security-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited security-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Any task involving user identity, data protection, payments, file handling, or credential management. When in doubt: load this skill.
security-reviewer.md persona.Apply these patterns by default — do not wait to be asked:
Authentication
crypto.randomBytes(32).Authorisation
Input handling
Content-Type header alone.Secrets
Run the OWASP checklist from security-reviewer.md against your own diff. Write findings to .planning/phases/phase-N/SECURITY-REVIEW-N.md.
== instead of a constant-time functionnone algorithmeval(), exec(), or shell commandsBefore marking a task done when this skill was active:
I remembered off the top of my head?
has that file been written to the correct path?
Do not silently fix it and move on. For every vulnerability found:
SECURITY-REVIEW-N.md immediately.Tell the user. Do not proceed with ANY other work until acknowledged.
SECURITY-REVIEW-N.md. Finish the current task.Flag at the end of the SUMMARY.md.
SECURITY-REVIEW-N.md. Note in SUMMARY.md.The worst security outcome is a vulnerability that was found, noted mentally, and then forgotten when context rolled over. Write it down. Always.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.