/drupal-security-review
Use when auditing Drupal 11 custom modules/themes for security issues such as unsafe input handling, XSS risks, SQL injection, and access control gaps.
$ npx -y skills add siva01c/claude-plugins --skill drupal-security-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/drupal-security-review
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use when auditing Drupal 11 custom modules/themes for security issues such as unsafe input handling, XSS risks, SQL injection, and access control gaps.
SKILL.md
drupal-security-review.SKILL.mdname: drupal-security-review description: Use when auditing Drupal 11 custom modules/themes for security issues such as unsafe input handling, XSS risks, SQL injection, and access control gaps.
Drupal Security Review Skill
Purpose
Use this skill to perform focused security reviews for Drupal 11 custom modules and themes.
When to apply
- Reviewing pull requests before merge.
- Auditing custom code for common web vulnerabilities.
- Preparing release readiness checks.
Review checklist
1. **Input handling**: Validate and sanitize all external input. 2. **Output escaping**: Escape output in Twig and PHP render logic. 3. **Database safety**: Use query builder or placeholders in all SQL operations. 4. **Access control**: Confirm route, entity, and operation permissions are enforced. 5. **Secrets and config**: Ensure credentials are never committed and sensitive config is protected.
Common anti-patterns to flag
- Direct SQL string concatenation with user data.
- Unescaped raw markup in render arrays.
- Trusting `$_GET`, `$_POST`, or request payloads without validation.
- Debug leftovers (`var_dump`, `kint`, `dpm`) in production paths.
Useful validation commands
rg "(var_dump|dpm\(|kint\()" web/modules/custom web/themes/custom rg "\$_(GET|POST|REQUEST)" web/modules/custom web/themes/custom
A curated collection of Claude Code plugins for Drupal development, security, and deployment. Each plugin covers one topic — Drupal itself, DDEV, Docker, CI/CD, git workflows, and security verification — so you install only what you need.
Other skills on claude-plugins.
- /github-actions
Use this skill when authoring or debugging GitHub Actions workflows (.github/workflows/*.yml) — e.g. "add CI for this Drupal project on GitHub", "run phpcs/phpstan/phpunit on pull requests", "cache composer dependencies", "deploy over SSH when main is pushed", "why didn't my
Open skill - /gitlab-ci
Use this skill when authoring or debugging GitLab CI/CD pipelines (.gitlab-ci.yml) — e.g. "add a CI pipeline for this Drupal project", "run phpcs/phpstan/phpunit in GitLab CI", "deploy with drush from a pipeline", "why is my job not running", "cache composer dependencies", or
Open skill - /drupal-ddev-operations
Use for operational Drupal 11 workflows in DDEV environments, including safe updates, backup-first procedures, and troubleshooting commands.
Open skill - /docker-compose
Use this skill when authoring or editing Docker Compose files (compose.yaml / docker-compose.yml), running multi-container stacks, or containerizing a Drupal/PHP application — e.g. "set up a local Drupal stack with nginx and MariaDB", "add Redis to my compose file", "why won't
Open skill - /docker-model
Use this skill when running local AI models with Docker Model Runner — the `docker model` CLI — e.g. "run an LLM locally with Docker", "pull a model from the ai/ namespace", "connect my app to a local model", "use a local model as backend for the Drupal AI module", or when
Open skill - /drupal-module-development
Use when creating or extending Drupal 11 custom modules, including scaffolding, service architecture, and dependency injection best practices.
Open skill

