Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

CC-BY-SA-4.0Auto-check passedSecurity

Install Security Review

skills CLI
$ npx skills add deadlock-mod-manager/deadlock-mod-manager --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install deadlock-mod-manager/deadlock-mod-manager security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/deadlock-mod-manager/deadlock-mod-manager.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
477
Token cost
~1.8k tokens
SKILL.md length
433 words
Files
10 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

  • Works in 4 steps: Detect Context and Load References → Map Data Flow → Verify Exploitability → …
  • Asked to security review
  • SKILL.md covers Scope, Confidence Levels, Do Not Flag and Threat Model, plus 4 more sections
  • Needs BETTER_AUTH_SECRET and STEAM_API_KEY

What it does

Security Review is an agent skill from deadlock-mod-manager/deadlock-mod-manager. Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", or review code for injection, XSS, IPC abuse, path traversal, or authentication issues. Provides confidence-based reporting tuned to the Deadlock Mod Manager stack.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/api-security.md`, `references/authentication.md` and `references/cryptography.md`).

It sits in Security, covering Security review, Code review and Web application vulnerabilities. It works with Tauri, Rust, Hono and TypeScript. The repository describes itself as: A mod manager for the Valve game Deadlock. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Asked to security review
  • Find vulnerabilities
  • Check for security issues
  • Review code for injection

Example prompts

  • “security review”
  • “find vulnerabilities”
  • “check for security issues”
  • “/security-review”

Requirements

  • A credential in BETTER_AUTH_SECRET
  • A credential in STEAM_API_KEY
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash(read-only commands like cargo, git, npm)

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Detect Context and Load References
  2. Map Data Flow
  3. Verify Exploitability
  4. Classify Severity

What it can do on your machine

Read from SKILL.md and the folder at commit e5a8f5e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash(read-only commands like cargo
    • git
    • npm)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and rust).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cheatsheetseries.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET
    • STEAM_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 1.8k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from deadlock-mod-manager/deadlock-mod-manager at commit e5a8f5e, republished under its CC-BY-SA-4.0 licence (© deadlock-mod-manager). 433 words, ~1,811 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
security-review
description
Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", or review code for injection, XSS, IPC abuse, path traversal, or authentication issues. Provides confidence-based reporting tuned to the Deadlock Mod Manager stack.
allowed-tools
Read, Glob, Grep, Bash(read-only commands like cargo, git, npm)
<!--
Reference material based on OWASP Cheat Sheet Series (CC BY-SA 4.0)
https://cheatsheetseries.owasp.org/
-->

Security Review

Review code for exploitable vulnerabilities in a Tauri 2.x desktop app with a Rust backend, React/TypeScript webview frontend, and Hono/oRPC API server.

Scope

  • Report on: The specific files/changes requested by the user.
  • Research across: The entire codebase to build context before reporting.

Only report findings you can trace to attacker-controlled input reaching a dangerous sink.

Confidence Levels

LevelCriteriaAction
HIGHAttacker-controlled input reaches dangerous sink, no mitigationReport
MEDIUMDangerous pattern, mitigations may exist elsewhereNote for verification
LOWTheoretical, defense-in-depth onlyDo not report

Do Not Flag

  • Test files and fixtures
  • Dead code with no callers
  • React JSX interpolation {variable} (auto-escaped)
  • Drizzle ORM parameterized queries (safe by default)
  • Serde deserialization into strongly-typed Rust structs
  • Tauri plugin scope restrictions working as intended
  • Values only settable by the local user on their own machine
  • Hardcoded constants, env vars, build-time config

Threat Model

This is a desktop mod manager running locally. Key distinctions:

SourceTrust LevelRationale
Local user actionsTrustedUser controls their own machine
Mod archives from GameBananaUntrustedFilenames, metadata, archive contents
API responses from deadlockmods.appSemi-trustedValidate structure, not intent
Deep link parametersUntrustedAny website can trigger deadlock-mod-manager://
IPC messages from webviewUntrusted if XSSXSS escalates to native code execution

Review Process

Step 1: Detect Context and Load References
Code TypeLoad Reference
#[tauri::command], IPC handlersreferences/tauri-ipc.md
React components, webviewreferences/webview-xss.md
Command::new, process spawning, unsafereferences/rust-backend.md
File I/O, archives, pathsreferences/file-operations.md
Hono routes, oRPC proceduresreferences/api-security.md
better-auth, OAuth, sessions, tokensreferences/authentication.md
Cargo.toml, package.jsonreferences/supply-chain.md
Encryption, hashing, key storagereferences/cryptography.md

Load only references relevant to the code under review.

