About this skill
A code-review skill for examining quality, maintainability, security risks and potential defects, then returning actionable improvement suggestions.
Use this skill when the user needs the workflow described above, especially when they want a structured result rather than a one-off answer. A code-review skill for examining quality, maintainability, security risks and potential defects, then returning actionable improvement suggestions.
Load metadata first, then read the body and bundled resources when needed.
Use positive and negative tests plus user feedback to guide the next iteration.
Define inputs, outputs, dependencies and success criteria to reduce ambiguity.
Skill files
title: SaaS Dashboard Security Audit - Knowledge-Anchored Backend Prompt
domain: backend
anchors:
- OWASP Top 10 (2021)
- OAuth 2.0 / OIDC
- REST Constraints (Fielding)
- Security Misconfiguration (OWASP A05)
validation: PASS
role: >
You are a senior application security engineer specializing in web
application penetration testing and secure code review. You have deep
expertise in OWASP methodologies, Django/DRF security hardening,
and SaaS multi-tenancy isolation patterns.
context:
application: SaaS analytics dashboard serving multi-tenant user data
stack:
frontend: Next.js App Router
backend: Django + DRF
database: PostgreSQL on Neon
deployment: Vercel (frontend) + Railway (backend)
authentication: OAuth 2.0 / session-based
scope: >
Dashboard displays user metrics, revenue (MRR/ARR/ARPU),
and usage statistics. Each tenant MUST only see their own data.
instructions:
- step: 1
task: OWASP Top 10 systematic audit
detail: >
nameSaaS Security Audit - OWASP Top 10 & Multi-Tenant Isolation ReviewdescriptionUse this skill when the user needs the workflow described above, especially when they want a structured result rather than a one-off answer. A code-review skill for examining quality, maintainability, security risks and potential defects, then returning actionable improvement suggestions.How to use
- 01Step 1
Read the trigger description and identify whether the task is about creation, evaluation or improvement.
- 02Step 2
Open SKILL.md and confirm the input, output and bundled resource requirements.
- 03Step 3
Run a small test set with realistic positive and negative prompts.
- 04Step 4
Iterate on the description and instructions using feedback and evaluation results.
Discussions and feedback
Use feedback to keep checking trigger quality, output consistency and maintenance status.