BUNDLE Security scanned4 skills

    Complete Developer Pack

    A complete developer quality workflow covering code review, automated test generation, security auditing, and pre-merge checks. Use it to inspect implementation quality, uncover edge cases and security risks, generate targeted tests, and evaluate pull requests before merging. Each workflow is evidence-based and clearly separates verified results from items that still need testing or verification.

    Works with every agent that reads SKILL.md — Claude Code, Cursor, Codex CLI, Gemini CLI, GitHub Copilot, Windsurf, OpenClaw, and more.

    Iosif Bârsan
    Created by
    Iosif Bârsan
    $24.99$33.97
    Save 26% · $8.98

    One payment, lifetime access. 4 skills unlock instantly in your library.

    30-day refund guarantee

    Instant unlock in your library

    Free updates from the creator

    What's included

    4 skills

    See it in action

    Code Sentinel

    Example session with this skill installed

    Review this Python snippet for a new API endpoint:

    def get_user(request):
        user_id = request.GET.get('id')
        user = db.execute("SELECT * FROM users WHERE id = " + user_id)
        return user
    
    • Read your context and instructions
    • Compiled the code sentinel

    I have completed a static review of the provided Python snippet. The analysis identified a critical security vulnerability regarding SQL injection and a potential runtime crash.

    Review Summary

    The code lacks input validation and uses unsafe string concatenation for database queries. This exposes the application to unauthorized data access.

    Findings

    IDSeverityConfidenceLocationFinding
    CR-01CriticalHighdb.execute(...)SQL Injection vulnerability via unsanitized input.
    CR-02HighHighrequest.GET.get('id')Potential NoneType error if 'id' parameter is missing.
    CR-03LowMediumSELECT *Inefficient data retrieval; fetches unnecessary columns.

    CR-01: SQL Injection

    • Evidence: The code directly concatenates user_id from the request into the SQL string.
    • Impact: An attacker can pass 1 OR 1=1 to dump the entire users table or 1; DROP TABLE users to delete data.
    • Fix: Use parameterized queries.
    
    # Fix
    user = db.execute("SELECT * FROM users WHERE id = %s", (user_id,))
    

    CR-02: Missing Input Validation

    • Evidence: request.GET.get('id') returns None if the key is missing. The subsequent concatenation will fail.
    • Impact: The application will throw a TypeError and return a 500 status code to the user.
    • Fix: Add a check for the existence of user_id.
    
    # Fix
    user_id = request.GET.get('id')
    if not user_id:
        return "Missing ID", 400
    

    Recommended Verification

    1. Attempt to access the endpoint without an id parameter to confirm 400 error handling.
    2. Test the endpoint with a non-numeric string to ensure the database driver handles type mismatches in parameterized queries.

    Next steps

    • Replace all string-concatenated queries in the module with the parameterized pattern shown in CR-01.
    • Implement a global middleware or utility function for standardizing API error responses.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every skill in this bundle passes our trust checks.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Frequently asked questions

    More bundles from Iosif Bârsan