More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Secure Pull Request Review Gate

    1

    Security-focused PR review that identifies introduced and worsened vulnerabilities, separates pre-existing issues, checks security-test coverage, and returns actionable merge conditions.

    $8

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Secure Pull Request Review Gate

    Secure Pull Request Review Gate

    Example session with this skill installed

    Review this Dockerfile and Node.js snippet for a public-facing API. It handles user uploads to S3. Dockerfile: FROM node:14. COPY . . CMD ["node", "app.js"]. Snippet: s3.putObject({Key: req.file.name, Body: req.file.buffer});

    • Read your context and instructions
    • Compiled the secure pull request
    • Generated the document

    The audit of the provided Dockerfile and S3 upload snippet is complete. The review identified critical configuration weaknesses and a lack of input validation.

    Security Audit Report

    IDFindingSeverityConfidenceLocationRecommendation
    SEC-001Root User ExecutionHighCertainDockerfile: L1-4Use USER node to avoid running the container as root.
    SEC-002Unsafe Base ImageMediumCertainDockerfile: L1Upgrade to node:14-alpine or a newer LTS version to reduce attack surface.
    SEC-003Unvalidated S3 KeyCriticalHighapp.js: L5User-controlled req.file.name allows for path traversal or object overwriting. Sanitize filenames.
    SEC-004Missing Content-TypeLowMediumapp.js: L5Explicitly set ContentType in S3 metadata to prevent MIME-sniffing attacks.

    Gate Decision: BLOCK

    Rationale: The implementation allows unvalidated user input to define S3 object keys (SEC-003), posing a critical risk of data corruption or unauthorized file writes. Additionally, the container runs as root, increasing the impact of any potential RCE.

    NOT_VERIFIED:

    • IAM Policy for S3: The execution role permissions were not provided.
    • Dependency Vulnerabilities: package-lock.json was not supplied.

    Next steps

    1. Implement a filename sanitization function (e.g., using a UUID or hash) for all S3 uploads.
    2. Update the Dockerfile to use a non-privileged user and a minimal base image.
    3. Provide the IAM policy associated with the S3 service for a follow-up review of the "Least Privilege" principle.

    secure-pull-request-review-gate.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Review pull requests for introduced or worsened security vulnerabilities before merge.Return evidence-based PASS, REQUEST_CHANGES, or BLOCK merge decisions.Detect authorization, tenant-isolation, injection, secret, and trust-boundary regressions in changed code.Review Dockerfile, Kubernetes, Terraform, dependency, and CI/CD changes for PR-scoped security risk.Separate introduced and worsened findings from fixed and pre-existing security issues.Assess whether security tests cover the changed invariant and provide safe retest criteria.Review remediation PRs and identify missing rotation, revocation, history, or artifact-cleanup evidence.Produce structured Markdown or schema-conformant JSON reports for CI/CD workflows.

    About this skill

    Secure Pull Request Review Gate reviews pull requests, merge requests, patches, commit ranges, changed files, and base/head comparisons for security regressions before merge.

    AG-3 focuses on what the proposed change introduced, worsened, fixed, or left unchanged. It traces relevant security data and control flows, evaluates authorization and trust boundaries, reviews dependency and CI/CD changes, checks infrastructure and production configuration, and assesses whether security tests cover the changed invariant.

    Every formal review returns one evidence-based decision:

    PASS — no unresolved material change-scoped security issue or merge blocker.

    REQUEST_CHANGES — a correctable Medium issue, material test gap, unsafe ambiguity, incomplete remediation, or conditionally accepted High risk remains.

    BLOCK — a credible Critical/High regression, exposed secret, removed authorization boundary, privileged untrusted-code path, unsafe production exposure, or material blocking evidence gap remains.

    Pre-existing issues stay separate so unrelated repository debt is not incorrectly blamed on the PR author. Findings include stable IDs, severity, confidence, change attribution, exact evidence, impact, prerequisites, remediation, owner suggestion, safe tests, and retest conditions. Optional JSON output supports CI/CD and policy workflows.

    The skill works only with supplied or explicitly available local evidence. It does not access networks, scan live systems, execute untrusted project code, test credentials, invent CVEs, or claim that a repository is fully secure.

    Key capabilities

    Change-focused security review for code, configuration, IaC, dependencies, containers, and CI/CD.

    Base-versus-head attribution: introduced, worsened, pre-existing, fixed, or not verified.

    Security data/control-flow reasoning across directly relevant context.

    Authorization, tenant isolation, injection, secrets, cryptography, data exposure, supply-chain, infrastructure, and availability review.

    Security regression-test assessment without pretending that unexecuted tests passed.

    Evidence-calibrated severity and confidence.

    Stable 48-bit finding fingerprints resilient to line movement, path normalization, Unicode variants, and harmless category formatting.

    Explicit PASS, REQUEST_CHANGES, or BLOCK decision.

    Formal JSON schema and hardened offline validation helper.

    Secret-shape redaction checks and resistance to instructions embedded in reviewed content.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 24 days ago

    • Passed all security checks, Safe to install

    Listed24 days ago
    Updated15 days ago

    What's inside

    Frequently Asked Questions