← Back to list

securityreview
by mgreenly
An AI Coding Agent
⭐ 1🍴 0📅 Jan 24, 2026
SKILL.md
name: security/review description: Security Code Review security skill
Security Code Review
Systematic checklist for reviewing C code for security vulnerabilities.
Review Checklist
Memory:
- All array accesses bounds-checked
- Integer overflow checked before allocation/indexing
- No use-after-free potential
- Strings null-terminated after operations
Input:
- All external input validated at trust boundary
- Path inputs canonicalized and checked
- No user data in format strings
- Lengths validated before use
Functions:
- No banned functions (strcpy, sprintf, gets, etc.)
- Buffer sizes passed to all string operations
- Return values checked
Secrets:
- No credentials in logs or error messages
- Config file permissions verified
- Secrets scrubbed from memory when done
Files:
- No TOCTOU races (access then open)
- Symlinks handled safely (O_NOFOLLOW)
- Temp files use mkstemp
Grep for red flags:
grep -rn 'strcpy\|sprintf\|gets\|strcat\|mktemp' src/
grep -rn 'printf.*%s.*user\|system(\|popen(' src/
Score
Total Score
60/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
✓LICENSE
ライセンスが設定されている
+10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
Reviews
💬
Reviews coming soon