security-review (affaan-m/ecc)

Helps developers implement secure features by listing concrete checks and recommended patterns for authentication, input handling, secret management, API endpoints, and payment or sensitive flows. Unlike similarly named tools that scan code or produce vulnerability audits, this one focuses on design-time guidance and implementation checklists — it does not run automated SAST, assign severity scores, or perform penetration-style audits of diffs.

A situation it fits

I'm about to design a new login + payment flow and want a clear, practical list of secure patterns, do/avoid rules, and concrete checks I should follow as I build the feature so we don't bake in mistakes. I don't want someone to comb the whole repo for every weakness, produce a full cross-system compliance report, or only review a single outstanding change.
security-review (affaan-m/ecc). Winner: security-review-affaan-m gives the practical, design-time guidance this person needs — concrete patterns and checks for authentication, input handling, secret management, endpoints and sensitive flows to follow while writing the feature. What it does that the others do not is focus on implementation guidance up front rather than producing vulnerability scan results, a prioritized compliance audit, or a narrow review of a pending change. Most tempting wrong answer: security-review-getsentry — it finds and labels code-level problems, so it looks useful, but its output is about surfacing and scoring findings from existing source code rather than giving the developer a checklist of patterns and design-time rules to follow. (Other traps: security-reviewer-jeffallan would overdeliver a prioritized, compliance-style audit across code, infra and deps — useful but the wrong scope and heavier than needed; security-review-waybarrios only examines the specific unmerged change and focuses on high-confidence exploit paths, so it won't provide the broad, feature-level implementation guidance the author wants.)

Skills it gets confused with

These share a family with security-review (affaan-m/ecc), which is another way of saying they are the ones you might reach for by mistake.

Knowing what security-review (affaan-m/ecc) does is the easy half. Telling it apart from the others under time pressure is the game.

Today's session

security-review (affaan-m/ecc) is part of affaan-m/ecc. Licence: MIT. The description above was written for this game, not taken from the skill.

← All skills