From ed06a70373617e3911143358f3282bb8b13417c5 Mon Sep 17 00:00:00 2001 From: Edward Date: Fri, 25 Sep 2026 09:35:52 -0500 Subject: [PATCH 1/9] Add draft cost skill --- cost/SKILL.md | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 cost/SKILL.md diff --git a/cost/SKILL.md b/cost/SKILL.md new file mode 100644 index 0000000..89a3ce0 --- /dev/null +++ b/cost/SKILL.md @@ -0,0 +1,46 @@ +--- +name: cost +description: Measures the cost of the project in terms of maintainability and complexity. +--- + +## Analyzing maintainability + +Use this skill when asked to assess code quality, complexity, technical debt, +or "how maintainable is this codebase". + +## Setup + +This skill requires Python. + +1. Setup the environment using the following commands: + +```bash +python -m venv .venv.analysis +.venv.analysis/bin/pip install radon vulture +``` + +## Analysis + +2. When this guide refers to `radon`, find it at `.venv.analysis/bin/radon`. + +2. When this guide refers to `vulture`, find it at `.venv.analysis/bin/vulture`. + +3. Maintainability index comes from `radon mi -j`. Treat rank `C` (MI < 10) + as a real problem worth flagging in a summary; rank `B` is borderline; + rank `A` is fine. + +4. Dead code comes from `vulture --min-confidence 80`. It is informational + only — cross-check a few hits before recommending deletion, since dynamic + dispatch (plugin loading via `PLUGIN_CLASS`/`TRANSFORMER_CLASS`) causes + false positives. + +## Report Format + +5. When summarizing for a human, lead with the handful of worst offenders + (by MI or complexity), not raw tool output. Group by directory + (`plugins_user/*` complexity is expected to run higher than `glance/` + core, since `_build_result` methods fan out over many response fields). +6. Always include the total count of lines of code in the report. +7. Include the average number of lines of code per file in the report. + +8. Write the output to a file named `reports/cost-report.md` From 7a49096bfd209db462be9bd0c22e7dbd09255f14 Mon Sep 17 00:00:00 2001 From: Edward Date: Fri, 25 Sep 2026 10:15:58 -0500 Subject: [PATCH 2/9] Add `gh skill` instructions --- README.md | 11 +++++++++++ cost/SKILL.md | 14 +++++--------- 2 files changed, 16 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index 97d5e85..80bfc72 100644 --- a/README.md +++ b/README.md @@ -27,6 +27,17 @@ for information about our development standards. - We want to help interpret and respond to these reports - they can be confusing, may contain false positives, and will raise questions. - Campus IT Professionals can contact securitysupport@illinois.edu. +## Installation + +```bash +cd ~/projects +git clone https://github.com/techservicesillinois/secdev-code-risk-tools +cd ~/projects/my_project_1 +gh skill install --from-local ~/projects/secdev-code-risk-tools/ +``` + +Then follow the interactive prompts to choose between the available skills, where they should be available, and for which LLM tools. + ## Data Sources For data sensitivity, see [Data Classification](https://www.cybersecurity.illinois.edu/data-classification/). diff --git a/cost/SKILL.md b/cost/SKILL.md index 89a3ce0..8c56b01 100644 --- a/cost/SKILL.md +++ b/cost/SKILL.md @@ -16,7 +16,7 @@ This skill requires Python. ```bash python -m venv .venv.analysis -.venv.analysis/bin/pip install radon vulture +.venv.analysis/bin/pip install radon vulture pycodestats ``` ## Analysis @@ -29,6 +29,8 @@ python -m venv .venv.analysis as a real problem worth flagging in a summary; rank `B` is borderline; rank `A` is fine. +4. Lines of code count come from `pycodestats` + 4. Dead code comes from `vulture --min-confidence 80`. It is informational only — cross-check a few hits before recommending deletion, since dynamic dispatch (plugin loading via `PLUGIN_CLASS`/`TRANSFORMER_CLASS`) causes @@ -36,11 +38,5 @@ python -m venv .venv.analysis ## Report Format -5. When summarizing for a human, lead with the handful of worst offenders - (by MI or complexity), not raw tool output. Group by directory - (`plugins_user/*` complexity is expected to run higher than `glance/` - core, since `_build_result` methods fan