Skip to content

Add security-review and security-remediation skills - #44

Open
Atharva0506 wants to merge 3 commits into
AOSSIE-Org:mainfrom
Atharva0506:feature/security-review-remediation-skill
Open

Atharva0506 wants to merge 3 commits into
AOSSIE-Org:mainfrom
Atharva0506:feature/security-review-remediation-skill

Conversation

@Atharva0506

@Atharva0506 Atharva0506 commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Addressed Issues:

No related issue — this adds tooling under .claude/skills/, agreed on separately with a maintainer.

Screenshots/Recordings:

Not applicable — this change only adds Claude Code skill definitions, no application behavior changes.

Additional Notes:

Adds two Claude Code skills, ported from the same change in ThruBox-Server:

  • security-review guides a security-focused code review, separates deliberate design tradeoffs into a Notes section instead of misfiling them as Findings or Limitations, and saves its report to unremediated-security-reviews/ (gitignored) instead of only printing it to chat.
  • security-remediation (new) reads that report, matches remediating commits via git log, confirms with the user, and — once every finding is remediated or explained — publishes both files to a tracked security-reviews/ folder.

Checklist

  • My code follows the project's code style and conventions
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings or errors
  • I have joined the Discord server and I will share a link to this PR with the project maintainers there
  • I have read the Contributing Guidelines

⚠️ AI Notice - Important!

This PR was written with Claude Code (model: Claude Sonnet 5), including the skill definitions themselves and this description.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added guided workflows for reviewing security across supported applications and tracking confirmed remediations in structured reports.
    • Security review reports remain private until findings are resolved or explained.
  • Chores

    • Updated the checklist status timestamp.

Atharva0506 and others added 2 commits September 23, 2026 18:12
- security-review guides a security-focused code review, saves its report
  to unremediated-security-reviews/ (gitignored), and separates deliberate
  design tradeoffs into a Notes section instead of misfiling them
- security-remediation reads that report, matches remediating commits via
  git log, confirms with the user, and publishes both files to
  security-reviews/ once every finding is remediated or explained

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions github-actions Bot added no-issue-linked PR is not linked to any issue configuration Configuration file changes documentation Changes to documentation files javascript JavaScript/TypeScript code changes size/XL Extra large PR (>500 lines changed) repeat-contributor PR from an external contributor who already had PRs merged needs-review labels Sep 23, 2026
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor
Messages
📖

⚠️ PR Template Check

These are non-blocking, but please fix:

  • No issue linked. Consider adding Fixes #<number> (e.g. Fixes #42) under the Addressed Issues section.

  • Some required checklist items are not completed:

  • My PR addresses a single issue

Generated by 🚫 dangerJS against 11808ab

@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 26 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: AOSSIE-Org/ThruBox-Client/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1ae61759-f15a-4032-bde5-67050cb88af5

📥 Commits

Reviewing files that changed from the base of the PR and between 9c5d565 and 11808ab.

📒 Files selected for processing (2)
  • .claude/skills/security-remediation/SKILL.md
  • .claude/skills/security-review/SKILL.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: AOSSIE-Org/ThruBox-Client/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: fd34415e-fc0a-4b22-98d0-0b5b14b56cd8

📥 Commits

Reviewing files that changed from the base of the PR and between 6f01694 and 9c5d565.

📒 Files selected for processing (4)
  • .claude/skills/security-remediation/SKILL.md
  • .claude/skills/security-review/SKILL.md
  • .gitignore
  • checklist-status.json
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • AOSSIE-Org/ThruBox-Server (manual)

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

Adds Claude Code skills for security review and remediation. The review skill defines review criteria and report handling. The remediation skill defines how to confirm findings, document remediation, and publish completed reports. The change also ignores private review reports and updates a checklist timestamp.

Changes

Security review and remediation

Layer / File(s) Summary
Security review workflow
.claude/skills/security-review/SKILL.md, .gitignore
Defines review scope, project-specific checks, finding criteria, report structure, and private report storage.
Find and confirm remediations
.claude/skills/security-remediation/SKILL.md
Defines how to locate a review report, parse findings, inspect candidate commits, and confirm remediation details with the user.
Write and publish remediation reports
.claude/skills/security-remediation/SKILL.md
Defines the remediation report format, commit links, private saving, publication conditions, and completion summary.

Checklist timestamp

Layer / File(s) Summary
Update checklist status date
checklist-status.json
Changes the updated date to 2026-09-23.

Priority: ⚪ Not assessed

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 9c5d5

The security-review and remediation skills are ready for normal checks before merging; no specific blocking issue is established.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding the security-review and security-remediation skills.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads each finding twice,
Then checks the commits for their ties.
Reports stay tucked away,
Till all are cleared to make their way.
The checklist marks September's day.

Comment @coderabbitai help to get the list of available commands.

Ports the same fix applied on the ThruBox-Server and Chainvoice sibling
PRs, so the skill definitions stay identical across repos:

- security-review: use an explicit base ref (three-dot diff) instead of
  bare `git diff` so committed PR changes aren't missed, resolve the repo
  root before writing the report/gitignore, include a commit-hash suffix
  in the report filename to avoid same-second collisions, stop describing
  .gitignore exclusion as "private", and add markdown language tags to
  the report-format code fences (MD040)
- security-remediation: add AskUserQuestion to allowed-tools (Step 4
  requires it), validate/quote report-derived git arguments, widen commit
  search beyond the finding's file, strip URL userinfo from commit links,
  and use the report path actually selected in Step 1 when publishing

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

configuration Configuration file changes documentation Changes to documentation files javascript JavaScript/TypeScript code changes needs-review no-issue-linked PR is not linked to any issue repeat-contributor PR from an external contributor who already had PRs merged size/XL Extra large PR (>500 lines changed)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant