SKILL ISSUE

Security Review (affaan-m) vs What Leaked About You (useosint)

Security Review (affaan-m) and What Leaked About You (useosint) are both Security skills, so an agent choosing between them is matching on descriptions that overlap. Here is where they actually diverge.

Security Review

affaan-m/ecc

Helps developers implement secure features by listing concrete checks and recommended patterns for authentication, input handling, secret management, API endpoints, and payment or sensitive flows. Unlike similarly named tools that scan code or produce vulnerability audits, this one focuses on design-time guidance and implementation checklists — it does not run automated SAST, assign severity scores, or perform penetration-style audits of diffs.

1 scenario in the bank answer to it

What Leaked About You

useosint

Checks an email, username, phone, or name against curated data-breach services — Have I Been Pwned, DeHashed, IntelX and the like — to enumerate which breaches an identity appears in and read what those records reveal, chiefly the list of services the person actually used. It is breach-exposure reconnaissance about a person, not a codebase tool: it does not scan your repository for hardcoded secrets, and it never uses a leaked password to access anything — reading the exposure is the whole job.

2 scenarios in the bank answer to it

What is the difference between Security Review (affaan-m) and What Leaked About You (useosint)?

Security Review (affaan-m)
Helps developers implement secure features by listing concrete checks and recommended patterns for authentication, input handling, secret management, API endpoints, and payment or sensitive flows. Unlike similarly named tools that scan code or produce vulnerability audits, this one focuses on design-time guidance and implementation checklists — it does not run automated SAST, assign severity scores, or perform penetration-style audits of diffs.
What Leaked About You (useosint)
Checks an email, username, phone, or name against curated data-breach services — Have I Been Pwned, DeHashed, IntelX and the like — to enumerate which breaches an identity appears in and read what those records reveal, chiefly the list of services the person actually used. It is breach-exposure reconnaissance about a person, not a codebase tool: it does not scan your repository for hardcoded secrets, and it never uses a leaked password to access anything — reading the exposure is the whole job.

Should I use Security Review (affaan-m) or What Leaked About You?

The clearest answer is a situation each one is unambiguously right for. Both of these are drawn from the game's question bank.

Reach for Security Review (affaan-m) when

I'm about to design a new login + payment flow and want a clear, practical list of secure patterns, do/avoid rules, and concrete checks I should follow as I build the feature so we don't bake in mistakes. I don't want someone to comb the whole repo for every weakness, produce a full cross-system compliance report, or only review a single outstanding change.

Winner: security-review-affaan-m gives the practical, design-time guidance this person needs — concrete patterns and checks for authentication, input handling, secret management, endpoints and sensitive flows to follow while writing the feature. What it does that the others do not is focus on implementation guidance up front rather than producing vulnerability scan results, a prioritized compliance audit, or a narrow review of a pending change. Most tempting wrong answer: security-review-getsentry — it finds and labels code-level problems, so it looks useful, but its output is about surfacing and scoring findings from existing source code rather than giving the developer a checklist of patterns and design-time rules to follow. (Other traps: security-reviewer-jeffallan would overdeliver a prioritized, compliance-style audit across code, infra and deps — useful but the wrong scope and heavier than needed; security-review-waybarrios only examines the specific unmerged change and focuses on high-confidence exploit paths, so it won't provide the broad, feature-level implementation guidance the author wants.)

Reach for What Leaked About You when

While cleaning out a dusty server closet, you spot a sticky note with your 2014 gaming alias. You dive into dump trawlers to see which tiny subscription box sites and forgotten hobby forums once held that string, purely to build a hit list, never to touch a password field.

This skill performs targeted reconnaissance on a single individual’s historical data exposure, querying compiled leak indexes to discover which external services originally stored a given identifier, without attempting to exploit or access anything. It wins here because your scenario explicitly describes trawling dumps to catalogue which small third-party businesses once held your old tag, which maps exactly to that exposure-readout mission, whereas the other options focus on writing code scanners, patching dependencies, or sanitizing server error output.

What they have in common

Both are filed under Security, the axis along which they collide. That shared ground is what makes an agent pick between them on description alone — and what makes it pick wrong.

Nearby comparisons

Reading the difference is not the same as spotting it at speed. That is the game.

Today's session