out over many response fields). -6. Always include the total count of lines of code in the report. -7. Include the average number of lines of code per file in the report. - -8. Write the output to a file named `reports/cost-report.md` +5. When summarizing for a human, lead with the handful of worst offending files. +8. Write the output to a file named with the current date and `cost-report.md` in a new folder named `reports`. From 73505c65fa13d2d03da5b58e6fee631e1826c25b Mon Sep 17 00:00:00 2001 From: Edward Date: Fri, 25 Sep 2026 14:49:39 -0500 Subject: [PATCH 3/9] Import a copy of our code review skill --- {cost => code-cost}/SKILL.md | 13 +-- code-risk/SKILL.md | 170 +++++++++++++++++++++++++++++++++++ 2 files changed, 177 insertions(+), 6 deletions(-) rename {cost => code-cost}/SKILL.md (75%) create mode 100644 code-risk/SKILL.md diff --git a/cost/SKILL.md b/code-cost/SKILL.md similarity index 75% rename from cost/SKILL.md rename to code-cost/SKILL.md index 8c56b01..94e4e6c 100644 --- a/cost/SKILL.md +++ b/code-cost/SKILL.md @@ -1,5 +1,5 @@ --- -name: cost +name: code-cost description: Measures the cost of the project in terms of maintainability and complexity. --- @@ -23,20 +23,21 @@ python -m venv .venv.analysis 2. When this guide refers to `radon`, find it at `.venv.analysis/bin/radon`. -2. When this guide refers to `vulture`, find it at `.venv.analysis/bin/vulture`. +3. When this guide refers to `vulture`, find it at `.venv.analysis/bin/vulture`. -3. Maintainability index comes from `radon mi -j`. Treat rank `C` (MI < 10) +4. Maintainability index comes from `radon mi -j`. Treat rank `C` (MI < 10) as a real problem worth flagging in a summary; rank `B` is borderline; rank `A` is fine. -4. Lines of code count come from `pycodestats` +5. Lines of code count come from `pycodestats` -4. Dead code comes from `vulture --min-confidence 80`. It is informational +6. Dead code comes from `vulture --min-confidence 80`. It is informational only — cross-check a few hits before recommending deletion, since dynamic dispatch (plugin loading via `PLUGIN_CLASS`/`TRANSFORMER_CLASS`) causes false positives. ## Report Format -5. When summarizing for a human, lead with the handful of worst offending files. +7. When summarizing for a human, lead with the handful of worst offending files. + 8. Write the output to a file named with the current date and `cost-report.md` in a new folder named `reports`. diff --git a/code-risk/SKILL.md b/code-risk/SKILL.md new file mode 100644 index 0000000..12849aa --- /dev/null +++ b/code-risk/SKILL.md @@ -0,0 +1,170 @@ +--- +name: code-risk +description: 'Conduct a read-only cybersecurity review of application code and configuration. Use when: performing a security audit, checking for OWASP Top 10 vulnerabilities, reviewing authentication or authorization logic, identifying injection risks, finding exposed secrets or misconfigured CSP headers, auditing third-party dependencies, or assessing input validation and output encoding. Produces a findings report.' +argument-hint: 'Optional: scope (e.g., "auth module", "API layer", "all files")' +--- + +# Cybersecurity Review + + +## Purpose + +Audit code, configuration, and dependencies for security vulnerabilities and produce a structured findings report. Agents should treat this skill as **read-only**. + +## When to Use + +- Security audit before a release or deployment +- Reviewing authentication, session management, or authorization code +- Checking CSP headers, CORS policy, or other HTTP security controls +- Identifying injection risks (SQL, XSS, command injection, etc.) +- Auditing third-party dependencies for known CVEs +- Scanning for hardcoded secrets or credentials in source code +- Assessing input validation and output encoding + +______________________________________________________________________ + +## Procedure + +### 1. Determine Scope + +If the user specified a scope (e.g., a module or file path), limit the review to that area. Otherwise, review the full workspace. Identify: + +- Entry points (HTTP handlers, CLI args, form inputs, file uploads) +- Trust boundaries (client/server, user/admin, external APIs) +- Data flows involving sensitive information + +### 2. Gather Context (Read-Only) + +Use search and file-reading tools to collect: + +- Source files +- Configuration files +- Dependency manifests +- Build/deploy scripts + +You may run `npm audit --json` for informational output. + +### 3. Evaluate Against Security Categories + +Check each applicable category below and record any findings. + +#### A01 — Broken Access Control + +- Are authorization checks present on all protected routes/resources? +- Can users access resources belonging to other users (IDOR)? +- Is the principle of least privilege applied? + +#### A02 — Cryptographic Failures + +- Is sensitive data (PII, tokens, passwords) transmitted or stored in plaintext? +- Are weak or deprecated algorithms in use (MD5, SHA1, DES)? +- Are TLS/HTTPS enforced for all external connections? + +#### A03 — Injection + +- Are user inputs sanitized or parameterized before use in queries, shell commands, or template engines? +- Is `innerHTML`, `dangerouslySetInnerHTML`, `eval()`, or `document.write()` used with user-controlled data? +- Are SQL/NoSQL queries built with string concatenation? + +#### A04 — Insecure Design + +- Are there missing rate limits on authentication or sensitive endpoints? +- Is business logic enforced server-side, or only client-side? + +#### A05 — Security Misconfiguration + +- Are default credentials or example configs present? +- Are debug modes, verbose error messages, or stack traces exposed in production? +- Are unnecessary features, ports, or services enabled? +- Are HTTP security headers present and correctly configured (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy)? + +#### A06 — Vulnerable and Outdated Components + +- Do dependency manifests include packages with known CVEs? +- Are dependencies pinned to specific versions? +- Are dev dependencies accidentally included in production builds? + +#### A07 — Identification and Authentication Failures + +- Are session tokens sufficiently random and rotated after login? +- Are there protections against brute force (lockouts, CAPTCHA, rate limiting)? +- Are passwords hashed with a modern algorithm (bcrypt, argon2, scrypt)? + +#### A08 — Software and Data Integrity Failures + +- Are third-party scripts loaded from CDNs with Subresource Integrity (SRI) hashes? +- Is CI/CD pipeline configuration reviewed for unauthorized modification risks? + +#### A09 — Security Logging and Monitoring Failures + +- Are security-relevant events (login failures, access denials) logged? +- Are logs free of sensitive data (passwords, tokens, PII)? + +#### A10 — Server-Side Request Forgery (SSRF) + +- Does the application make HTTP requests to URLs supplied by the user? +- Are allow-lists used to restrict permissible destinations? + +#### Additional Checks + +- **Secrets in source**: Look for hardcoded API keys, tokens, passwords, or private keys in source files and git history hints. +- **Cookie security**: Are `HttpOnly`, `Secure`, and `SameSite` attributes set on sensitive cookies? +- **Content Security Policy**: Is a CSP defined? Does it avoid `unsafe-inline` or `unsafe-eval`? +- **Dependency confusion**: Are internal package names squattable on public registries? +- **Supply chain**: Are `package-lock.json` or equivalent dependency files omitted from source control? + +### 4. Compile the Findings Report + +Structure the report as follows. Omit sections with no findings. + +Use the report text below verbatim replacing placeholders with actual values. If a finding requires further investigation beyond available tools, note it as "Needs manual review". + +## Findings Report + +**Reviewed:** `` +**Date:** `` + +The purpose of this document is to help DevOps staff associated with the University of Illinois fulfill their [responsibility](https://cam.illinois.edu/policies/fo-36) to comply with Illinois Cybersecurity standards, including[IT05](https://go.illinois.edu/secstd-IT05), [IT07](https://go.illinois.edu/secstd-IT07), [IT08](https://go.illinois.edu/secstd-IT08), and [IT13](https://go.illinois.edu/secstd-IT13). + +This