Security Review
Security checklist for Muse: secrets management, input validation, auth patterns, and API hardening, with FAIL/PASS examples to catch vulnerabilities before they ship.
- What
- Security checklist for Muse: secrets management, input validation, auth patterns, and API hardening, with FAIL/PASS examples to catch vulnerabilities before they ship.
- Cost
- Free
- Needs
- Use "Security Review" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a security review skill that turns Muse into a systematic code auditor for the moments that matter most: adding authentication, handling user input, working with secrets, creating API endpoints, or touching payment and sensitive features. Instead of vague advice it ships a concrete, checkable list: secrets management (no hardcoded keys, env vars verified at startup, .env.local in .gitignore, nothing sensitive in git history, production secrets in the hosting platform), input validation with schemas (zod examples for emails, ranges, and required fields), plus patterns for authentication, authorization, API hardening, and third-party integrations. Every rule comes with FAIL/PASS code pairs so the difference between vulnerable and safe is unmistakable, and verification steps you can tick off before merging. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: a checklist, not a penetration test; it catches common mistakes, not novel attack chains; always review security-related code yourself, and never paste real secrets into any chat. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Security Review" with your Muse. Prerequisites: none to install. Pure guidance; have the code or pull request you want reviewed ready. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/security-review/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Review this code for security issues: [paste code or describe the change]." 3. Work through the checklist it returns (secrets, input validation, auth, API surface) and fix each FAIL before merging. Tip: run it on every PR that touches authentication, user input, secrets, or payments. Safety: a skill is plain-text instructions; it runs nothing by itself. Never paste real API keys, tokens, or passwords into a chat, even for review.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.