security-review

Review GymBro iOS and Azure changes for security vulnerabilities and compliance.

Updated Apr 6, 2026
One-click install
npx skills add https://github.com/jperezdelreal/GymBro --skill security-review-jperezdelreal
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/jperezdelreal/GymBro/tree/main/.squad/skills/shared/security-review
Command: npx skills add https://github.com/jperezdelreal/GymBro --skill security-review-jperezdelreal

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security reviews identify vulnerabilities, misconfigurations, and policy gaps across the GymBro iOS client and Azure backend, helping protect HealthKit data, credentials, and API surfaces.

Core Features & Use Cases

  • Trigger points include new API endpoints, authentication changes, data handling updates, and new cloud resources.
  • Provides a security-review framework with checklists, remediation guidance, severity scoring, and coverage for both on-device and backend surfaces.
  • Use cases include pre-release audits, post-deployment validation, dependency-security reviews, and incident response follow-ups.

Quick Start

Perform a security review of GymBro's iOS client and Azure backend and generate a remediation plan.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security review for an iOS client and Azure backend?

To perform a security review, audit authentication changes, API endpoints, and cloud resources across the iOS client and Azure backend. This process identifies vulnerabilities and ensures compliance with TLS enforcement, JWT validation, and HealthKit data protection best practices.

What does a security audit cover for HealthKit data and prompt injection?

A security audit covers HealthKit data protection and prompt injection mitigation by evaluating data handling updates and API surfaces. It identifies policy gaps and applies severity scoring to prevent data exfiltration across on-device and backend environments.

When do I need to run a security review on API endpoints and cloud infrastructure?

You need to run a security review when trigger points occur, such as provisioning new cloud resources, adding API endpoints, or updating dependencies. It is also applicable for pre-release audits, post-deployment validation, and incident response follow-ups.

Can I use a security review framework for JWT validation and TLS enforcement?

Yes, the security review framework includes checklists and remediation guidance specifically for JWT validation and TLS enforcement. It evaluates configuration security and generates a remediation plan to satisfy compliance requirements.

Does the security audit generate remediation plans with severity levels?

Yes, the security audit generates a remediation plan that includes severity scoring and actionable guidance. It evaluates vulnerabilities across iOS and Azure surfaces to prevent data exfiltration and secure cloud configurations.

What is the best way to prevent data exfiltration during authentication changes?

The best way to prevent data exfiltration during authentication changes is to apply a security review framework with specific trigger points. This audits JWT validation, identifies vulnerabilities, and ensures secure configuration across the Azure backend.