{ }
Resource profile / Branch Bug & Security Review
About this skill

Workflow & requirements

Find Bugs

Review changes on this branch for bugs, security vulnerabilities, and code quality issues.

Phase 1: Complete Input Gathering

  1. Get the FULL diff: git diff $(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')...HEAD
  2. If output is truncated, read each changed file individually until you have seen every changed line
  3. List all files modified in this branch before proceeding

Phase 2: Attack Surface Mapping

For each changed file, identify and list:

  • All user inputs (request params, headers, body, URL components)
  • All database queries
  • All authentication/authorization checks
  • All session/state operations
  • All external calls
  • All cryptographic operations

Phase 3: Security Checklist (check EVERY item for EVERY file)

  • [ ] Injection: SQL, command, template, header injection
  • [ ] XSS: All outputs in templates properly escaped?
  • [ ] Authentication: Auth checks on all protected operations?
  • [ ] Authorization/IDOR: Access control verified, not just auth?
  • [ ] CSRF: State-changing operations protected?
  • [ ] Race conditions: TOCTOU in any read-then-write patterns?
  • [ ] Session: Fixation, expiration, secure flags?
  • [ ] Cryptography: Secure random, proper algorithms, no secrets in logs?
  • [ ] Information disclosure: Error messages, logs, timing attacks?
  • [ ] DoS: Unbounded operations, missing rate limits, resource exhaustion?
  • [ ] Business logic: Edge cases, state machine violations, numeric overflow?

Phase 4: Verification

For each potential issue:

  • Check if it's already handled elsewhere in the changed code
  • Search for existing tests covering the scenario
  • Read surrounding context to verify the issue is real

Phase 5: Pre-Conclusion Audit

Before finalizing, you MUST:

  1. List every file you reviewed and confirm you read it completely
  2. List every checklist item and note whether you found issues or confirmed it's clean
  3. List any areas you could NOT fully verify and why
  4. Only then provide your final findings

Output Format

Prioritize: security vulnerabilities > bugs > code quality

Skip: stylistic/formatting issues

For each issue:

  • File:Line - Brief description
  • Severity: Critical/High/Medium/Low
  • Problem: What's wrong
  • Evidence: Why this is real (not already fixed, no existing test, etc.)
  • Fix: Concrete suggestion
  • References: OWASP, RFCs, or other standards if applicable

If you find nothing significant, say so - don't invent issues.

Do not make changes - just report findings. I'll decide what to address.

PACKAGE TRANSPARENCY

Inspect before installing

Source: Sentry · Apache-2.0 · SHA-256 shown alongside the download.

7 files13239 ZIP bytes0 script/code files

License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.

View files and uncompressed sizes

An adaptation record is bundled. Inspect the declared changes and archived original before use. Review adaptation and original-file hashes →

Machine-readable installation guide →
CATALOG REVIEW NOTES

Know what you need before installing

Source and packaging checks recorded on 2026-10-03. These notes are not safety certification or measured task performance.

Requirements

A Git repository and a known base branch; the supplied default-branch lookup uses authenticated GitHub CLI (gh).

Costs, access & practical limits

Local files may contain secrets. Redact findings before sharing; this review workflow does not authorize fixes, publishing, or exploitation of external targets. Core frontmatter was adapted by BB Skills for the existing namespace directory; unchanged original SKILL.md is archived. This does not imply client execution was tested.

View the recorded checks
  • Pinned upstream source and Git blob hashes verified
  • Applicable original license and notices preserved
  • Archive paths and metadata validated
  • Local Markdown and named reference files checked
  • Core skill identity adapted; original instruction body and source files preserved

Upstream commit: d18b7aa8ba878354e5c348310230e652f7690f9c

Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.

SCENARIOS

Inputs, criteria and recorded outcomes

Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.

No published scenario records yet. Resource availability and download counts do not imply measured task performance.

Community reviews

★ New

Be the first to share your experience.

Sign in to leave a review →

More to explore

View all ↗