Add security-review and security-remediation skills - #44
Atharva0506 wants to merge 3 commits into
Conversation
- security-review guides a security-focused code review, saves its report to unremediated-security-reviews/ (gitignored), and separates deliberate design tradeoffs into a Notes section instead of misfiling them - security-remediation reads that report, matches remediating commits via git log, confirms with the user, and publishes both files to security-reviews/ once every finding is remediated or explained Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedNext included review available in 26 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: AOSSIE-Org/ThruBox-Client/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: AOSSIE-Org/ThruBox-Client/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughAdds Claude Code skills for security review and remediation. The review skill defines review criteria and report handling. The remediation skill defines how to confirm findings, document remediation, and publish completed reports. The change also ignores private review reports and updates a checklist timestamp. ChangesSecurity review and remediation
Checklist timestamp
Priority: ⚪ Not assessed Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The security-review and remediation skills are ready for normal checks before merging; no specific blocking issue is established. 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit reads each finding twice, Comment |
Ports the same fix applied on the ThruBox-Server and Chainvoice sibling PRs, so the skill definitions stay identical across repos: - security-review: use an explicit base ref (three-dot diff) instead of bare `git diff` so committed PR changes aren't missed, resolve the repo root before writing the report/gitignore, include a commit-hash suffix in the report filename to avoid same-second collisions, stop describing .gitignore exclusion as "private", and add markdown language tags to the report-format code fences (MD040) - security-remediation: add AskUserQuestion to allowed-tools (Step 4 requires it), validate/quote report-derived git arguments, widen commit search beyond the finding's file, strip URL userinfo from commit links, and use the report path actually selected in Step 1 when publishing Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addressed Issues:
No related issue — this adds tooling under
.claude/skills/, agreed on separately with a maintainer.Screenshots/Recordings:
Not applicable — this change only adds Claude Code skill definitions, no application behavior changes.
Additional Notes:
Adds two Claude Code skills, ported from the same change in ThruBox-Server:
security-reviewguides a security-focused code review, separates deliberate design tradeoffs into a Notes section instead of misfiling them as Findings or Limitations, and saves its report tounremediated-security-reviews/(gitignored) instead of only printing it to chat.security-remediation(new) reads that report, matches remediating commits viagit log, confirms with the user, and — once every finding is remediated or explained — publishes both files to a trackedsecurity-reviews/folder.Checklist
This PR was written with Claude Code (model: Claude Sonnet 5), including the skill definitions themselves and this description.
🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Chores