Agent skill

Security Review Checklist

by ZeroDeng01 in ZeroDeng01/sublinkPro

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

MITAuto-check passedSecurity

Install Security Review Checklist

skills CLI
$ npx skills add ZeroDeng01/sublinkPro --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZeroDeng01/sublinkPro security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZeroDeng01/sublinkPro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
1.7k
Token cost
~2.3k tokens
SKILL.md length
928 words
Files
11 (incl. references)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

  • Works in 4 steps: Identify Security-Sensitive Changes → Apply Relevant Checklists → Test Security Controls → …
  • Reviewing a change to login, token or session handling
  • SKILL.md covers Security Review Checklist, Security Review Process, Common Security Anti-Patterns and Exit Criteria, plus 1 more section
  • Calls yarn and go

What it does

The skill is a checklist for code changes that touch authentication and authorization logic, MFA, sensitive data such as passwords, tokens and keys, permissioned API endpoints, input validation, database queries, cryptography, CORS and CSP settings, session management or file upload and download. General code review is out of scope. Each area lists what to check, points to a reference guide with code examples and names the project files that are relevant.

Sample checks include whether an endpoint can be reached without authentication, whether roles and permissions are enforced, whether JWT and API tokens are validated for signature, expiry and issuer, and whether sessions use timeouts and secure flags. The MFA section covers enforcement, bypass paths, backup codes, TOTP secret encryption and rate limiting, and the sensitive data section covers password hashing and secrets in logs, responses, transit and storage. The references folder has guides for API security, authentication, cryptography, databases, dependencies, files, input validation, MFA, sensitive data and sessions.

When your agent uses it

  • Reviewing a change to login, token or session handling
  • Checking MFA code for bypass paths and unprotected secrets
  • Auditing a new endpoint for permission checks and input validation

Example prompts

  • “Review my changes to the login handler against the security checklist.”
  • “Check the new MFA backup code feature for storage and rate limiting problems.”
  • “Audit the file upload endpoint I added for validation and permission gaps.”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify Security-Sensitive Changes
  2. Apply Relevant Checklists
  3. Test Security Controls
  4. Document Security Implications

What it can do on your machine

Read from SKILL.md and the folder at commit d9d9e5a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • github.com
    • cheatsheetseries.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review Checklist loads about 2.3k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 928 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ZeroDeng01/sublinkPro at commit d9d9e5a, republished under its MIT licence (© ZeroDeng01). 928 words, ~2,330 tokens.

Download SKILL.mdSave it as .claude/skills/security-review/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
security-review
description
Security review checklist for authentication, authorization, and sensitive data handling. Use when changing auth, MFA, secrets, input validation, or security-critical features. Not for general code review.
version
2.0.0
author
SublinkPro Team
user-invocable
true

Security Review Skill

This skill provides a comprehensive security review checklist for code changes that involve authentication, authorization, sensitive data handling, or security-critical features.

When to use: When making changes to:

  • Authentication/authorization logic
  • MFA (Multi-Factor Authentication) functionality
  • Sensitive data handling (passwords, tokens, API keys, secrets)
  • API endpoints with permission requirements
  • Input validation and sanitization
  • Database queries
  • Cryptographic operations
  • CORS/CSP configurations
  • Session management
  • File upload/download functionality

Security Review Checklist

🔐 1. Authentication & Authorization

Check for:

  • Authentication bypass: Can the endpoint/feature be accessed without proper authentication?
  • Authorization checks: Are user permissions verified before allowing access?
  • Role-based access control: Are roles (admin, user, guest) properly enforced?
  • Token validation: Are JWT/API tokens properly validated (signature, expiration, issuer)?
  • Session security: Are sessions properly managed (timeout, secure flags, HttpOnly)?

Detailed guide: references/authentication-guide.md (includes code examples)

Relevant files:

  • api/auth.go
  • api/auth_mfa.go
  • middlewares/auth.go
  • middlewares/mfa.go

🔑 2. MFA (Multi-Factor Authentication)

Check for:

  • MFA enforcement: Is MFA required for sensitive operations?
  • MFA bypass prevention: Can MFA be circumvented through alternate flows?
  • Backup codes security: Are backup codes securely generated and stored?
  • TOTP secret protection: Are TOTP secrets encrypted at rest?
  • Rate limiting: Is there rate limiting on MFA verification attempts?

Detailed guide: references/mfa-guide.md

Relevant files:

  • api/auth_mfa.go
  • models/mfa.go
  • middlewares/mfa.go

🛡️ 3. Sensitive Data Handling

Check for:

  • Password storage: Are passwords hashed with bcrypt/argon2 (never plain text)?
  • Secrets in logs: Are secrets/tokens masked in logs and error messages?
  • Secrets in responses: Are sensitive fields (passwords, tokens) excluded from API responses?
  • Secrets in transit: Are sensitive data transmitted over HTTPS only?
  • Secrets in database: Are secrets encrypted at rest (API keys, tokens)?

