$npx -y skills add sordi-ai/skill-everything --skill security-reviewApply when performing a security review, checking for vulnerabilities, or implementing authentication and authorization logic.
| 1 | # Sub-Skill: Security Review Depth |
| 2 | <!-- target: tokens_target above. Run `python tools/render_readme_table.py` to update README. --> |
| 3 | |
| 4 | **Purpose:** Deep security rules for authentication, authorization, injection, session management, and API hardening. Complements code-quality rules 20–23 with IDOR, SSRF, and access-control depth. |
| 5 | |
| 6 | --- |
| 7 | |
| 8 | ## Rules |
| 9 | |
| 10 | ### Authentication vs. Authorization |
| 11 | |
| 12 | 1. **AuthN/AuthZ separation.** Always treat authentication (who are you?) and authorization (what can you do?) as distinct checks; never collapse them into a single boolean `is_logged_in` guard. |
| 13 | 2. **Resource ownership check.** Always verify resource ownership in addition to role-based access on mutation endpoints — a valid role does not imply ownership of the target record. Reference: ERR-2026-019 |
| 14 | 3. **IDOR prevention.** Never expose sequential or predictable resource IDs in URLs without a server-side ownership assertion; use opaque UUIDs and always re-fetch the record to confirm the caller owns it. |
| 15 | 4. **Privilege escalation guard.** Never allow a user to elevate their own role or grant permissions they do not already hold; enforce privilege changes through a separate admin-only path. |
| 16 | 5. **Token scope enforcement.** Always validate that the token's declared scope covers the requested operation before executing it; reject tokens with insufficient scope with 403, not 401. |
| 17 | |
| 18 | ### Session Management |
| 19 | |
| 20 | 6. **Session fixation prevention.** Always regenerate the session identifier immediately after a successful login to prevent session fixation attacks. |
| 21 | 7. **Idle and absolute timeouts.** Ensure sessions carry both an idle timeout (e.g., 15 min) and an absolute expiry (e.g., 8 h); never issue non-expiring session tokens. |
| 22 | 8. **Secure cookie attributes.** Always set `HttpOnly`, `Secure`, and `SameSite=Strict` (or `Lax`) on session cookies; never omit any of these three attributes. |
| 23 | 9. **Logout invalidation.** Always invalidate the server-side session record on logout; never rely solely on deleting the client-side cookie. |
| 24 | |
| 25 | ### Injection and Input Handling |
| 26 | |
| 27 | 10. **Parameterized queries everywhere.** Never construct database queries by string concatenation with user-supplied values; always use parameterized statements or an ORM that enforces binding. |
| 28 | 11. **Output encoding context.** Always encode output in the context where it will be rendered (HTML entity encoding for HTML, JSON encoding for JSON responses, URL encoding for query strings); never apply a single generic escape. |
| 29 | 12. **SSRF mitigation.** Before making any server-side HTTP request to a URL derived from user input, validate the resolved IP against an allowlist; block private RFC-1918 ranges and loopback addresses. |
| 30 | 13. **File path traversal.** Never concatenate user input into file system paths; always resolve the canonical path and assert it falls within the expected base directory before opening. |
| 31 | |
| 32 | ### API and Transport Hardening |
| 33 | |
| 34 | 14. **CORS allowlist.** Avoid wildcard `Access-Control-Allow-Origin: *` on endpoints that return authenticated data; always enumerate trusted origins explicitly. |
| 35 | 15. **CSP header.** Ensure every HTML response includes a `Content-Security-Policy` header that restricts `script-src` to known origins; never use `unsafe-inline` without a nonce or hash. |
| 36 | 16. **Rate limiting on auth endpoints.** Always apply rate limiting and exponential back-off to login, password-reset, and OTP endpoints; never expose them without request throttling. |
| 37 | 17. **Sensitive data in logs.** Never log passwords, tokens, full credit-card numbers, or other PII; mask or omit them before writing to any log sink. |
| 38 | |
| 39 | ### Secrets and Dependencies |
| 40 | |
| 41 | 18. **Secret rotation readiness.** Always design secret consumption so that rotating a credential requires only an environment variable update with no code change; never hard-code secrets or embed them in config files committed to version control. |
| 42 | 19. **Dependency CVE scan.** Before merging any PR that adds or upgrades a dependency, run a CVE scan (e.g., `pip-audit`, `npm audit`, `trivy`); block merge if high-severity findings are unresolved. |
| 43 | 20. **Audit logging on sensitive actions.** Always emit a structured audit log entry (actor, action, resource ID, timestamp, outcome) for every privileged or destructive operation; never skip audit logging for admin endpoints. |
| 44 | |
| 45 | --- |
| 46 | |
| 47 | ## See also |
| 48 | |
| 49 | - `skills/code-quality/SKILL.md` — rules 20–23 cover sanitization, parameterized queries, and secret hygiene at a general level; this skill deepens those with IDOR, SSRF, and session specifics. |
| 50 | - `skills/error-log/SKILL.md` — ERR-2026-019 motivated rule 2 (resource ownership check). |
| 51 | |
| 52 | --- |