security-and-secrets-review - Review secrets, authentication, and security configuration
Reviews secrets, authentication, tokens, CORS, cookies, logging, unsafe sinks, and configuration, reporting evidence, severity, fixes, and rotation flags without exposing raw secrets.
Tags
Updated: 2026-09-29Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Locate secret surfaces
- Scan committed credentials
- Review token handling
- Check CORS and cookies
- Inspect logging redaction
- Find unsafe sinks
- Rank findings and fixes
Inputs
- Source code tree
- Configuration files
- Environment files
- Git repository
- Approved Git history
- Security architecture documentation
Outputs
- Security findings report
- File-and-line evidence references
- Severity ratings
- Concrete remediation guidance
- Secret rotation flags
Requirements
- Repository read access
- Configuration read access
- Git command access
- ripgrep or grep