skill is a DRAFT. Rather than share this DRAFT, please encourage colleagues to contact securitysupport@illinois.edu for the latest version. + +This document is [TLP:AMBER](https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage), as it may contain information about potential vulnerabilities in a live campus service. This document should be shared only within the impacted team and the Privacy and Cybersecurity teams, and with their leadership, as needed, but otherwise kept confidential. + +Faculty and staff of the the University of Illinois may contact securitysupport@illinois.edu for assistance with understanding these results. + +### Summary + +| OWASP Category | Count | +|-----------------------------------------------------|-------| +| A01 — Broken Access Control | N | +| A02 — Cryptographic Failures | N | +| A03 — Injection | N | +| A04 — Insecure Design | N | +| A05 — Security Misconfiguration | N | +| A06 — Vulnerable and Outdated Components | N | +| A07 — Identification and Authentication Failures | N | +| A08 — Software and Data Integrity Failures | N | +| A09 — Security Logging and Monitoring Failures | N | +| A10 — Server-Side Request Forgery (SSRF) | N | +| Other Findings | N | + +______________________________________________________________________ + +### Findings + +For each finding, use this format: + +#### Title — Category + +**File/Location:** `path/to/file.ts:line` +**Description:** What the vulnerability is and why it matters. +**Evidence:** Relevant code snippet or configuration value (quote directly from source). +**Recommendation:** What should be done to remediate (description only). +**Reference:** OWASP link and CVE if applicable. + +______________________________________________________________________ + +## Constraints + +- This skill is meant to produce findings only. +- If a finding requires further investigation beyond available tools, note it as "Needs manual review" rather than speculating. From 3c6632569b31a0e3648a34820149d2f657ed593c Mon Sep 17 00:00:00 2001 From: Edward Date: Mon, 28 Sep 2026 14:21:11 -0500 Subject: [PATCH 4/9] Fixup spelling --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 80bfc72..1a737b9 100644 --- a/README.md +++ b/README.md @@ -36,7 +36,7 @@ cd ~/projects/my_project_1 gh skill install --from-local ~/projects/secdev-code-risk-tools/ ``` -Then follow the interactive prompts to choose between the available skills, where they should be available, and for which LLM tools. +Then follow the interactive prompts to choose between the available skills, where they should be available, and for which AI tools. ## Data Sources From 6fc5e9b0c33354e43722844ed9997f4c1d63b952 Mon Sep 17 00:00:00 2001 From: Edward Date: Mon, 28 Sep 2026 14:54:31 -0500 Subject: [PATCH 5/9] Add instructions for JavaScript --- code-cost/SKILL.md | 37 ++++++++++++++++++++----------------- 1 file changed, 20 insertions(+), 17 deletions(-) diff --git a/code-cost/SKILL.md b/code-cost/SKILL.md index 94e4e6c..298783e 100644 --- a/code-cost/SKILL.md +++ b/code-cost/SKILL.md @@ -10,34 +10,37 @@ or "how maintainable is this codebase". ## Setup -This skill requires Python. +Prompt the user for where to install tools and output reports. +Default to `~/code-risks/`. -1. Setup the environment using the following commands: +## Setup if there are JavaScript files + +Use `eslint` to assess code quality. +Use `knip` to look for dead code in JavaScript code files. + +## Setup if there are Python files + +If the project contains Python code, install Python static analysis tools: ```bash python -m venv .venv.analysis .venv.analysis/bin/pip install radon vulture pycodestats ``` -## Analysis +Use `radon` to analyze Python file code complexity. + +- Maintainability index for Python comes from `radon mi -j`. +- Treat rank `C` (MI less than 10) as a real problem worth flagging in a summary. -2. When this guide refers to `radon`, find it at `.venv.analysis/bin/radon`. +Use `vulture` to look for dead code in Python files. -3. When this guide refers to `vulture`, find it at `.venv.analysis/bin/vulture`. +- Use `vulture --min-confidence 