security-review
The first pass of every review. These are the highest-impact, most-missed classes. Map to OWASP Top 10; for a deep audit escalate to the `security-auditor` agent and the `owasp-top10` skill.
$ npx -y skills add vanara-agents/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
The first pass of every review. These are the highest-impact, most-missed classes. Map to OWASP Top 10; for a deep audit escalate to the `security-auditor` agent and the `owasp-top10` skill.
Agent definition
security-review.mdSecurity Review
The first pass of every review. These are the highest-impact, most-missed classes. Map to OWASP Top 10; for a deep audit escalate to the `security-auditor` agent and the `owasp-top10` skill.
Injection
User input must never be interpreted as code/query syntax.
// BAD — SQL injection
db.query(`SELECT * FROM orders WHERE status = '${req.query.status}'`);
// GOOD — parameterized
db.query('SELECT * FROM orders WHERE status = $1', [req.query.status]);- SQL: bind parameters; never string-concatenate. For dynamic columns (sort/filter), **whitelist**
the allowed set — you can't parameterize an identifier.
- Command: avoid shelling out with user input; if unavoidable, pass an argv array, never a shell
string.
- Template/XSS: escape output by default; treat any HTML built from input as suspect.
Broken authorization (IDOR)
The most common real vuln in CRUD apps. Authentication ≠ authorization.
// BAD — authenticated, but ownership never checked
const doc = await db.docs.findById(req.params.id);
// GOOD — verify the caller owns the resource
const doc = await db.docs.findById(req.params.id);
if (!doc || doc.ownerId !== req.session.userId) return res.status(404).end();
- Check ownership/role on **every** action that reads or mutates a specific resource.
- Prefer 404 over 403 for resources the caller may not even know exist (avoid leaking existence).
- Don't trust IDs, roles, or prices sent from the client — re-derive server-side.
Secrets
- No hardcoded keys, tokens, passwords, or connection strings — even in tests or comments.
- Pull from environment variables or a secret manager; validate presence at startup.
- If a secret is found in a diff, flag CRITICAL and instruct rotation — committed secrets are
compromised even if later removed (git history).
Unsafe deserialization
- Never deserialize untrusted data with executable formats: Python `pickle`, `yaml.load` (use
`safe_load`), Java native serialization, PHP `unserialize` on user input.
- Prefer JSON with a schema validator at the boundary.
Other high-value checks
- **SSRF:** outbound requests to user-supplied URLs must be allow-listed; block internal IP ranges
and metadata endpoints (`169.254.169.254`).
- **Path traversal:** normalize and confine file paths to a base directory; reject `..` segments.
- **Crypto:** constant-time comparison for tokens (`crypto.timingSafeEqual`); strong, salted hashing
(argon2/bcrypt/scrypt) for passwords; never MD5/SHA1 for secrets.
- **Rate limiting:** state-changing and auth endpoints should be rate-limited (return 429).
- **Error leakage:** no stack traces or internal details in client-facing error responses.
Read more
Security Review
The first pass of every review. These are the highest-impact, most-missed classes. Map to OWASP Top 10; for a deep audit escalate to the `security-auditor` agent and the `owasp-top10` skill.
Injection
User input must never be interpreted as code/query syntax.
// BAD — SQL injection
db.query(`SELECT * FROM orders WHERE status = '${req.query.status}'`);
// GOOD — parameterized
db.query('SELECT * FROM orders WHERE status = $1', [req.query.status]);- SQL: bind parameters; never string-concatenate. For dynamic columns (sort/filter), **whitelist**
the allowed set — you can't parameterize an identifier.
- Command: avoid shelling out with user input; if unavoidable, pass an argv array, never a shell
string.
- Template/XSS: escape output by default; treat any HTML built from input as suspect.
Broken authorization (IDOR)
The most common real vuln in CRUD apps. Authentication ≠ authorization.
// BAD — authenticated, but ownership never checked const doc = await db.docs.findById(req.params.id); // GOOD — verify the caller owns the resource const doc = await db.docs.findById(req.params.id); if (!doc || doc.ownerId !== req.session.userId) return res.status(404).end();
- Check ownership/role on **every** action that reads or mutates a specific resource.
- Prefer 404 over 403 for resources the caller may not even know exist (avoid leaking existence).
- Don't trust IDs, roles, or prices sent from the client — re-derive server-side.
Secrets
- No hardcoded keys, tokens, passwords, or connection strings — even in tests or comments.
- Pull from environment variables or a secret manager; validate presence at startup.
- If a secret is found in a diff, flag CRITICAL and instruct rotation — committed secrets are
compromised even if later removed (git history).
Unsafe deserialization
- Never deserialize untrusted data with executable formats: Python `pickle`, `yaml.load` (use
`safe_load`), Java native serialization, PHP `unserialize` on user input.
- Prefer JSON with a schema validator at the boundary.
Other high-value checks
- **SSRF:** outbound requests to user-supplied URLs must be allow-listed; block internal IP ranges
and metadata endpoints (`169.254.169.254`).
- **Path traversal:** normalize and confine file paths to a base directory; reject `..` segments.
- **Crypto:** constant-time comparison for tokens (`crypto.timingSafeEqual`); strong, salted hashing
(argon2/bcrypt/scrypt) for passwords; never MD5/SHA1 for secrets.
- **Rate limiting:** state-changing and auth endpoints should be rate-limited (return 429).
- **Error leakage:** no stack traces or internal details in client-facing error responses.
🐒 Free agents, skills & packs for Claude Code One subscription. An army of Claude Code agents. 30 production-grade agents, skills, and packs for Claude Code — free, Apache-2.0, install with one command.
Repo: vanara-agents/skills
Other agents on vanara-agents-skills.
- AGENT
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination, filtering, error envelopes, versioning, and idempotency. Produces a reviewable API contract plus an OpenAPI snippet, not
Open agent - review-notes
This shows how the api-designer agent reviews a flawed draft. Findings are severity-ranked so the implementer fixes the contract-breakers first. Severity legend: **CRITICAL** (breaks clients / data risk), **HIGH** (real bug or inconsistency), **MEDIUM** (maintainability),
Open agent - contract-and-openapi
The contract is the deliverable. Express it as an **OpenAPI 3.1** document so it is human-readable *and* machine-checkable. This reference covers how to structure that document and what `scripts/lint-openapi.mjs` enforces.
Open agent - design-checklist
Run through this before declaring an API contract done. It is ordered the way you should *design*: resources first, cross-cutting rules last. Every box is a place real APIs go wrong in production.
Open agent - versioning-and-evolution
APIs are forever once published: a consumer you've never met may depend on any field you expose. Design so you can **add without breaking**, and version explicitly when you must break.
Open agent - pr-comment-template
Copy-paste templates for leaving review comments. Keep each comment to one finding: an anchor, the problem, and the fix.
Open agent