Detailed guide: references/sensitive-data-guide.md (includes code examples)


🔍 4. Input Validation & Sanitization

Check for:

  • SQL injection: Are SQL queries parameterized (no string concatenation)?
  • XSS (Cross-Site Scripting): Is user input sanitized before rendering?
  • Command injection: Are shell commands parameterized (no user input in commands)?
  • Path traversal: Are file paths validated (no ../ attacks)?
  • Type validation: Are input types validated (strings, numbers, emails, URLs)?
  • Length validation: Are input lengths limited to prevent DoS?
  • Whitelist validation: Are inputs validated against allowed values?

Detailed guide: references/input-validation-guide.md (includes code examples)


🗄️ 5. Database Security

Check for:

  • Parameterized queries: Are all queries parameterized (GORM Where with ?)?
  • Mass assignment protection: Are only allowed fields updated?
  • Soft delete leaks: Are soft-deleted records excluded from queries?
  • Permission checks before queries: Is authorization checked before database access?
  • Transactions for critical ops: Are multi-step operations wrapped in transactions?

Detailed guide: references/database-security-guide.md (includes code examples)


🌐 6. API Security

Check for:

  • CORS configuration: Are CORS origins properly restricted (not * in production)?
  • Rate limiting: Are endpoints rate-limited to prevent abuse?
  • API key validation: Are API keys validated before processing requests?
  • HTTPS enforcement: Is HTTPS required for sensitive endpoints?
  • Content-Type validation: Are Content-Type headers validated?
  • Error information leakage: Do error messages avoid exposing internal details?

Detailed guide: references/api-security-guide.md (includes code examples)


🔐 7. Cryptography

Check for:

  • Strong algorithms: Are modern algorithms used (AES-256, bcrypt, argon2)?
  • Avoid weak algorithms: No MD5/SHA1 for passwords, no DES/RC4 for encryption
  • Proper key management: Are encryption keys stored securely (not in code)?
  • Secure random generation: Is crypto/rand used (not math/rand)?
  • IV/Salt usage: Are IVs/salts unique per encryption/hash?

Detailed guide: references/cryptography-guide.md (includes code examples)


📤 8. File Upload/Download Security

Check for:

  • File type validation: Are file types validated by content (not just extension)?
  • File size limits: Are file sizes limited to prevent DoS?
  • Filename sanitization: Are filenames sanitized to prevent path traversal?
  • Virus scanning: Are uploaded files scanned for malware (if applicable)?
  • Storage location: Are files stored outside the web root?
  • Download authorization: Is authorization checked before file download?

Detailed guide: references/file-security-guide.md (includes code examples)


Show full SKILL.md (345 more words)Show less
🔒 9. Session Management

Check for:

  • Session timeout: Are sessions expired after inactivity?
  • Secure flags: Are session cookies marked as Secure and HttpOnly?
  • SameSite attribute: Is SameSite attribute set to prevent CSRF?
  • Session regeneration: Are session IDs regenerated after login?
  • Logout functionality: Does logout properly invalidate the session?

Detailed guide: references/session-management-guide.md (includes code examples)


🛡️ 10. Dependency Security

Check for:

  • Known vulnerabilities: Are dependencies scanned for CVEs?
  • Dependency versions: Are dependencies pinned to specific versions?
  • Minimal dependencies: Are only necessary dependencies included?
  • License compliance: Are dependency licenses compatible with project license?

Detailed guide: references/dependency-security-guide.md

Scan commands:

bash
# Go: Check for known vulnerabilities
govulncheck ./...

# Frontend: Check npm dependencies
cd webs && yarn audit

Security Review Process

Step 1: Identify Security-Sensitive Changes

Review the diff and identify if the change involves authentication, sensitive data, user input, database queries, API endpoints, file operations, or cryptographic operations.

Step 2: Apply Relevant Checklists

Go through the relevant sections above and verify each item. Consult detailed guides in references/ for in-depth coverage.

Step 3: Test Security Controls
  • Manual testing: Try to bypass security controls
  • Automated testing: Run security linters (gosec, eslint-plugin-security)
  • Dependency scanning: Check for known vulnerabilities

Run security linters:

bash
# Backend: gosec
go install github.com/securego/gosec/v2/cmd/gosec@latest
gosec ./...

