security-review

โดย mastra-ai

Security-focused code review checklist for identifying vulnerabilities

npx skills add https://github.com/mastra-ai/template-github-review-agent --skill security-review

Security Review

When reviewing code for security issues, check each category below. Reference the detailed checklist in references/security-checklist.md.

Injection Vulnerabilities

  • SQL injection: Look for string concatenation in database queries
  • Command injection: Check for unsanitized input passed to shell commands (exec, spawn)
  • XSS: Look for unsanitized user input rendered in HTML/templates
  • Path traversal: Check for user input in file paths without sanitization

Authentication & Authorization

  • Verify authentication checks on protected routes/endpoints
  • Ensure authorization checks match the required access level
  • Look for privilege escalation paths (e.g., user can modify other users' data)
  • Check that password/token comparison uses constant-time comparison

Secrets & Credentials

  • Hardcoded API keys, passwords, tokens, or connection strings
  • Secrets in configuration files that might be committed
  • Sensitive data in logs or error messages
  • Credentials passed via URL query parameters

Input Validation

  • Validate and sanitize all external input (user input, API responses, file contents)
  • Check for missing or weak input validation on API endpoints
  • Verify type coercion doesn't bypass validation
  • Look for overly permissive CORS or CSP configurations

Data Exposure

  • Sensitive data returned in API responses unnecessarily
  • PII or secrets in application logs
  • Information leakage in error messages (stack traces, internal paths)
  • Missing data encryption for sensitive fields

Severity Levels

  • 🔴 CRITICAL: Exploitable vulnerability (injection, auth bypass, exposed secrets)
  • 🟠 HIGH: Potential vulnerability that needs investigation
  • 🟡 MEDIUM: Security weakness or missing best practice
  • 🔵 LOW: Minor security improvement suggestion

Skills เพิ่มเติมจาก mastra-ai

testing-mastracode-tui
mastra-ai
ทดสอบฟีเจอร์ TUI ของ mastracode แบบโต้ตอบใน Konsole ครอบคลุมการกำหนดค่าโมเดล วงจรชีวิตของเธรด การแยกสถานะของงาน และอุปสรรคทั่วไป
official
mastra-smoke-test
mastra-ai
ทดสอบโปรเจกต์ Mastra แบบ Smoke ทดสอบในเครื่องหรือ deploy ไปยัง staging/production ทดสอบ Studio UI, agents, tools, workflows, traces, memory และอื่นๆ รองรับทั้ง local…
official
security-review
mastra-ai
รายการตรวจสอบโค้ดที่เน้นความปลอดภัยสำหรับระบุช่องโหว่
official
technical-writing
mastra-ai
แนวทางสำหรับการสร้างเอกสารทางเทคนิคที่ชัดเจนและมีโครงสร้างที่ดี
official
code-standards
mastra-ai
มาตรฐานคุณภาพโค้ดและแนวทางรูปแบบสำหรับการตรวจสอบ pull requests
official
debugging-difficult-bugs
mastra-ai
ใช้แต่เนิ่นๆ เมื่อดีบักบั๊กระดับกลางหรือยาก โดยเฉพาะเมื่อการทดสอบเพียงอย่างเดียวอาจไม่เผยให้เห็นความล้มเหลวรันไทม์จริง เรียกใช้ก่อนการวนซ้ำ TDD แบบขยายเวลา…
official
e2e-frontend-validation
mastra-ai
เวิร์กโฟลว์การตรวจสอบ E2E สำหรับการเปลี่ยนแปลงฟรอนต์เอนด์ในแพ็กเกจ playground โดยใช้ Playwright MCP
official
e2e-tests-studio
mastra-ai
จำเป็นเมื่อแก้ไขไฟล์ใดๆ ใน packages/playground-ui หรือ packages/playground 触发เมื่อ: การสร้าง/แก้ไข/ปรับโครงสร้าง React component, การเปลี่ยนแปลง UI,…
official