security-review

Identify and remediate security vulnerabilities across authentication, input handling, secrets, and API endpoints.

2|Updated Jan 21, 2026
One-click install
npx skills add https://github.com/anton-dovnar/cursor --skill security-review-anton-dovnar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/anton-dovnar/cursor/tree/main/skills/security-review
Command: npx skills add https://github.com/anton-dovnar/cursor --skill security-review-anton-dovnar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps teams prevent security vulnerabilities by providing a structured, comprehensive checklist and patterns for authentication, input handling, secrets management, API security, and sensitive feature implementations.

Core Features & Use Cases

  • Comprehensive security checklist and patterns covering secrets management, input validation, authentication and authorization, data handling, rate limiting, and secure coding practices.
  • Useful for reviewing new features, API endpoints, or payment-related flows to ensure vulnerabilities are mitigated before deployment.
  • Example: Evaluate a new API endpoint to ensure proper token handling, secrets usage, and input validation.

Quick Start

Perform a security review on the new feature by validating secrets, authentication, authorization, input handling, and API security.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security review on a new API endpoint?

Perform a security review on a new API endpoint by validating token handling, secrets usage, input validation, authentication, authorization, and rate limiting. This skill provides a comprehensive vulnerability checklist covering those areas to ensure proper mitigation before deployment.

What security vulnerabilities should I check for when handling sensitive data in a web app?

When handling sensitive data, check for vulnerabilities in secrets management, input validation, authentication, authorization, data handling, rate limiting, and safe logging. This skill provides a structured checklist and secure coding patterns to identify and remediate these specific issues across web apps and services.

How do I ensure proper secrets management and input validation before deploying a new feature?

Ensure proper secrets management and input validation before deployment by applying the comprehensive security checklist and secure defaults provided by this skill. It includes specific verification steps for secrets handling and input validation to mitigate vulnerabilities in new feature development.

Can I use this security checklist to review payment-related flows and authentication?

Yes, you can use this security checklist to review payment-related flows and authentication. It is specifically designed to evaluate sensitive feature implementations, applying secure coding practices, vulnerability checks, and verification steps to ensure payment and authentication mechanisms are properly secured.

What is the best way to enforce secure coding practices across authentication and API endpoints?

The best way to enforce secure coding practices across authentication and API endpoints is to apply a structured vulnerability checklist with secure defaults. This skill provides comprehensive patterns for authentication, token handling, and API security to remediate vulnerabilities across web apps and services.

Do I need any specific dependencies or components to run a secure coding review?

No specific dependencies or components are required to run a secure coding review using this skill. It operates independently, providing a comprehensive vulnerability checklist, secure defaults, and verification steps for secrets, input validation, authentication, authorization, rate limiting, and safe logging without external requirements.