security-review

Identify and remediate security vulnerabilities in software projects.

Updated Jan 30, 2026
One-click install
npx skills add https://github.com/CobaltSato/avalanche-build-games-tool-kit --skill security-review-cobaltsato
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/CobaltSato/avalanche-build-games-tool-kit/tree/main/.claude/skills/security-review
Command: npx skills add https://github.com/CobaltSato/avalanche-build-games-tool-kit --skill security-review-cobaltsato

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps teams ensure code correctness and resilience by enforcing security best practices and early vulnerability detection across projects.

Core Features & Use Cases

  • Comprehensive security checklist and patterns for authentication, input validation, secrets management, API endpoints, and payments.
  • Threat modeling, secure configuration guidance, and best practices for secure development.
  • Use cases include integrating authentication, validating user input, managing secrets, designing secure API endpoints, implementing payment flows, and ensuring secure data handling.

Quick Start

Run a security review on your new modules using the checklist to validate authentication, input handling, secrets management, API endpoints, and payment workflows.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify security vulnerabilities in my API endpoints and authentication flows?

Security review processes identify vulnerabilities by applying a structured checklist to validate authentication, input handling, and API endpoint configurations across web apps and serverless functions. This enforces early threat detection and secure development best practices.

What is the best way to manage secrets and validate user input in web applications?

The best way to manage secrets and validate user input is to enforce secure configuration guidance and structured validation patterns. Applying a comprehensive security checklist ensures proper secret rotation and robust data handling across your application workflows.

How do I perform threat modeling and secure configuration for serverless functions?

Threat modeling for serverless functions involves assessing data handling and API endpoints against proven security patterns. Structured validation and secure configuration guidance ensure code correctness and resilience across your deployment.

Does this security review approach work for payment flows and sensitive data handling?

Yes, this security review approach works for payment flows and sensitive data handling by validating transaction workflows against strict security checklists. It ensures proper error handling and secure configuration to protect critical payment infrastructure.

When do I need a structured security checklist for my software project?

You need a structured security checklist when integrating authentication, designing secure API endpoints, or implementing payment flows. It provides threat modeling and secure configuration guidance to ensure early vulnerability detection and code resilience.

How do I remediate security flaws found during code review?

To remediate security flaws found during code review, apply secure development best practices for proper error handling and secret rotation. The security checklist provides validation patterns to correct vulnerabilities across authentication and API endpoints.