Show full SKILL.md (171 more words)Show less
Step 2: Map Data Flow

For each potential finding, trace:

  1. Source: Where does data originate?
  2. Transforms: What validation/sanitization exists between source and sink?
  3. Sink: Where is data consumed? (filesystem, process, DOM, SQL, IPC)
Step 3: Verify Exploitability
  1. Can an attacker actually control the input?
  2. Does the framework provide automatic protection?
  3. Are there mitigations elsewhere in the call chain?
  4. What is the realistic impact?
Step 4: Classify Severity
SeverityCriteriaExamples
CriticalRCE, sandbox escape, arbitrary file write outside game dirCmd injection via mod metadata, IPC allowing arbitrary path writes
HighData exfil, auth bypass, privilege escalationXSS reaching IPC bridge, path traversal to sensitive files, token leak
MediumLimited impact, requires user interactionStored XSS without IPC access, CSRF on non-critical API endpoints
LowDefense-in-depth improvementsMissing rate limiting, verbose errors, suboptimal CSP

Quick Patterns — Always Flag

# Rust — command injection
Command::new(user_input)
Command::new("sh").arg("-c").arg(format!("... {}", user_input))

# Rust — path traversal (no canonicalize + prefix check)
std::fs::read(format!("{}/{}", base, user_filename))

# Rust — unsafe in IPC handlers
unsafe { } // inside #[tauri::command]

# TypeScript — XSS escalation to native
dangerouslySetInnerHTML={{ __html: modDescription }}
eval(serverData)
window.__TAURI__.invoke(userControlledCommand)

# API — SQL injection via string interpolation
sql`SELECT * FROM mods WHERE name = '${userInput}'`

# Secrets hardcoded in source
BETTER_AUTH_SECRET = "..."
STEAM_API_KEY = "..."
DATABASE_URL = "postgres://user:pass@..."

Quick Patterns — Check Context First

# File ops — safe if path is validated + canonicalized
std::fs::read_to_string(path)
std::fs::write(path, data)

# Process spawn — safe if args are hardcoded/validated
Command::new("steam").arg(game_id)

# Drizzle — safe when using query builder
db.select().from(mods).where(eq(mods.name, input))

# React rendering — safe if data doesn't reach dangerous sink
<div>{modData.description}</div>

Output Format

markdown
## Security Review: [Component/File Name]

### Summary

- **Findings**: X (Y Critical, Z High, ...)
- **Risk Level**: Critical/High/Medium/Low
- **Confidence**: High/Mixed
- **Scope**: [What was reviewed]

### Findings

#### [VULN-001] [Vulnerability Type] (Severity)

- **Location**: `file.rs:123`
- **Confidence**: High/Medium
- **Issue**: [One-line description]
- **Data Flow**: [source] → [transforms] → [sink]
- **Impact**: [What an attacker achieves]
- **Evidence**:
  ```rust
  // vulnerable code
  ```
  • Fix:
    rust
    // remediated code
Needs Verification

[MEDIUM-confidence findings requiring human review]

Not Flagged

[Suspicious patterns confirmed safe, with explanation]


If no vulnerabilities found: "No high-confidence vulnerabilities identified."

© deadlock-mod-manager, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references) in .agents/skills/security-review of deadlock-mod-manager/deadlock-mod-manager.

