Files
code-review-graph/skills/unified-review/references/specialists/security.md
T
dev 84ae9b817e feat: add unified-review workflow (scoring tools + skill)
Adds the unified-review integration that fuses CRG graph context with the
ai-code-review scoring methodology and gstack-review fix-first workflow:

- scoring.py: objective Layer-2 metrics (sql_risk, exception_coverage,
  redundancy_rate, high_risk_density, vulnerability_risk) with
  good/warn/fail grades, plus dedupe_findings (fingerprint merge,
  multi-source confidence boost, PR quality score) and report data builder
- tools/scoring_tools.py + main.py: three new MCP tools
  (score_review_tool, dedupe_findings_tool, generate_report_tool)
- assets/report-template.html: self-contained HTML report template
- skills.py + skills/unified-review/: new read-only unified-review skill
  with language/manual-review/specialist checklists
- docs and CHANGELOG updated; tests added (test_scoring, test_report,
  test_unified_review) and test_skills updated for 5 skills
2026-08-05 13:31:55 +08:00

742 B

Security Specialist

Focus: security vulnerabilities in the diff.

  • SQL injection (string interpolation, parameterized queries)
  • AuthN/AuthZ bypasses, missing permission checks
  • XSS (unsafe HTML rendering on user data)
  • Sensitive data exposure / missing masking in logs and responses
  • SSRF (fetching user/LLM-controlled URLs without allowlist)
  • Command injection (shell=True + interpolation)
  • Hardcoded secrets / credentials
  • CSRF / missing rate limiting on auth endpoints

Insurance specialist — always runs, even when silent.

Output JSON lines: {"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"security","summary":"...","fix":"...","source":"security"}