db4ae19c0a
Move all 24 review entries from skills-review/catalog.js +
skills-review/submitted-catalog.js into a typed Astro content collection at
src/content/reviews/. Each entry is a Markdown file with frontmatter for the
review metadata (id, author, focus, wins, improve, extras, name, description)
and a body that holds the 'improved' SKILL.md content.
Re-point scripts/build-skill-review.mjs at the new collection. The generator
reads each .md file, parses its YAML frontmatter, and writes
skill-reviews/improved/{id}/SKILL.md in the same shape the legacy catalog
produced — verified byte-identical via 'git diff --exit-code skill-reviews/'.
The 'name' field is preserved separately from 'id' because two entries
renamed the skill during review (id angular-accessibility-root → name
angular-accessibility; id confectionary-skill-hub → name confectionery-orders).
Without it the generator output would drift on those two files.
Does not yet delete skills-review/catalog.js or submitted-catalog.js —
verify.mjs and the legacy review-desk page both still read them, so they
stay as a mirror until task 16 rewires the page to the collection. Adding a
new submission today requires editing both the .md file (new source of
truth) and the legacy catalog.js (until task 16).
Done-when:
- 24 entries under src/content/reviews/ ✓
- verify.mjs's id:' count assertion still passes ✓
- git diff --exit-code skill-reviews/ clean after regenerating ✓
- astro check passes (22 files: 0 errors, 0 warnings, 2 hints) ✓
Co-Authored-By: Claude Code <noreply@anthropic.com>
1.8 KiB
1.8 KiB
author, description, extras, focus, id, improve, name, path, status, title, wins
| author | description | extras | focus | id | improve | name | path | status | title | wins | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Andre Salvo | Audit a changed code path for SQL injection. Use when code constructs or executes SQL, query-builder fragments, or ORM raw queries. | Add an eval with a parameterized query and a dynamic `ORDER BY` allowlist. | Trace user-controlled data to SQL sinks and verify values are parameterized. | sql-injection-audit |
|
sql-injection-audit | ../submitted-skills/Andre%20Salvo/skills/sql-injection-audit/SKILL.md | Fix metadata | SQL injection audit |
|
sql-injection-audit
Inputs
Changed files, branch diff, or a named query path.
Workflow
- Find SQL execution sinks and trace request, CLI, external, and stored user input to them.
- Confirm values use driver or ORM parameters. For dynamic identifiers, confirm a finite allowlist maps a user choice to a trusted token.
- Review raw-query escape hatches and stored procedures.
- Report only evidenced findings with source, sink, location, impact, and a safe pattern.
Rules
- Escaping is not a substitute for parameterization.
- Passing tests are supporting evidence, not proof of safety.
- Do not modify code unless the user asks for a fix.
Output
Return a findings table and the scope reviewed; say explicitly when a path could not be traced.