Files
ECC/.opencode/commands/security.md
T
Gaurav Dubey 9d1ecb0754 fix(opencode): resolve command agent ids to registered opencode agents (#2477)
The `.opencode/commands/*.md` frontmatter referenced agents with the Claude
Code plugin namespace (`agent: everything-claude-code:<name>`), but ECC's
opencode integration registers its agents unscoped in `opencode.json`'s
`agent` map (`code-reviewer`, `planner`, ...), and that file's own `command`
section already references them unscoped. The `everything-claude-code:` scope
resolves under no opencode config (the opencode plugin package is
`ecc-universal`, and inline-config agents are bare), so subtask commands like
`/code-review` hard-fail with `Agent not found: everything-claude-code:code-reviewer`.
Non-subtask commands fall back to the default agent and appear to work — which
is why only some commands failed.

Strip the `everything-claude-code:` prefix from all 30 command frontmatter
agent ids so they match the registered agents, fix the MIGRATION.md example,
and replace the test that enforced the broken scoped invariant with one that
asserts each command agent id is a registered opencode agent (fails on the old
scoped ids, passes on the fix).

Fixes #2477
2026-07-10 09:46:40 +05:30

2.0 KiB

description, agent, subtask
description agent subtask
Run comprehensive security review security-reviewer true

Security Review Command

Conduct a comprehensive security review: $ARGUMENTS

Your Task

Analyze the specified code for security vulnerabilities following OWASP guidelines and security best practices.

Security Checklist

OWASP Top 10

  1. Injection (SQL, NoSQL, OS command, LDAP)

    • Check for parameterized queries
    • Verify input sanitization
    • Review dynamic query construction
  2. Broken Authentication

    • Password storage (bcrypt, argon2)
    • Session management
    • Multi-factor authentication
    • Password reset flows
  3. Sensitive Data Exposure

    • Encryption at rest and in transit
    • Proper key management
    • PII handling
  4. XML External Entities (XXE)

    • Disable DTD processing
    • Input validation for XML
  5. Broken Access Control

    • Authorization checks on every endpoint
    • Role-based access control
    • Resource ownership validation
  6. Security Misconfiguration

    • Default credentials removed
    • Error handling doesn't leak info
    • Security headers configured
  7. Cross-Site Scripting (XSS)

    • Output encoding
    • Content Security Policy
    • Input sanitization
  8. Insecure Deserialization

    • Validate serialized data
    • Implement integrity checks
  9. Using Components with Known Vulnerabilities

    • Run npm audit
    • Check for outdated dependencies
  10. Insufficient Logging & Monitoring

    • Security events logged
    • No sensitive data in logs
    • Alerting configured

Additional Checks

  • Secrets in code (API keys, passwords)
  • Environment variable handling
  • CORS configuration
  • Rate limiting
  • CSRF protection
  • Secure cookie flags

Report Format

Critical Issues

[Issues that must be fixed immediately]

High Priority

[Issues that should be fixed before release]

Recommendations

[Security improvements to consider]


IMPORTANT: Security issues are blockers. Do not proceed until critical issues are resolved.