スキル一覧に戻る
mgreenly

securityreview

by mgreenly

An AI Coding Agent

1🍴 0📅 2026年1月24日
GitHubで見るManusで実行

SKILL.md


name: security/review description: Security Code Review security skill

Security Code Review

Systematic checklist for reviewing C code for security vulnerabilities.

Review Checklist

Memory:

  • All array accesses bounds-checked
  • Integer overflow checked before allocation/indexing
  • No use-after-free potential
  • Strings null-terminated after operations

Input:

  • All external input validated at trust boundary
  • Path inputs canonicalized and checked
  • No user data in format strings
  • Lengths validated before use

Functions:

  • No banned functions (strcpy, sprintf, gets, etc.)
  • Buffer sizes passed to all string operations
  • Return values checked

Secrets:

  • No credentials in logs or error messages
  • Config file permissions verified
  • Secrets scrubbed from memory when done

Files:

  • No TOCTOU races (access then open)
  • Symlinks handled safely (O_NOFOLLOW)
  • Temp files use mkstemp

Grep for red flags:

grep -rn 'strcpy\|sprintf\|gets\|strcat\|mktemp' src/
grep -rn 'printf.*%s.*user\|system(\|popen(' src/

スコア

総合スコア

60/100

リポジトリの品質指標に基づく評価

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新がある

0/10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

0/5

レビュー

💬

レビュー機能は近日公開予定です