← Back to list

security-lens
by malston
⭐ 1🍴 0📅 Jan 24, 2026
SKILL.md
name: security-lens description: Apply security awareness during code review and implementation. Catches common vulnerabilities without requiring full security audit. allowed-tools:
- Read
- Grep
- Glob
Security Awareness Lens
When reviewing or writing code, check for:
Input Handling
- User input validated before use
- SQL uses parameterized queries (never string concat)
- HTML output escaped to prevent XSS
- File paths validated (no path traversal)
Authentication/Authorization
- Auth checks at controller level, not just UI
- Sensitive operations re-verify permissions
- Session tokens are httpOnly, secure, sameSite
Data Exposure
- Logs don't contain secrets, tokens, PII
- Error messages don't leak internal details
- API responses don't include unnecessary fields
Secrets
- No hardcoded credentials
- Secrets from environment/vault, not config files
- .gitignore covers .env, credentials
See @owasp-quick-ref.md for detailed vulnerability patterns.
Score
Total Score
50/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
○LICENSE
ライセンスが設定されている
0/10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
Reviews
💬
Reviews coming soon