Agent skill
security_audit
Checklist for security-sensitive coding, ensuring MaiHouses guards and policies are respected.
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/security-audit-cityfish91159-maihouses-35e7d064-2
SKILL.md
Security Audit Protocol
1. Critical "Guard" Files
WARNING: The following files are OFF-LIMITS for modification without explicit user approval.
scripts/ai-diff-gate.ts.github/workflows/**- Any file with
midlaworpolicyin the name.
2. Database Security (Supabase)
- RLS (Row Level Security):
- EVERY table must have RLS enabled.
- Policies must explicitly define
USINGandWITH CHECKclauses. - NEVER use
service_rolekey in frontend client code.
- SQL Injection:
- Use parameterized queries or ORM methods (Supabase JS client) only.
- Avoid raw SQL string concatenation.
3. API Security
- Authentication:
- Verify
userexists inreq(usually populated by middleware/auth helper). - Check permissions before performing actions (e.g.
checkPermission(user.id, 'post.create')).
- Verify
- Input Validation:
- Validate ALL inputs using
zodschemas. - Sanitize HTML inputs if rendering user content (use
DOMPurify).
- Validate ALL inputs using
4. Audit Checklist
- Are guards/policies untouched?
- Is RLS enabled and tested?
- Is input validation (
zod) in place? - Are no secrets committed to code?
- Did I run
/security-review(if available) or manual check?
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?