Claude Skill

security-review

Review authorized application code, configuration, designs or artifacts for concrete authorization, data exposure, injection, secret, dependency and LLM/tool security risks. Use for a requested security review or a change affecting a trust boundary.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download sgaabdu4-building-flutter-apps-.agents_skills_security-review-c396097.zip · 1 KB
Part of sgaabdu4/building-flutter-apps — 14 skills

Install

skills CLI npx skills add https://github.com/sgaabdu4/building-flutter-apps/tree/main/.agents/skills/security-review
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install sgaabdu4-building-flutter-apps@llmmart
Git git clone https://github.com/sgaabdu4/building-flutter-apps.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole sgaabdu4/building-flutter-apps collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Security Review

Load the review method; use Research when dependency/advisory claims need current evidence. Reuse existing fix/testing authority; review alone adds no remediation or live-exploitation authority.

flowchart LR
  R[Code Review method] -->|Current dependency / advisory evidence| D[Research]
  click R "../code-review/references/review.md"
  click D "../research/SKILL.md"
  • Trace = sensitive asset + caller/input + required permission → actual enforcing owner → operation/data. UI visibility or a caller's check does not prove server authorization.
  • Coverage = focused change → affected path + adjacent callers; broad review → actual entry points + assets, then relevant surfaces below. Mark material missing evidence.
Surface Resolve
Identity / sessions Caller-selected identity, role or tenant; login, recovery, expiry + revocation boundaries.
Data / privilege Actor + tenant enforcement for object, field, list/export + mutation; alternate entry points.
Input / files Query, markup, URL, path, upload/archive → normalization + downstream parser, fetch, storage or execution.
Secrets / artifacts Source, logs, client bundle, generated config + packaged output exposure; inspect the actual in-scope artifact. Internal address alone ≠ secret.
LLM / tools Untrusted content influencing privileged actions; permissions + validated arguments outside the model; required approval at the action boundary.
Dependencies Resolved lockfile/image/SBOM/runtime version + existing scan + primary advisory ranges. Trace production/build/dev/transitive use; manifest range ≠ resolved version. Confirmed vulnerable version ≠ proven exploitability; unknown reachability never waives a required gate.
  • Finding = entry point + actor/input preconditions + enforcing/missing control + affected asset + realistic impact. Test competing explanations through source + permitted probes; unproven exploit path stays unknown.
  • Secret evidence = type + location + exposure path; mask values. Keep findings, optional hardening + unresolved questions distinct.
  • Authorized fix = smallest control satisfying the requirement; verify original unauthorized path denied + legitimate access preserved at the actual permission/input boundary. Run applicable gates.
  • Result = assessed surfaces + findings + gaps. Scanner success proves only its checked scope; no whole-application certification or implied runtime proof.
Files (building-flutter-apps)
  • agents
    • openai.yaml 308 B
      interface:
        display_name: "Security Review"
        short_description: "Review application security with evidence"
        default_prompt: "Use $security-review to review this authorized application surface for concrete security risks and report supporting evidence and gaps."
      policy:
        allow_implicit_invocation: true
      
  • SKILL.md 2.7 KB
    ---
    name: security-review
    description: Review authorized application code, configuration, designs or artifacts for concrete authorization, data exposure, injection, secret, dependency and LLM/tool security risks. Use for a requested security review or a change affecting a trust boundary.
    ---
    
    # Security Review
    
    Load the review method; use Research when dependency/advisory claims need current evidence. Reuse existing fix/testing authority; review alone adds no remediation or live-exploitation authority.
    
    ```mermaid
    flowchart LR
      R[Code Review method] -->|Current dependency / advisory evidence| D[Research]
      click R "../code-review/references/review.md"
      click D "../research/SKILL.md"
    ```
    
    - Trace = sensitive asset + caller/input + required permission → actual enforcing owner → operation/data. UI visibility or a caller's check does not prove server authorization.
    - Coverage = focused change → affected path + adjacent callers; broad review → actual entry points + assets, then relevant surfaces below. Mark material missing evidence.
    
    | Surface | Resolve |
    |---|---|
    | Identity / sessions | Caller-selected identity, role or tenant; login, recovery, expiry + revocation boundaries. |
    | Data / privilege | Actor + tenant enforcement for object, field, list/export + mutation; alternate entry points. |
    | Input / files | Query, markup, URL, path, upload/archive → normalization + downstream parser, fetch, storage or execution. |
    | Secrets / artifacts | Source, logs, client bundle, generated config + packaged output exposure; inspect the actual in-scope artifact. Internal address alone ≠ secret. |
    | LLM / tools | Untrusted content influencing privileged actions; permissions + validated arguments outside the model; required approval at the action boundary. |
    | Dependencies | Resolved lockfile/image/SBOM/runtime version + existing scan + primary advisory ranges. Trace production/build/dev/transitive use; manifest range ≠ resolved version. Confirmed vulnerable version ≠ proven exploitability; unknown reachability never waives a required gate. |
    
    - Finding = entry point + actor/input preconditions + enforcing/missing control + affected asset + realistic impact. Test competing explanations through source + permitted probes; unproven exploit path stays unknown.
    - Secret evidence = type + location + exposure path; mask values. Keep findings, optional hardening + unresolved questions distinct.
    - Authorized fix = smallest control satisfying the requirement; verify original unauthorized path denied + legitimate access preserved at the actual permission/input boundary. Run applicable gates.
    - Result = assessed surfaces + findings + gaps. Scanner success proves only its checked scope; no whole-application certification or implied runtime proof.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related