80`. +- `vulture` output is informational only — cross-check a few hits before recommending deletion, since dynamic dispatch can cause false positives. -4. Maintainability index comes from `radon mi -j`. Treat rank `C` (MI < 10) - as a real problem worth flagging in a summary; rank `B` is borderline; - rank `A` is fine. +Use `pycodestats` to generate counts of lines of code in Python files. -5. Lines of code count come from `pycodestats` - -6. Dead code comes from `vulture --min-confidence 80`. It is informational - only — cross-check a few hits before recommending deletion, since dynamic - dispatch (plugin loading via `PLUGIN_CLASS`/`TRANSFORMER_CLASS`) causes - false positives. ## Report Format -7. When summarizing for a human, lead with the handful of worst offending files. - -8. Write the output to a file named with the current date and `cost-report.md` in a new folder named `reports`. +- When summarizing for a human, lead with the handful of worst offending files. +- Write the output to a file named with the current date and `cost-report.md` in a new folder named `reports`. From a1bf47c2bf18e7ca6995fd6d68c385463c5e93db Mon Sep 17 00:00:00 2001 From: Edward Date: Mon, 28 Sep 2026 14:55:46 -0500 Subject: [PATCH 6/9] Fixup --- code-cost/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code-cost/SKILL.md b/code-cost/SKILL.md index 298783e..cebf3bb 100644 --- a/code-cost/SKILL.md +++ b/code-cost/SKILL.md @@ -43,4 +43,4 @@ Use `pycodestats` to generate counts of lines of code in Python files. ## Report Format - When summarizing for a human, lead with the handful of worst offending files. -- Write the output to a file named with the current date and `cost-report.md` in a new folder named `reports`. +- Write the output to a file named with the current date and `cost-report.md` in the folder selected by the user, earlier. From 8f41c2cecbb6a282c43357c5fe9c444eb35142f0 Mon Sep 17 00:00:00 2001 From: Edward Date: Mon, 28 Sep 2026 15:36:04 -0500 Subject: [PATCH 7/9] Better path --- code-cost/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code-cost/SKILL.md b/code-cost/SKILL.md index cebf3bb..143e235 100644 --- a/code-cost/SKILL.md +++ b/code-cost/SKILL.md @@ -11,7 +11,7 @@ or "how maintainable is this codebase". ## Setup Prompt the user for where to install tools and output reports. -Default to `~/code-risks/`. +Default to `.agents/.code-cost`. ## Setup if there are JavaScript files From ed1b37a83b75ce000dfe36ee00450ba5bdc90608 Mon Sep 17 00:00:00 2001 From: Edward Date: Mon, 28 Sep 2026 15:36:46 -0500 Subject: [PATCH 8/9] Fixup --- code-cost/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code-cost/SKILL.md b/code-cost/SKILL.md index 143e235..529de9e 100644 --- a/code-cost/SKILL.md +++ b/code-cost/SKILL.md @@ -11,7 +11,7 @@ or "how maintainable is this codebase". ## Setup Prompt the user for where to install tools and output reports. -Default to `.agents/.code-cost`. +Default to `.agents/`. ## Setup if there are JavaScript files From 70ec48c7e9e5b5455c0489c7c6bf109346717add Mon Sep 17 00:00:00 2001 From: Edward Date: Mon, 28 Sep 2026 15:41:00 -0500 Subject: [PATCH 9/9] Prompt for working directory and output report name --- code-cost/SKILL.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/code-cost/SKILL.md b/code-cost/SKILL.md index 529de9e..5c1761f 100644 --- a/code-cost/SKILL.md +++ b/code-cost/SKILL.md @@ -11,7 +11,7 @@ or "how maintainable is this codebase". ## Setup Prompt the user for where to install tools and output reports. -Default to `.agents/`. +Default to using a temporary directory. ## Setup if there are JavaScript files @@ -39,8 +39,8 @@ Use `vulture` to look for dead code in Python files. Use `pycodestats` to generate counts of lines of code in Python files. - ## Report Format - When summarizing for a human, lead with the handful of worst offending files. -- Write the output to a file named with the current date and `cost-report.md` in the folder selected by the user, earlier. +- Prompt the user where to place the output report. +- Default to a name that includes `code-cost` and the current project name, and the current date.