{ }
Resource profile / Evidence-Based Security Code Review
About this skill

Workflow & requirements

Security Review Skill

Identify exploitable security vulnerabilities in code. Report only HIGH CONFIDENCE findings—clear vulnerable patterns with attacker-controlled input.

Scope: Research vs. Reporting

CRITICAL DISTINCTION:

  • Report on: Only the specific file, diff, or code provided by the user
  • Research: The ENTIRE codebase to build confidence before reporting

Before flagging any issue, you MUST research the codebase to understand: - Where does this input actually come from? (Trace data flow) - Is there validation/sanitization elsewhere? - How is this configured? (Check settings, config files, middleware) - What framework protections exist?

Do NOT report issues based solely on pattern matching. Investigate first, then report only what you're confident is exploitable.

Confidence Levels

Level Criteria Action
HIGH Vulnerable pattern + attacker-controlled input confirmed Report with severity
MEDIUM Vulnerable pattern, input source unclear Note as "Needs verification"
LOW Theoretical, best practice, defense-in-depth Do not report

Do Not Flag

General Rules

  • Test files (unless explicitly reviewing test security)
  • Dead code, commented code, documentation strings
  • Patterns using constants or server-controlled configuration
  • Code paths that require prior authentication to reach (note the auth requirement instead)

Server-Controlled Values (NOT Attacker-Controlled)

These are configured by operators, not controlled by attackers:

Source Example Why It's Safe
Django settings settings.API_URL, settings.ALLOWED_HOSTS Set via config/env at deployment
Environment variables os.environ.get('DATABASE_URL') Deployment configuration
Config files config.yaml, app.config['KEY'] Server-side files
Framework constants django.conf.settings.* Not user-modifiable
Hardcoded values BASE_URL = "https://api.internal" Compile-time constants

SSRF Example - NOT a vulnerability:

# SAFE: URL comes from Django settings (server-controlled)
response = requests.get(f"{settings.SEER_AUTOFIX_URL}{path}")

SSRF Example - IS a vulnerability:

# VULNERABLE: URL comes from request (attacker-controlled)
response = requests.get(request.GET.get('url'))

Framework-Mitigated Patterns

Check language guides before flagging. Common false positives:

Pattern Why It's Usually Safe
Django {{ variable }} Auto-escaped by default
React {variable} Auto-escaped by default
Vue {{ variable }} Auto-escaped by default
User.objects.filter(id=input) ORM parameterizes queries
cursor.execute("...%s", (input,)) Parameterized query
innerHTML = "<b>Loading...</b>" Constant string, no user input

Only flag these when: - Django: {{ var|safe }}, {% autoescape off %}, mark_safe(user_input) - React: dangerouslySetInnerHTML={{__html: userInput}} - Vue: v-html="userInput" - ORM: .raw(), .extra(), RawSQL() with string interpolation

Review Process

1. Detect Context

What type of code am I reviewing?

Code Type Load These References
API endpoints, routes authorization.md, authentication.md, injection.md
Frontend, templates xss.md, csrf.md
File handling, uploads file-security.md
Crypto, secrets, tokens cryptography.md, data-protection.md
Data serialization deserialization.md
External requests ssrf.md
Business workflows business-logic.md
GraphQL, REST design api-security.md
Config, headers, CORS misconfiguration.md
CI/CD, dependencies supply-chain.md
Error handling error-handling.md
Audit, logging logging.md

2. Load Language Guide

Based on file extension or imports:

Indicators Guide
.py, django, flask, fastapi languages/python.md
.js, .ts, express, react, vue, next languages/javascript.md
.go, go.mod languages/go.md
.rs, Cargo.toml languages/rust.md
.java, spring, @Controller languages/java.md

3. Load Infrastructure Guide (if applicable)

File Type Guide
Dockerfile, .dockerignore infrastructure/docker.md
K8s manifests, Helm charts infrastructure/kubernetes.md
.tf, Terraform infrastructure/terraform.md
GitHub Actions, .gitlab-ci.yml infrastructure/ci-cd.md
AWS/GCP/Azure configs, IAM infrastructure/cloud.md

4. Research Before Flagging

For each potential issue, research the codebase to build confidence:

  • Where does this value actually come from? Trace the data flow.
  • Is it configured at deployment (settings, env vars) or from user input?
  • Is there validation, sanitization, or allowlisting elsewhere?
  • What framework protections apply?