# Frontend: eslint with security plugin (if configured)
cd webs
yarn lint
Step 4: Document Security Implications

If the change has security implications:

  • Update docs/security-guidelines.md if introducing new security patterns
  • Add security notes to PR description
  • Request security review from another team member for critical changes

Common Security Anti-Patterns

  • Trusting user input: Never trust user input directly; always validate and sanitize
  • Security by obscurity: Obscure endpoints still need proper authentication
  • Client-side validation only: Always validate on backend; frontend validation can be bypassed
  • Logging sensitive data: Never log passwords, tokens, or API keys

Exit Criteria

Before completing the security review:

  • All relevant checklist items have been verified
  • Security linters (gosec, ESLint) pass with no critical issues
  • No sensitive data is exposed in logs, errors, or responses
  • Input validation is implemented for all user-controlled data
  • Authorization checks are in place for all sensitive operations
  • Security implications are documented (if any)
  • Tests cover security scenarios (auth failures, permission denials, invalid input)

References

© ZeroDeng01, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in .agents/skills/security-review of ZeroDeng01/sublinkPro.

  • SKILL.md
  • references/api-security-guide.md
  • references/authentication-guide.md
  • references/cryptography-guide.md
  • references/database-security-guide.md
  • references/dependency-security-guide.md
  • references/file-security-guide.md
  • references/input-validation-guide.md
  • references/mfa-guide.md
  • references/sensitive-data-guide.md
  • references/session-management-guide.md

Open the folder on GitHubat commit d9d9e5a

Compare with similar skills

Security Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review Checklist this skillZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT
Cb Security HardeningBlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Codewhale Security Reviewcodewhale-hq/Codewhale41k—~844Automated safety check: PassMIT
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Codewhale Security Review

    codewhale-hq/Codewhale

    Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

    41k GitHub stars~844 tokensUpdated today
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Agent-Core Security Checklist

    openJiuwen-ai/agent-core

    A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

    442 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check: notes

More from ZeroDeng01/sublinkPro

All 8 skills in this repo
  • Performance Check

    ZeroDeng01/sublinkPro

    Checklist for reviewing code changes that touch queries, APIs, rendering, caching or algorithms for performance, scalability and resource-usage problems.

    1.7k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • SublinkPro Manager

    ZeroDeng01/sublinkPro

    Manages a SublinkPro proxy subscription server through natural language, adding nodes, building subscriptions and share links, and editing templates and tags.

    1.7k GitHub stars~7.2k tokensUpdated today
    Auto-check passed
  • Post-Development Workflow

    ZeroDeng01/sublinkPro

    A required checklist for after code changes: validate each changed layer, check that docs and other layers stay in sync, and test before committing or opening a PR.

    1.7k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Documentation Sync Check

    ZeroDeng01/sublinkPro

    Checklist for keeping README, feature, configuration, install and API docs in step with code changes in the same PR, including the Chinese copies.

    1.7k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Pre-Commit Check Gate

    ZeroDeng01/sublinkPro

    Blocking checklist that runs formatting, lint and test commands for changed Go and frontend files before any git add, commit or pull request.

    1.7k GitHub stars~2.9k tokensUpdated today
    Auto-check: notes
  • Theme Adaptation Checklist

    ZeroDeng01/sublinkPro

    A checklist for UI changes that touch colors, surfaces or theme code, making sure light and dark modes, devices, states and layering all still work.

    1.7k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Security Review Checklist

What does Security Review Checklist do?

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. The skill is a checklist for code changes that touch authentication and authorization logic, MFA, sensitive data such as passwords, tokens and keys, permissioned API endpoints, input validation, database queries, cryptography, CORS and CSP settings, session management or file upload and download. General code review is out of scope.

When should I use Security Review Checklist?

Security Review Checklist fits situations like: reviewing a change to login, token or session handling; checking MFA code for bypass paths and unprotected secrets; auditing a new endpoint for permission checks and input validation.

How do I install Security Review Checklist in Claude Code?

Run `npx skills add ZeroDeng01/sublinkPro --skill security-review -a claude-code`. Or copy the skill folder (.agents/skills/security-review in ZeroDeng01/sublinkPro) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review Checklist in Codex?

Run `npx skills add ZeroDeng01/sublinkPro --skill security-review -a codex`. Or copy the skill folder (.agents/skills/security-review in ZeroDeng01/sublinkPro) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZeroDeng01/sublinkPro --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review Checklist need to run?

Going by SKILL.md and its folder, Security Review Checklist needs the command-line tools its instructions call (yarn and go).

Does Security Review Checklist access the network?

SKILL.md names 3 domains. As links in the text: owasp.org, github.com and cheatsheetseries.owasp.org. This is read from the text; nothing was executed.

Is Security Review Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review Checklist use?

Security Review Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Review Checklist use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.7k tokens, read only when the agent opens those files.

What are the alternatives to Security Review Checklist?

Skills that share tags, products or a category with Security Review Checklist: Cb Security Hardening (BlkLeg/CircuitBreaker, 201 stars), Discover Security (rand/cc-polymath, 181 stars), Codewhale Security Review (codewhale-hq/Codewhale, 41k stars) and Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review Checklist?

ZeroDeng01 (a GitHub user) maintains it in ZeroDeng01/sublinkPro, which has 1,666 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 8, 2026.

Source: ZeroDeng01/sublinkPro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.