More screenshots
Works with the AI tools you already use
Secure Pull Request Review Gate
Security-focused PR review that identifies introduced and worsened vulnerabilities, separates pre-existing issues, checks security-test coverage, and returns actionable merge conditions.
$8
Secure Pull Request Review Gate
Example session with this skill installed
Review this Dockerfile and Node.js snippet for a public-facing API. It handles user uploads to S3. Dockerfile: FROM node:14. COPY . . CMD ["node", "app.js"]. Snippet: s3.putObject({Key: req.file.name, Body: req.file.buffer});
- Read your context and instructions
- Compiled the secure pull request
- Generated the document
The audit of the provided Dockerfile and S3 upload snippet is complete. The review identified critical configuration weaknesses and a lack of input validation.
Security Audit Report
| ID | Finding | Severity | Confidence | Location | Recommendation |
|---|---|---|---|---|---|
| SEC-001 | Root User Execution | High | Certain | Dockerfile: L1-4 | Use USER node to avoid running the container as root. |
| SEC-002 | Unsafe Base Image | Medium | Certain | Dockerfile: L1 | Upgrade to node:14-alpine or a newer LTS version to reduce attack surface. |
| SEC-003 | Unvalidated S3 Key | Critical | High | app.js: L5 | User-controlled req.file.name allows for path traversal or object overwriting. Sanitize filenames. |
| SEC-004 | Missing Content-Type | Low | Medium | app.js: L5 | Explicitly set ContentType in S3 metadata to prevent MIME-sniffing attacks. |
Gate Decision: BLOCK
Rationale: The implementation allows unvalidated user input to define S3 object keys (SEC-003), posing a critical risk of data corruption or unauthorized file writes. Additionally, the container runs as root, increasing the impact of any potential RCE.
NOT_VERIFIED:
- IAM Policy for S3: The execution role permissions were not provided.
- Dependency Vulnerabilities:
package-lock.jsonwas not supplied.
Next steps
- Implement a filename sanitization function (e.g., using a UUID or hash) for all S3 uploads.
- Update the Dockerfile to use a non-privileged user and a minimal base image.
- Provide the IAM policy associated with the S3 service for a follow-up review of the "Least Privilege" principle.
secure-pull-request-review-gate.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Secure Pull Request Review Gate reviews pull requests, merge requests, patches, commit ranges, changed files, and base/head comparisons for security regressions before merge.
AG-3 focuses on what the proposed change introduced, worsened, fixed, or left unchanged. It traces relevant security data and control flows, evaluates authorization and trust boundaries, reviews dependency and CI/CD changes, checks infrastructure and production configuration, and assesses whether security tests cover the changed invariant.
Every formal review returns one evidence-based decision:
PASS — no unresolved material change-scoped security issue or merge blocker.
REQUEST_CHANGES — a correctable Medium issue, material test gap, unsafe ambiguity, incomplete remediation, or conditionally accepted High risk remains.
BLOCK — a credible Critical/High regression, exposed secret, removed authorization boundary, privileged untrusted-code path, unsafe production exposure, or material blocking evidence gap remains.
Pre-existing issues stay separate so unrelated repository debt is not incorrectly blamed on the PR author. Findings include stable IDs, severity, confidence, change attribution, exact evidence, impact, prerequisites, remediation, owner suggestion, safe tests, and retest conditions. Optional JSON output supports CI/CD and policy workflows.
The skill works only with supplied or explicitly available local evidence. It does not access networks, scan live systems, execute untrusted project code, test credentials, invent CVEs, or claim that a repository is fully secure.
Key capabilities
Change-focused security review for code, configuration, IaC, dependencies, containers, and CI/CD.
Base-versus-head attribution: introduced, worsened, pre-existing, fixed, or not verified.
Security data/control-flow reasoning across directly relevant context.
Authorization, tenant isolation, injection, secrets, cryptography, data exposure, supply-chain, infrastructure, and availability review.
Security regression-test assessment without pretending that unexecuted tests passed.
Evidence-calibrated severity and confidence.
Stable 48-bit finding fingerprints resilient to line movement, path normalization, Unicode variants, and harmless category formatting.
Explicit PASS, REQUEST_CHANGES, or BLOCK decision.
Formal JSON schema and hardened offline validation helper.
Secret-shape redaction checks and resistance to instructions embedded in reviewed content.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 24 days ago
- Passed all security checks, Safe to install