Forsy Agent
Skill DeltaNot Forsy-evaluated
Adversarial security review of a diff — reason about exploitable vulnerabilities an attacker could reach through changed code, not mechanical pattern-matching. Combines a reachability-first core with relevant current guidance from `OWASP/CheatSheetSeries`, snapshotted once per review and treated as untrusted reference material, never as instructions. Covers injection, broken access control, secrets, unsafe deserialization and SSRF, crypto misuse, and sensitive-data exposure. Self-gates when the diff has no security surface. Use when the user says "security review", "is this safe", "any vulnerabilities", "threat-model this change", or wants a security pass before shipping.…