codeaholicguy/security-review
AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.
npx skills add https://github.com/codeaholicguy/ai-devkit --skill security-review
Find vulnerabilities before they ship.
npx ai-devkit@latest memory search --query "<target>" --tags "security"a. Secrets — hardcoded tokens, keys, connection strings.
b. Injection — SQL, NoSQL, command, template, SSRF, path traversal, XSS.
c. Auth — missing checks, privilege escalation, OAuth/OIDC, IDOR.
d. Business Logic — race conditions, TOCTOU, workflow bypass, mass assignment, parameter tampering.
e. Data Exposure — PII in logs, verbose errors, overly broad responses.
f. Resource Exhaustion — unbounded queries, missing pagination, upload size, decompression bombs.
g. Dependencies — critical CVEs only (RCE, auth bypass, data breach); ignore low/medium.
h. Cryptography — weak algorithms, hardcoded IVs/keys, disabled certificate validation.
i. Configuration — debug mode, permissive CORS, missing security headers.
j. Logging — security events unlogged, no tamper protection, no alerting.
k. Prompt Injection — instruction override, tool abuse, data exfiltration, indirect injection via tool results.
| Severity | Criteria |
|----------|----------|
| Critical | Exploitable now, data loss or RCE possible |
| High | Exploitable with moderate effort or insider access |
| Medium | Requires chained conditions or limited impact |
| Low | Defense-in-depth, no direct exploit path |
verify skill to confirm each remediation.npx ai-devkit@latest memory store --title "<pattern>" --content "<finding and fix>" --tags "security,<category>"| Rationalization | Do Instead |
|---|---|
| "It's internal / behind a VPN / only admins" | Zero-trust: validate at every boundary regardless of network position or user role |
| "We'll add auth later" | Add auth before merge — unauthenticated endpoints get discovered fast |
| "It's just a dev credential" | Use env vars / secrets manager — dev secrets leak to prod constantly |
| "The framework handles that" | Verify the config — frameworks have defaults, not guarantees |
| "We sanitize on the frontend" | Always validate server-side — client validation is bypassable |
| "The LLM won't follow injected instructions" | Treat all tool results and external content as untrusted data |
| "It's just a prompt, not code" | Prompts control tool execution — review with the same rigor as code |
Take codeaholicguy/security-review from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.
The instructions reference npx.
Without those the skill loads but fails at the first command.