
  )

  const responses = await Promise.all(requests)
  const tooManyRequests = responses.filter(r => r.status === 429)

  expect(tooManyRequests.length).toBeGreaterThan(0)
})

Pre-Deployment Security Checklist

Before ANY production deployment:

  • Secrets: No hardcoded secrets, all in env vars
  • Input Validation: All user inputs validated
  • SQL Injection: All queries parameterized
  • XSS: User content sanitized
  • CSRF: Protection enabled
  • Authentication: Proper token handling
  • Authorization: Role checks in place
  • Rate Limiting: Enabled on all endpoints
  • HTTPS: Enforced in production
  • Security Headers: CSP, X-Frame-Options configured
  • Error Handling: No sensitive data in errors
  • Logging: No sensitive data logged
  • Dependencies: Up to date, no vulnerabilities
  • Row Level Security: Enabled in Supabase
  • CORS: Properly configured
  • File Uploads: Validated (size, type)
  • Wallet Signatures: Verified (if blockchain)

Resources


Remember: Security is not optional. One vulnerability can compromise the entire platform. When in doubt, err on the side of caution.

© jewbetcha, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security-review of jewbetcha/opentrace.

Open the folder on GitHubat commit 3211e35

Used in 18 other repositories

We found 44 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 18 other GitHub owners. This page covers the copy in jewbetcha/opentrace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skilljewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC276k1 repos~3.2kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.5kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT
Securityserithemage/serverless-openclaw196—~633Automated safety check: PassNone
Vibe Checkbenavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    276k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

    2k GitHub stars~2.5k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    在添加身份验证、处理用户输入、操作机密信息、创建 API 接口或实现支付/敏感功能时使用此技能。提供全面的安全自查清单和模式。

    2k GitHub stars~2.4k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security

    serithemage/serverless-openclaw

    References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw.

    196 GitHub stars~633 tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Vibe Check

    benavlabs/vibe-check

    Security audit for web apps, especially AI-built ("vibe coded") ones.

    118 GitHub stars~1.1k tokensUpdated 20 days ago
    SecurityAuto-check: notes
  • Kuri Agent

    justrach/kuri

    Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

    365 GitHub stars~1.3k tokensUpdated 2 mo ago
    SecurityAuto-check: notes

More from jewbetcha/opentrace

  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check: notes
  • Code Review Checklist

    jewbetcha/opentrace

    Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability

    116 GitHub starsUsed in 7 repos~2.9k tokens
    Auto-check passed
  • Codex Review

    jewbetcha/opentrace

    Professional code review with auto CHANGELOG generation, integrated with Codex AI

    116 GitHub starsUsed in 8 repos~243 tokens
    Auto-check passed

Works with

Questions about Security Review

What does Security Review do?

A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Security Review is an agent skill from jewbetcha/opentrace. Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

When should I use Security Review?

Security Review fits situations like: adding authentication; handling user input; working with secrets; creating API endpoints.

How do I install Security Review in Claude Code?

Run `npx skills add jewbetcha/opentrace --skill security-review -a claude-code`. Or copy the skill folder (.agents/skills/security-review in jewbetcha/opentrace) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add jewbetcha/opentrace --skill security-review -a codex`. Or copy the skill folder (.agents/skills/security-review in jewbetcha/opentrace) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jewbetcha/opentrace --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (npm and git) and credentials named OPENAI_API_KEY. Our summary lists: Node.js; A credential in OPENAI_API_KEY.

Does Security Review access the network?

SKILL.md names 4 domains. As links in the text: owasp.org, nextjs.org, supabase.com and portswigger.net. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Security Review (affaan-m/ECC, 276k stars), Security Review (xu-xiang/everything-claude-code-zh, 2k stars), Security Review (xu-xiang/everything-claude-code-zh, 2k stars) and Security (serithemage/serverless-openclaw, 196 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

jewbetcha (a GitHub user) maintains it in jewbetcha/opentrace, which has 116 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on May 23, 2026.

Source: jewbetcha/opentrace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.