Only report issues where you have HIGH confidence after understanding the broader context.

5. Verify Exploitability

For each potential finding, confirm:

Is the input attacker-controlled?

Attacker-Controlled (Investigate) Server-Controlled (Usually Safe)
request.GET, request.POST, request.args settings.X, app.config['X']
request.json, request.data, request.body os.environ.get('X')
request.headers (most headers) Hardcoded constants
request.cookies (unsigned) Internal service URLs from config
URL path segments: /users/<id>/ Database content from admin/system
File uploads (content and names) Signed session data
Database content from other users Framework settings
WebSocket messages

Does the framework mitigate this? - Check language guide for auto-escaping, parameterization - Check for middleware/decorators that sanitize

Is there validation upstream? - Input validation before this code - Sanitization libraries (DOMPurify, bleach, etc.)

6. Report HIGH Confidence Only

Skip theoretical issues. Report only what you've confirmed is exploitable after research.


Severity Classification

Severity Impact Examples
Critical Direct exploit, severe impact, no auth required RCE, SQL injection to data, auth bypass, hardcoded secrets
High Exploitable with conditions, significant impact Stored XSS, SSRF to metadata, IDOR to sensitive data
Medium Specific conditions required, moderate impact Reflected XSS, CSRF on state-changing actions, path traversal
Low Defense-in-depth, minimal direct impact Missing headers, verbose errors, weak algorithms in non-critical context

Quick Patterns Reference

Always Flag (Critical)

eval(user_input)           # Any language
exec(user_input)           # Any language
pickle.loads(user_data)    # Python
yaml.load(user_data)       # Python (not safe_load)
unserialize($user_data)    # PHP
deserialize(user_data)     # Java ObjectInputStream
shell=True + user_input    # Python subprocess
child_process.exec(user)   # Node.js

Always Flag (High)

innerHTML = userInput              # DOM XSS
dangerouslySetInnerHTML={user}     # React XSS
v-html="userInput"                 # Vue XSS
f"SELECT * FROM x WHERE {user}"    # SQL injection
`SELECT * FROM x WHERE ${user}`    # SQL injection
os.system(f"cmd {user_input}")     # Command injection

Always Flag (Secrets)

password = "hardcoded"
api_key = "sk-..."
AWS_SECRET_ACCESS_KEY = "..."
private_key = "-----BEGIN"

Check Context First (MUST Investigate Before Flagging)

# SSRF - ONLY if URL is from user input, NOT from settings/config
requests.get(request.GET['url'])     # FLAG: User-controlled URL
requests.get(settings.API_URL)       # SAFE: Server-controlled config
requests.get(f"{settings.BASE}/{x}") # CHECK: Is 'x' user input?

# Path traversal - ONLY if path is from user input
open(request.GET['file'])            # FLAG: User-controlled path
open(settings.LOG_PATH)              # SAFE: Server-controlled config
open(f"{BASE_DIR}/{filename}")       # CHECK: Is 'filename' user input?

# Open redirect - ONLY if URL is from user input
redirect(request.GET['next'])        # FLAG: User-controlled redirect
redirect(settings.LOGIN_URL)         # SAFE: Server-controlled config

# Weak crypto - ONLY if used for security purposes
hashlib.md5(file_content)            # SAFE: File checksums, caching
hashlib.md5(password)                # FLAG: Password hashing
random.random()                      # SAFE: Non-security uses (UI, sampling)
random.random() for token            # FLAG: Security tokens need secrets module

Output Format

## Security Review: [File/Component Name]

### Summary
- **Findings**: X (Y Critical, Z High, ...)
- **Risk Level**: Critical/High/Medium/Low
- **Confidence**: High/Mixed

### Findings

#### [VULN-001] [Vulnerability Type] (Severity)
- **Location**: `file.py:123`
- **Confidence**: High
- **Issue**: [What the vulnerability is]
- **Impact**: [What an attacker could do]
- **Evidence**:
  ```python
  [Vulnerable code snippet]
  ```
- **Fix**: [How to remediate]

### Needs Verification

#### [VERIFY-001] [Potential Issue]
- **Location**: `file.py:456`
- **Question**: [What needs to be verified]

If no vulnerabilities found, state: "No high-confidence vulnerabilities identified."


