Code Sentinel

    1

    Disciplined code auditing for bugs, security risks, and performance issues with severity-ranked fixes.

    $6.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Code Sentinel

    Example session with this skill installed

    Review this Python snippet for a new API endpoint:

    def get_user(request):
        user_id = request.GET.get('id')
        user = db.execute("SELECT * FROM users WHERE id = " + user_id)
        return user
    
    • Read your context and instructions
    • Compiled the code sentinel

    I have completed a static review of the provided Python snippet. The analysis identified a critical security vulnerability regarding SQL injection and a potential runtime crash.

    Review Summary

    The code lacks input validation and uses unsafe string concatenation for database queries. This exposes the application to unauthorized data access.

    Findings

    IDSeverityConfidenceLocationFinding
    CR-01CriticalHighdb.execute(...)SQL Injection vulnerability via unsanitized input.
    CR-02HighHighrequest.GET.get('id')Potential NoneType error if 'id' parameter is missing.
    CR-03LowMediumSELECT *Inefficient data retrieval; fetches unnecessary columns.

    CR-01: SQL Injection

    • Evidence: The code directly concatenates user_id from the request into the SQL string.
    • Impact: An attacker can pass 1 OR 1=1 to dump the entire users table or 1; DROP TABLE users to delete data.
    • Fix: Use parameterized queries.
    
    # Fix
    user = db.execute("SELECT * FROM users WHERE id = %s", (user_id,))
    

    CR-02: Missing Input Validation

    • Evidence: request.GET.get('id') returns None if the key is missing. The subsequent concatenation will fail.
    • Impact: The application will throw a TypeError and return a 500 status code to the user.
    • Fix: Add a check for the existence of user_id.
    
    # Fix
    user_id = request.GET.get('id')
    if not user_id:
        return "Missing ID", 400
    

    Recommended Verification

    1. Attempt to access the endpoint without an id parameter to confirm 400 error handling.
    2. Test the endpoint with a non-numeric string to ensure the database driver handles type mismatches in parameterized queries.

    Next steps

    • Replace all string-concatenated queries in the module with the parameterized pattern shown in CR-01.
    • Implement a global middleware or utility function for standardizing API error responses.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Audit pull requests for logic flaws and security vulnerabilities before merge.Identify O(n^2) performance bottlenecks in new backend endpoints.Locate hardcoded secrets and unsafe string concatenations in legacy code.Standardize code style and maintainability across team repositories.

    About this skill

    Manual code reviews are slow and often miss edge cases under pressure. This skill provides a disciplined, first-pass static analysis to identify correctness bugs, security risks, and performance bottlenecks before they hit production.

    What it does

    • Severity-ranked auditing classifies issues from Critical to Suggestion so you know what to fix first.
    • Evidence-based findings link every reported issue to specific code locations with concrete impact analysis.
    • Logic and security vetting checks for race conditions, data integrity, and common vulnerabilities without inventing false positives.
    • Actionable remediation provides specific code fixes for every identified problem.

    How it works

    1. Analyze scope by ingesting your provided source code, diffs, or pull request content.
    2. Scan categories including correctness, security, error handling, performance, and maintainability.
    3. Generate findings structured in a standardized table with confidence ratings.
    4. Detail fixes for each issue, providing the "why" behind the recommendation.

    Frameworks & tools

    This skill works with any programming language or framework including JavaScript, Python, Go, Rust, and Java. It integrates with existing shell or git tools if available to verify file paths and diff context.

    Why this beats prompting it yourself

    Generic prompts often result in vague "make it cleaner" advice or hallucinated line numbers. This skill enforces a structured severity-based framework that prevents the agent from inventing files or vulnerabilities while ensuring high-impact bugs are never buried in style suggestions.

    Use cases

    • Pull request audits to catch logic flaws before merging into the main branch.
    • Security pre-screening to find hardcoded secrets or unsafe data handling.
    • Performance tuning to identify O(n^2) operations or memory leaks in new features.
    • Legacy refactoring to assess technical debt in inherited codebases.

    Known limitations

    Does not perform runtime execution or dynamic analysis unless external test tools are explicitly provided. Requires provided code context to be accurate.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 8 days ago

    • Passed all security checks, Safe to install

    Listed8 days ago

    What's inside

    Frequently Asked Questions