security-review

द्वारा mastra-ai

सुरक्षा-केंद्रित कोड समीक्षा जाँचसूची जो कमजोरियों की पहचान करने के लिए है

npx skills add https://github.com/mastra-ai/template-github-review-agent --skill security-review

Security Review

When reviewing code for security issues, check each category below. Reference the detailed checklist in references/security-checklist.md.

Injection Vulnerabilities

  • SQL injection: Look for string concatenation in database queries
  • Command injection: Check for unsanitized input passed to shell commands (exec, spawn)
  • XSS: Look for unsanitized user input rendered in HTML/templates
  • Path traversal: Check for user input in file paths without sanitization

Authentication & Authorization

  • Verify authentication checks on protected routes/endpoints
  • Ensure authorization checks match the required access level
  • Look for privilege escalation paths (e.g., user can modify other users' data)
  • Check that password/token comparison uses constant-time comparison

Secrets & Credentials

  • Hardcoded API keys, passwords, tokens, or connection strings
  • Secrets in configuration files that might be committed
  • Sensitive data in logs or error messages
  • Credentials passed via URL query parameters

Input Validation

  • Validate and sanitize all external input (user input, API responses, file contents)
  • Check for missing or weak input validation on API endpoints
  • Verify type coercion doesn't bypass validation
  • Look for overly permissive CORS or CSP configurations

Data Exposure

  • Sensitive data returned in API responses unnecessarily
  • PII or secrets in application logs
  • Information leakage in error messages (stack traces, internal paths)
  • Missing data encryption for sensitive fields

Severity Levels

  • 🔴 CRITICAL: Exploitable vulnerability (injection, auth bypass, exposed secrets)
  • 🟠 HIGH: Potential vulnerability that needs investigation
  • 🟡 MEDIUM: Security weakness or missing best practice
  • 🔵 LOW: Minor security improvement suggestion

mastra-ai की और Skills

e2e-frontend-validation
mastra-ai
प्ले Playwright MCP का उपयोग करके प्लेग्राउंड पैकेजों में फ्रंटएंड बदलावों के लिए E2E सत्यापन वर्कफ़्लो
code-standards
mastra-ai
कोड गुणवत्ता मानक और पुल रिक्वेस्ट की समीक्षा के लिए शैली मार्गदर्शिका
general-tasks
mastra-ai
खुली-समाप्ति वाले कार्यों को संभालने की डिफ़ॉल्ट प्रक्रिया जो फ़ाइलों, शेल या वेब से संबंधित हैं।
gh-bulk-issues
mastra-ai
समानांतर Mastra Code हेडलेस इंस्टेंस को व्यवस्थित करके एक साथ कई GitHub मुद्दों को डीबग और ठीक करें
create-mastra
mastra-ai
Mastra AI फ्रेमवर्क के लिए पूर्ण प्रोजेक्ट सेटअप गाइड। इसमें शामिल: CLI इंस्टॉलेशन (create-mastra), मैन्युअल इंस्टॉलेशन, TypeScript कॉन्फ़िगरेशन (ES2022…
understand-issue
mastra-ai
सहयोगात्मक रूप से GitHub मुद्दे या बग की जाँच करें — इतिहास का पता लगाएँ, आर्किटेक्चर समझें, मूल कारण का निदान करें
performance-review
mastra-ai
प्रदर्शन-केंद्रित कोड समीक्षा जो बाधाओं और अनुकूलन अवसरों की पहचान करने के लिए होती है
research-tasks
mastra-ai
वेब का उपयोग करके शोध प्रश्नों के उत्तर देने और निष्कर्षों को वर्कस्पेस में सहेजने की प्रक्रिया।