Skip to content
Back to skills

Security Review

ASecurity

Application security checklist: auth and session, authorisation and Firestore rules, input validation, secrets, PII exposure, dependencies, infra and CI. Apply during any security review.

  • 8 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentsgoflaskgitapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 19, 2026

npx -y skills add Adilmunawar/ZD-claude-plugin --skill security-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/adilmunawar-security-review/badge)](https://www.skillsdirectory.com/skills/adilmunawar-security-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-review
description: Application security checklist: auth and session, authorisation and Firestore rules, input validation, secrets, PII exposure, dependencies, infra and CI. Apply during any security review.
---

Authentication and session
- Firebase Auth required on all cadastral collections; token refresh handled; sign-out on real 401 only. Expo tokens in secure store, session horizon enforced, device lock on.
- .NET: JWT lifetime and refresh rotation; password hashing (ASP.NET Identity or Argon2/bcrypt); OTP rate limits and expiry; lockout after repeated failures.

Authorisation
- Firestore rules: default deny; per-user paths owner-only; shared collections validated on write; no `allow read: if true`.
- API: object-level checks (a farmer sees only their applications/land); admin routes behind roles; no IDOR on numeric ids.

Input validation
- API routes and Flask endpoints validate body/shape/size; geometry vertex caps; file uploads: type, size, filename sanitised, stored outside the web root; zip-bomb protection on parcel zips.

Secrets and config
- `/zd-core:secrets-audit` clean; server secrets not `NEXT_PUBLIC_`; Space/App Hosting/Vercel secrets set; service-account key rotated after any exposure; least-privilege IAM (Earth Engine read/export only).

Data exposure
- CNIC masked by default; logs never contain response bodies, tokens or PII; error responses without stack traces; Storage URLs not guessable or signed with expiry.

Dependencies
- `npm audit --omit=dev`, `pip-audit`, `dotnet list package --vulnerable`; pin major versions; Dependabot enabled.

Infrastructure and CI
- HTTPS only with the correct certificate chain (custom CA pinned in the app if used); CORS restricted; branch protection on `main` (PR + CI + review); GitHub secret scanning and push protection on; Actions pinned to versions.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…