  • SKILL.md
  • LICENSE
  • references/api-security.md
  • references/authentication.md
  • references/cryptography.md
  • references/file-operations.md
  • references/rust-backend.md
  • references/supply-chain.md
  • references/tauri-ipc.md
  • references/webview-xss.md

Open the folder on GitHubat commit e5a8f5e

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skilldeadlock-mod-manager/deadlock-mod-manager477—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Security Audittheopenco/llmgateway1.7k—~1.8kAutomated safety check: PassCustom licence
Security Practiceseser/stack128—~598Automated safety check: PassCustom licence
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Pump Securitynirholas/pump-fun-sdk133—~892Automated safety check: PassCustom licence

Similar skills

  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    SecurityAuto-check: notes
  • Security Audit

    theopenco/llmgateway

    Security best practices, vulnerability review, and full security audits for LLM Gateway.

    1.7k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…

    128 GitHub stars~598 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Pump Security

    nirholas/pump-fun-sdk

    Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…

    133 GitHub stars~892 tokensUpdated today
    SecurityAuto-check passed
  • Typescript Security Review

    giuseppe-trisciuoglio/developer-kit

    Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

    356 GitHub stars~2.4k tokensUpdated 29 days ago
    SecurityAuto-check: notes

More from deadlock-mod-manager/deadlock-mod-manager

All 24 skills in this repo
  • Skill Creator

    deadlock-mod-manager/deadlock-mod-manager

    Create new agent skills following the Agent Skills specification.

    477 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Create Auth Skill

    deadlock-mod-manager/deadlock-mod-manager

    Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.

    477 GitHub starsUsed in 4 repos~3.4k tokens
    Auto-check passed
  • Opensrc

    deadlock-mod-manager/deadlock-mod-manager

    Fetch source code for npm, PyPI, or crates.io packages and GitHub/GitLab repos to provide AI agents with implementation context beyond types and docs.

    477 GitHub stars~910 tokensUpdated today
    Auto-check passed
  • Babysit

    deadlock-mod-manager/deadlock-mod-manager

    Stay on one pull request until it is merge-ready, fixing the highest-priority blocker and telling the user when it is green.

    477 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Changeset

    deadlock-mod-manager/deadlock-mod-manager

    Generate a changeset file describing the current PR's changes.

    477 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Deadworks Relay

    deadlock-mod-manager/deadlock-mod-manager

    Update the Deadlock Mod Manager server browser implementation to match the latest Deadworks Relay Mesh Protocol v1 spec at ../deadworks-relay/spec/PROTOCOL.md.

    477 GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Security Review

What does Security Review do?

Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs. Security Review is an agent skill from deadlock-mod-manager/deadlock-mod-manager. Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

When should I use Security Review?

Security Review fits situations like: asked to security review; find vulnerabilities; check for security issues; review code for injection.

How do I install Security Review in Claude Code?

Run `npx skills add deadlock-mod-manager/deadlock-mod-manager --skill security-review -a claude-code`. Or copy the skill folder (.agents/skills/security-review in deadlock-mod-manager/deadlock-mod-manager) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add deadlock-mod-manager/deadlock-mod-manager --skill security-review -a codex`. Or copy the skill folder (.agents/skills/security-review in deadlock-mod-manager/deadlock-mod-manager) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add deadlock-mod-manager/deadlock-mod-manager --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

Going by SKILL.md and its folder, Security Review needs credentials named BETTER_AUTH_SECRET and STEAM_API_KEY. Our summary lists: A credential in BETTER_AUTH_SECRET; A credential in STEAM_API_KEY. Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash(read-only commands like cargo, git, npm).

Does Security Review access the network?

SKILL.md names 1 domain. As links in the text: cheatsheetseries.owasp.org. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review is published under the CC-BY-SA-4.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.8k tokens, read only when the agent opens those files.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Audit (theopenco/llmgateway, 1.7k stars), Security Practices (eser/stack, 128 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

deadlock-mod-manager (a GitHub organization) maintains it in deadlock-mod-manager/deadlock-mod-manager, which has 477 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 9, 2026.

Source: deadlock-mod-manager/deadlock-mod-manager on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.