Maps sensitive flows and evidence before trusting AI-built code.
SB Security Assessment Starter
Reduces blind trust in AI-built security-sensitive code.
Ranks findings by severity and safe fix order.
What is this?
A Level 1 defensive security review skill for checking AI-built code, configuration, auth, payment, download, passcode, secrets, and admin flows before users trust the output.
Who this is for
- Non-technical builders shipping AI-generated code that touches customer data, payments, downloads, or admin access
- Founders who want a defensive first-pass security review before launch
- Creators using vibe coding tools and needing safer remediation steps
What problem it solves
- Reduces blind trust in AI-built security-sensitive code.
- Forces findings to be evidence-based instead of fear-based or guessed.
- Creates a safer handoff from security review to clean-code remediation.
What files do I get?
How it works
- 01
Download or claim the ZIP.
- 02
Open START_HERE.
- 03
Use @SB_security_assessment when asking your AI agent to start.
- 04
Check safety and verification before relying on output.
Example security review report
A shortened defensive review sample for checkout and download access flows.
Security Assessment Starter Result Scope: Defensive review of SkillBundle checkout and download access flow. Sensitive flows: PayPal checkout, order capture, passcode generation, signed download token, private ZIP download. Overall risk: Medium until webhook handling and concurrent download-limit checks are hardened. Findings: - PayPal webhook route needs verified provider handling before async payment events are trusted. - Download count should be enforced atomically under concurrent requests. - Secrets and private artifact access are handled through environment variables and private download paths. Verification focus: - Signed PayPal sandbox webhook. - Parallel download requests against the 3-download limit. - No public permanent ZIP URL exposure. Recommended next skill: @SB_clean_code for the atomic download-limit fix.
Impact dashboard
Practical targets for saving time, reducing repeated prompting, and checking AI output. Results vary by task and source quality.
Maps sensitive flows and evidence before trusting AI-built code.
Checks environment, logs, and public files for unsafe secret handling.
Ranks findings by severity and safe fix order.
Turns vague risk into concrete checks before release.
Safety and verification
- Safety checklist.
- Verification checklist.
- Antigravity, Codex, and VS Code install guides.
- Success-page download plus email backup.
Included interface patterns
A plain-English map of entry points, assets, and trust boundaries.
Sensitive-flow review scope and missing-evidence list.A defensive file or route review for secrets, auth, payment, download, and logging risks.
Evidence-based findings with severity and safe remediation.A safe fix order that avoids weakening existing controls.
Patch notes, verification steps, and `@SB_clean_code` handoff.Reviews for SB Security Assessment Starter
Emails are masked publicly. New user reviews are collected as pending approval tasks before they can appear on the storefront.
No approved public reviews yet.
Reviews for this product are collected as pending approval tasks before they can appear publicly.
FAQ
No. SkillBundle packages are designed for non-technical users.
Yes. Paid products are available for instant download after successful payment.
Yes. We send the download link, usage guide, product details, and order reference to your email.
Yes. Packages include instructions for Antigravity, Codex, VS Code, and other agent environments.
