security-review

작성자: langfuse

Langfuse의 보안 검토 패턴입니다. 코드 리뷰, 설계 또는 계획 중 사용자 제공 URL, 호스트/엔드포인트/baseURL 필드 등을 수용하는 변경 사항이 있을 때 사용하세요.

npx skills add https://github.com/langfuse/langfuse --skill security-review

Security Review

Use this skill when reviewing or planning code that touches a security-sensitive surface in Langfuse. It collects the recurring findings the team has seen in external security reports so that future agents catch them at design and review time rather than after the fact.

When to Apply

Apply this skill when the change touches any of:

  • a user-supplied URL, host, endpoint, baseURL, or webhook target
  • a new outbound HTTP request (fetch, axios, AWS SDK client init with a custom endpoint, OpenAI/Anthropic/Bedrock client init with a custom baseURL, etc.)
  • a new integration form under Settings -> Integrations or any admin-configurable network destination
  • a new tRPC procedure or public API route that mutates project-scoped data or changes who can access it
  • secrets, API keys, signing secrets, or encryption-at-rest fields
  • redirect-following or cross-origin header handling
  • file uploads, image proxies, or other binary data flowing in or out
  • product analytics, browser monitoring, session replay, or another client-side telemetry path that can transmit customer-controlled content

Apply this skill during plan mode when designing a new integration so the correct validation surfaces land in the plan, not in a follow-up CVE.

How to Read This Skill

  1. Open references/checklist.md and run the mental sweep against the change.
  2. For each bullet that fires, open the matching topic reference.
TopicOpen whenFile
SSRF and outbound URL validationThe change accepts or fetches a user-supplied URL, host, or endpointreferences/outbound-url-validation.md
Secret read pathsThe change shapes what a read route returns for an entity or config blob that also stores a credentialreferences/secret-read-paths.md
Client telemetry and session replayThe change records DOM, browser state, events, logs, or network data in a third-party systemreferences/client-telemetry-privacy.md

The catalog is intentionally short today. New topic files are added as new finding classes recur (see "Extending This Skill").

Output Expectations (Review Mode)

When this skill is used during code review:

  • List findings first, ordered by severity, with file and line references.
  • For each finding, name the canonical helper or known-good call site the author should copy.
  • For SSRF-class findings, point at references/outbound-url-validation.md rather than re-deriving the fix.
  • Call out missing negative tests (private-IP, cross-tenant, missing-scope) as findings, not as nice-to-haves.

Output Expectations (Design / Plan Mode)

When this skill is used while planning:

  • Restate which surfaces the new feature exposes (forms, public API routes, worker entrypoints).
  • For each surface that matches a checklist trigger, name the validator or helper that must be invoked and at which layer (save-time, use-time, connection-time, redirect-time).
  • Treat "we will validate later" as a design defect: validation belongs in the same change that introduces the surface.

Extending This Skill

Add a new references/<topic>.md whenever a security finding recurs across features or PR reviews. Keep each reference narrow and concrete:

  1. Threat in plain language (one paragraph).
  2. Canonical helpers in this repo, with paths.
  3. Known-good call sites that can be copied.
  4. Required defenses (save-time, use-time, transport-time, etc.).
  5. Anti-patterns to flag in review.

Then add a one-line trigger to references/checklist.md pointing at the new topic file, and add a row to the table above.

Candidates for future references (do not add until a real finding recurs):

  • Tenant isolation (projectId filters across Prisma and ClickHouse)
  • Redirect mishandling and sensitive-header propagation
  • File upload validation and content-type sniffing
  • RBAC scope drift on new tRPC/public API endpoints
  • Signed URL scoping (expiry, path, method)
  • Public API rate limiting and auth boundary checks

Integration With Other Skills

  • The shared code-review skill should defer here for any change that matches the triggers above; see code-review/SKILL.md.
  • The shared backend-dev-guidelines skill should defer here when adding outbound HTTP, integration config, or URL-accepting procedures; see backend-dev-guidelines/SKILL.md.
  • Confirmed issues with reproduction evidence go through linear-bug-triage for Linear handoff.

langfuse의 다른 스킬

frontend-browser-review
langfuse
이 스킬은 변경 사항이 브라우저에서 사용자가 보거나 수행하는 작업에 영향을 미칠 때 사용하세요.
frontend-large-feature-architecture
langfuse
대규모 Langfuse 프론트엔드 기능, 가상화된 목록, 대형 테이블, 컨트롤러 컴포넌트, 로컬 기능을 구축, 변경 또는 리팩터링할 때 사용합니다.
skill-developer
langfuse
Anthropic 모범 사례에 따라 Claude Code 스킬을 생성하고 관리합니다. 새 스킬을 만들거나, skill-rules.json을 수정하거나, 트리거를 이해할 때 사용합니다…
langfuse-prompt-migration
langfuse
하드코딩된 프롬프트를 Langfuse로 마이그레이션하여 버전 관리와 배포 없는 반복을 가능하게 합니다. 사용자가 프롬프트를 외부화하거나, 프롬프트를 Langfuse로 이동하려는 경우 사용합니다.
incident-alert-tickets
langfuse
Read and, after human approval, update the Linear `incident-alert` knowledge base. Use before and after investigating a named Datadog monitor,…
refactor-react-effects
langfuse
Langfuse 프론트엔드 코드에서 피할 수 있는 React useEffect 사용을 리팩터링합니다. 효과를 추가, 검토 또는 제거할 때; 폼이나 로컬 UI 상태를 초기화할 때 사용합니다…
sentry-instrumentation
langfuse
Decide whether and how errors report to Sentry. Use when touching capture or error-handling paths in `web/**`, triaging Sentry noise, or changing Sentry…
posthog-instrumentation
langfuse
Product analytics with posthog. Use when adding a meaningful user action or feature in `web/**`, touching PostHog capture code, or answering product-usage…