36 lines
2.0 KiB
Markdown
36 lines
2.0 KiB
Markdown
---
|
|
name: security-audit
|
|
description: Use when performing security audits, vulnerability scanning, threat modeling, or reviewing code for OWASP Top 10 vulnerabilities, injection flaws, and authentication/authorization issues.
|
|
---
|
|
|
|
# Security Audit & Threat Modeling
|
|
|
|
## Purpose
|
|
Rigorously review code, APIs, and infrastructure configurations for security vulnerabilities, information leaks, authorization flaws, and untrusted input exploitation.
|
|
|
|
## Core Audit Vectors
|
|
|
|
### 1. Injection & Deserialization
|
|
- **SQL / NoSQL Injection:** Are queries parameterized? Are dynamic clauses safely validated against strict allowlists?
|
|
- **Command Injection:** Are subprocess arguments passed as arrays (`argv`) rather than concatenated shell strings? Is shell evaluation (`shell: true`, `eval`, `exec`) avoided?
|
|
- **Unsafe Deserialization:** Is arbitrary YAML/JSON deserialization guarded against code execution (`js-yaml` with `DEFAULT_SCHEMA` vs dangerous constructors)?
|
|
|
|
### 2. Authentication & Access Control (Broken Object-Level Auth)
|
|
- Are access checks enforced on every endpoint/resolver, or solely in the UI?
|
|
- Can user A access or mutate resources of user B by altering IDs/keys in requests (IDOR)?
|
|
- Are session tokens and credentials rotated and scrubbed from telemetry/logs?
|
|
|
|
### 3. File System & Path Traversal
|
|
- Are file paths normalized and verified to stay within designated workspace/sandbox boundaries (`path.resolve`, canonical path traversal checks)?
|
|
- Are symlinks resolved to prevent sandbox escaping?
|
|
|
|
### 4. Data Exposure & Secrets Management
|
|
- Are API keys, tokens, and database passwords excluded from git commits and client bundles?
|
|
- Are errors sanitized in production to avoid leaking internal stack traces and server topology?
|
|
- Is CORS and CSP configured to minimum required access?
|
|
|
|
## Deliverables
|
|
1. **Threat Model:** Identified attack surfaces and threat actors.
|
|
2. **Vulnerabilities List:** Ranked by CVSS/Severity (Critical, High, Medium, Low) with concrete PoC scenarios.
|
|
3. **Remediation Plan:** Immediate patch and long-term architectural defense-in-depth.
|