security-review

Assess security risks in web application authentication, input handling, and API endpoints.

Updated Nov 21, 2025
One-click install
npx skills add https://github.com/MBarry01/dousell-immo --skill security-review-mbarry01
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/MBarry01/dousell-immo/tree/main/.claude/skills/security-review
Command: npx skills add https://github.com/MBarry01/dousell-immo --skill security-review-mbarry01

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Assess and mitigate security risks across your software delivery lifecycle, ensuring robust safeguards are in place.

Core Features & Use Cases

  • Guided security checks: Authentication, input handling, secrets management, API design, and payment flow security.
  • Best-practice patterns: Reusable guardrails and checklists to implement secure defaults.
  • Use Case: A software team reviews a new API endpoint and its authentication flow to ensure least privilege and secret handling compliance.

Quick Start

Run a structured security review of a new feature by applying the provided checklist to your authentication, input handling, and secrets management processes.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security review on web application authentication and API endpoints?

To perform a security review, you apply a structured checklist to your authentication, API endpoints, and secrets management processes, verifying risk patterns and enforcing secure defaults to ensure least privilege compliance.

What is the best way to check for secrets management and input validation risks in production code?

The best way to check for secrets management and input validation risks is by applying systematic security checks with best-practice patterns that verify risk controls and enforce auditable safeguards across your software delivery lifecycle.

How does a structured security checklist help mitigate risks in payment flows?

A structured security checklist mitigates risks in payment flows by providing reusable guardrails and structured guidance that enforce secure defaults, verify risk patterns, and ensure robust safeguards are in place for sensitive transactions.

Can I use this security review process to enforce least privilege on a new API endpoint?

Yes, you can use this security review process to enforce least privilege on a new API endpoint by applying the provided authentication and secrets management checklists to verify compliance and implement auditable controls.

When do I need to run a systematic security check on my web application?

You need to run a systematic security check when reviewing new features, API endpoints, or authentication flows to ensure input handling, secrets management, and payment processing comply with best-practice security patterns.

What are the limitations of using a checklist for API security and risk management?

The limitation of using a checklist for API security is that it provides structured guidance and best-practice patterns, but teams must still manually verify risk patterns and implement the secure defaults and auditable controls specific to their architecture.