gtrabanco/agentic-workflow

review-security

Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry.

Ver código-fonte
Documento original do Skill

Renderizado do repositório de origem, preservando títulos, exemplos, código, tabelas, links e imagens.

Review Security (internal)

Composed by review-change / product-audit within their conversation — on any agent, follow this file inline as the routed step. Findings only; never edits, never refactors.

Scope

The diff or path/glob the caller passes; default the current change vs the default branch. State the scope at the top of the returned table.

Checklist (evaluate EVERY item — none is optional; n/a must be stated)

✓ No secrets/credentials/tokens in code, config, tests, or fixtures (grep the diff for key-like strings) ✓ Every external input on the changed paths is validated/sanitized before use ✓ No injection vectors (SQL/command/path/template) — parameterized/escaped, never concatenated ✓ AuthN/AuthZ enforced on every new/changed endpoint or entry point (cite where) ✓ No PII or secrets written to logs/error messages on the changed paths ✓ Webhooks/callbacks verify signatures before processing ✓ Rate limiting / abuse controls considered where a new public surface appears (n/a if none) ✓ New/updated dependencies pinned and free of known-critical advisories (state how you checked) ✓ Error responses don't leak stack traces or internal paths ✓ Unsafe deserialization / dynamic evaluation of untrusted data absent

Materiality bar

Report a row only when a competent user's outcome changes or a rule the project explicitly declares is violated — cite the rule it violates beside the evidence. Not findings: comment/punctuation typos, formatting-only drift, style preference with no cited rule, hypothetical robustness beyond the SPEC's named scenarios. An empty table with Decision: PASS is the expected result for a well-formed change — never pad the table.

Return exactly

REVIEW SECURITY — scope: <scope>

| # | Finding | Sev | Evidence | Suggested fix |
|---|---------|-----|----------|---------------|
| 1 | <what>  | critical|major|minor | <file:line> | <smallest action> |

Checklist: <n> evaluated, <n> pass, <n> findings, <n> n/a (<which + why>)
Summary: <1-2 sentences>
Decision: PASS | FAIL

FAIL if any critical or major finding is open; PASS otherwise. Minor findings never block — they route to the caller's triage step.

Done when

  • Every checklist item was evaluated with evidence (file:line or command output)

or explicitly marked n/a with the reason.

  • The fixed-format block above is returned — nothing more, nothing less — and

no code was changed.

do mesmo repositório

Mais Skills

Todos os Skills
gtrabanco
Comunidade

review-code

Internal correctness + simplification review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks correctness, error handling, duplication, dead code, and simplification opportunities against the project's own conventions. Findings only; never edits code.

instalações
1
GitHub Stars
21
Atualizado
9 de set.
gtrabanco
Comunidade

review-plan

Independent read-only review of a frozen Engineering plan before execution, in a context that did not cut it: feature or fix snapshot, obligation ledger sweep, phase and validator checks. Returns only PLAN-REVIEW-PASS or PLAN-REVIEW-FAIL with a snapshot-bound receipt (a product-intent gap is PLAN-REVIEW-FAIL with class: product). Never edits a plan artifact. Triggers: "review-plan", "review the plan", "review the phases".

instalações
1
GitHub Stars
21
Atualizado
9 de set.
gtrabanco
Comunidade

review-seo

Internal SEO review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks changed web pages/routes for indexability, metadata, and structured data — applies only to public web surfaces. Findings only; never edits code.

instalações
1
GitHub Stars
21
Atualizado
9 de set.
gtrabanco
Comunidade

review-spec

Independent read-only review of a frozen Product half before engineering planning. Runs the exact Product checks in a clean context and returns only SPEC-REVIEW-PASS, SPEC-REVIEW-FAIL, or NEEDS-DESIGN with a content-bound receipt. Never edits the reviewed SPEC. Triggers: "review-spec", "review the spec", "review product design".

instalações
1
GitHub Stars
21
Atualizado
9 de set.