← Search

Security Review
Security
⚙ Needs: Use "Security Review" with your Muse.

Security Review

Security checklist for Muse: secrets management, input validation, auth patterns, and API hardening, with FAIL/PASS examples to catch vulnerabilities before they ship.

At a glance
What
Security checklist for Muse: secrets management, input validation, auth patterns, and API hardening, with FAIL/PASS examples to catch vulnerabilities before they ship.
Cost
Free
Needs
Use "Security Review" with your Muse.
Install
Copy the installer prompt below into your Muse — your agent does the rest.

Version:

⌁

Install

Copy the install package below, then paste it into Muse
Wanna be extra careful?

The install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?

How to check a build before installing →

Use "Security Review" with your Muse. Prerequisites: none to install. Pure guidance; have the code or pull request you want reviewed ready. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/security-review/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Review this code for security issues: [paste code or describe the change]." 3. Work through the checklist it returns (secrets, input validation, auth, API surface) and fix each FAIL before merging. Tip: run it on every PR that touches authentication, user input, secrets, or payments. Safety: a skill is plain-text instructions; it runs nothing by itself. Never paste real API keys, tokens, or passwords into a chat, even for review.

?

Questions

How do I install a build?

Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.

Where does my money go?

Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.

What does the ✓ next to a creator’s name mean?

It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.