Adds the unified-review integration that fuses CRG graph context with the ai-code-review scoring methodology and gstack-review fix-first workflow: - scoring.py: objective Layer-2 metrics (sql_risk, exception_coverage, redundancy_rate, high_risk_density, vulnerability_risk) with good/warn/fail grades, plus dedupe_findings (fingerprint merge, multi-source confidence boost, PR quality score) and report data builder - tools/scoring_tools.py + main.py: three new MCP tools (score_review_tool, dedupe_findings_tool, generate_report_tool) - assets/report-template.html: self-contained HTML report template - skills.py + skills/unified-review/: new read-only unified-review skill with language/manual-review/specialist checklists - docs and CHANGELOG updated; tests added (test_scoring, test_report, test_unified_review) and test_skills updated for 5 skills
18 lines
742 B
Markdown
18 lines
742 B
Markdown
# Security Specialist
|
|
|
|
Focus: security vulnerabilities in the diff.
|
|
|
|
- [ ] SQL injection (string interpolation, parameterized queries)
|
|
- [ ] AuthN/AuthZ bypasses, missing permission checks
|
|
- [ ] XSS (unsafe HTML rendering on user data)
|
|
- [ ] Sensitive data exposure / missing masking in logs and responses
|
|
- [ ] SSRF (fetching user/LLM-controlled URLs without allowlist)
|
|
- [ ] Command injection (`shell=True` + interpolation)
|
|
- [ ] Hardcoded secrets / credentials
|
|
- [ ] CSRF / missing rate limiting on auth endpoints
|
|
|
|
Insurance specialist — always runs, even when silent.
|
|
|
|
Output JSON lines:
|
|
`{"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"security","summary":"...","fix":"...","source":"security"}`
|