Reference Files

Core Vulnerabilities (references/)

File Covers
injection.md SQL, NoSQL, OS command, LDAP, template injection
xss.md Reflected, stored, DOM-based XSS
authorization.md Authorization, IDOR, privilege escalation
authentication.md Sessions, credentials, password storage
cryptography.md Algorithms, key management, randomness
deserialization.md Pickle, YAML, Java, PHP deserialization
file-security.md Path traversal, uploads, XXE
ssrf.md Server-side request forgery
csrf.md Cross-site request forgery
data-protection.md Secrets exposure, PII, logging
api-security.md REST, GraphQL, mass assignment
business-logic.md Race conditions, workflow bypass
modern-threats.md Prototype pollution, LLM injection, WebSocket
misconfiguration.md Headers, CORS, debug mode, defaults
error-handling.md Fail-open, information disclosure
supply-chain.md Dependencies, build security
logging.md Audit failures, log injection

Language Guides (languages/)

  • python.md - Django, Flask, FastAPI patterns
  • javascript.md - Node, Express, React, Vue, Next.js
  • go.md - Go-specific security patterns
  • rust.md - Rust unsafe blocks, FFI security
  • java.md - Spring, Java EE patterns

Infrastructure (infrastructure/)

  • docker.md - Container security
  • kubernetes.md - K8s RBAC, secrets, policies
  • terraform.md - IaC security
  • ci-cd.md - Pipeline security
  • cloud.md - AWS/GCP/Azure security
PACKAGE TRANSPARENCY

Inspect before installing

Source: Sentry · Apache-2.0 AND CC-BY-SA-4.0 · SHA-256 shown alongside the download.

28 files98159 ZIP bytes0 script/code files

License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.

View files and uncompressed sizes

An adaptation record is bundled. Inspect the declared changes and archived original before use. Review adaptation and original-file hashes →

Machine-readable installation guide →
CATALOG REVIEW NOTES

Know what you need before installing

Source and packaging checks recorded on 2026-10-03. These notes are not safety certification or measured task performance.

Requirements

A repository or diff you are authorized to inspect; project-wide context and a client able to read/search files. No scanner binary is included.

Costs, access & practical limits

Do not execute exploit payloads or scan external systems. Findings require manual verification. Keep secrets out of reports. This resource is not a security certification; preserve file-specific license and attribution conditions. Core frontmatter was adapted by BB Skills for the existing namespace directory; unchanged original SKILL.md is archived. This does not imply client execution was tested.

View the recorded checks
  • Pinned source and Git blob hashes verified
  • Repository and skill-level license notices retained
  • Attribution, unchanged-file declaration and source links included
  • Archive paths, metadata and local references verified
  • Core skill identity adapted; original instruction body and source files preserved

Upstream commit: d18b7aa8ba878354e5c348310230e652f7690f9c

Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.

LICENSE & ATTRIBUTION

Different files carry different terms

This bundle preserves more than one upstream license. The labels do not mean that every file is offered under either license at your choice. Read the original notices before adapting or redistributing it.

Apache-2.0 ↗

Repository-level license preserved from Sentry. Read the skill-level notice as well; this does not replace its terms.

Attribution: Sentry contributors, as identified in the original repository license.

Changes: BB Skills adapted core frontmatter on 2026-10-03: namespaced name and, where overlong, shortened description. Original SKILL.md retained separately; instruction body, scripts, references and license texts unchanged. Header YAML formatting normalized.

Included notice: getsentry-security-review/upstream-notices/LICENSE

Declared source ↗

CC-BY-SA-4.0 ↗

OWASP-derived reference material identified by the original skill-level LICENSE.

Attribution: OWASP Foundation and the OWASP Cheat Sheet Series; Sentry maintains this skill. Retain the original notices and source links.

Changes: Original upstream files are unchanged; catalog source and review metadata were added.

Included notice: getsentry-security-review/LICENSE

Declared source ↗

For the CC BY-SA material, retain attribution and license links, indicate changes, and apply the required ShareAlike terms to adaptations. These notices do not imply endorsement by the original creators.

SCENARIOS

Inputs, criteria and recorded outcomes

Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.

No published scenario records yet. Resource availability and download counts do not imply measured task performance.

Community reviews

★ New

Be the first to share your experience.

Sign in to leave a review →

More to explore

View all ↗