skills/authn-authz-review/SKILL.md
Workflow to review authentication and authorization flows (sessions, tokens, RBAC/ABAC) and produce fix guidance.
npx skillsauth add robotti-io/copilot-security-instructions authn-authz-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when reviewing login, session management, token validation, or authorization checks.
invoice:read, admin:user:delete)Related prompts:
review-auth-flows.prompt.mdcheck-access-controls.prompt.mdHttpOnly/Secure/SameSite, CSRF defenses, and session rotation on privilege change.tools
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
testing
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
tools
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
content-media
Triage a dependency CVE using local repo evidence and remediation guidance.