Files
open-claw-team/.openclaw/workspace/skills/security-review/SKILL.md
T

2.5 KiB

name, description
name description
security-review Security audit for code — scan for vulnerabilities, hardcoded secrets, input validation issues, injection risks, auth misconfigurations. Use when reviewing code, before merge, or on request.

Security Review Skill

Based on ECC AgentShield patterns + OWASP Top 10.

When to Use

  • Before merging any code
  • Code review step
  • User explicitly requests security scan
  • Adding auth or handling sensitive data

Scan Checklist

1. Secrets Detection

  • Hardcoded API keys, passwords, tokens, connection strings
  • .env files committed (check .gitignore)
  • AWS credentials, JWT secrets, OAuth client secrets
  • Search patterns: password\s*=\s*["'], api_key\s*=\s*["'], secret\s*=\s*["']

2. Input Validation

  • ALL user input validated before use
  • No raw string concatenation for SQL
  • HTML output escaped (XSS prevention)
  • File path traversal prevention
  • File upload type and size validation

3. Authentication & Authorization

  • Protected endpoints require auth
  • Role-based access control enforced server-side
  • JWT tokens validated (expiration, signature)
  • Session security (HttpOnly, Secure, SameSite)
  • No privilege escalation paths

4. Data Protection

  • Sensitive data encrypted at rest
  • TLS in transit
  • PII not logged
  • Password hashing (bcrypt, argon2 — NOT md5, sha1)

5. Infrastructure

  • HTTPS enforced
  • CORS configured (not wildcard)
  • Rate limiting on public endpoints
  • Security headers (CSP, HSTS, X-Frame-Options)
  • Dependencies scanned for CVEs

Execution

# Quick scan for secrets
grep -rn --include='*.py' --include='*.ts' --include='*.js' --include='*.go' \
  -E '(password|secret|api_key|token)\s*=\s*["\x27][^$\{]' app/ tests/

# Check .gitignore
cat .gitignore | grep -E '\.env|credentials|secrets'

# Check dependencies for CVEs
npm audit        # Node.js
pip audit         # Python
go list -m all -json | nancy check  # Go

# Check for common injection patterns
grep -rn 'exec\(|eval\(|system(' app/
grep -rn 'SELECT.*' + app/   # SQL concatenation
grep -rn 'innerHTML\s*=' app/   # XSS

Report Format

## Security Review: [Project/Task]
**Overall Risk**: Low / Medium / High / Critical

### Critical (must fix before deploy):
1. [Issue] at [file:line] — [recommendation]

### High (should fix):
1. [Issue] — [recommendation]

### Medium (recommended):
1. [Issue] — [recommendation]

### Verified Safe:
- [List: input validation, auth enforcement, no hardcoded secrets, etc.]

### Dependencies:
- Vulnerabilities found: X (Critical: Y, High: Z)