Review perspective: Contracts & Security
SkillSecurityThis skill is a review perspective for PostHog Review that guides an agent to check changed code for security flaws and breaking API changes. It examines API contracts, injection and authorization gaps, input validation, and schema alignment. It reports only security and contract findings, leaving logic and performance to other reviewers.
Use Review perspective: Contracts & Security in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Review perspective: Contracts & Security and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Review perspective: Contracts & Security skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have a code change or pull request chunk ready for review.
What your AI can do with it
- Check changed request and response formats for breaking changes
- Find removed or renamed fields and data-type changes
- Look for SQL injection, XSS, and prompt-injection risks
- Verify authentication and authorization checks
- Confirm database schemas match code models and interfaces
Getting started
- Have a code change or pull request chunk ready for review.
- Add the review-hog-perspective-contracts-security skill to your agent.
- Configure the agent to run this perspective on the chunk.
- Let the agent use search commands to find endpoints, queries, and auth code.
- Collect the security and contract findings it reports.
What this skill tells your AI
The instructions your AI receives, as published by posthog/posthog in products/review_hog/skills/review-hog-perspective-contracts-security/SKILL.md and read by ahel’s review.
You are reviewing a PR chunk through the Contracts & Security perspective: is the code safe, and does it preserve compatibility? Concentrate on API contracts and breaking changes, security vulnerabilities, input validation, and schema / interface alignment.
This is one of several independent perspectives reviewing the same chunk in parallel — logic and performance are covered elsewhere. Stay in your lane, and report every security or contract issue you find without worrying about what another perspective might also report (overlap is resolved later by a separate deduplication step).
Primary investigation areas
-
API contracts & breaking changes
- Check for changed request / response formats
- Identify removed or renamed fields
- Validate data-type changes
- Ensure version compatibility
- Check GraphQL / REST contract compliance
-
Security vulnerabilities
- Look for SQL injection vulnerabilities
- Check for XSS attack vectors
- Identify prompt-injection risks (for LLM code)
- Verify authentication / authorization checks
- Ensure sensitive data is not exposed
-
Input validation & boundaries
- Verify validation at all entry points
- Check input sanitization
- Validate type safety
- Ensure range and limit checks
- Check for buffer-overflow risks
-
Schema & interface alignment
- Verify database schema matches code models
- Check frontend / backend type consistency
- Validate API specifications
- Ensure migration compatibility
Investigation commands
- Find API endpoints:
rg "@action\(|@api_view\(|class \w+(ViewSet|APIView)" --type py -B 2 -A 5(DRF endpoints; route wiring lives inurls.py/routes.pyfiles) - Check input validation:
rg "validate|sanitize|clean.*input" --type py -A 5 - Find SQL queries:
rg "execute|query|raw.*sql" --type py -B 2 -A 5 - Check auth:
rg "authenticate|authorize|permission|@login_required" --type py -B 2 -A 3 - Find schema definitions:
rg "class.*Model|Schema|Interface" --type py --type ts -A 10
Where to focus
Concentrate primary attention on:
- API endpoints and controllers
- Database models and migrations (critical for schema validation)
- Type definitions and interfaces (
*.d.ts, type annotations) - Authentication / authorization modules
- Input validation and sanitization code
- Data serialization / deserialization logic
- External API integrations
- API specification files (OpenAPI, GraphQL schemas) and security configuration files
Detect issues only in non-test files; reference docs and frontend-only UI components without data handling for context, but don't raise contract / security findings on them.
What to leave to other perspectives
- Logic and correctness errors → Logic & Correctness
- Performance optimizations and error-handling completeness → Performance & Reliability
- Code style or formatting → not a PostHog Review concern
Key questions
- Are all inputs properly validated and sanitized?
- Could this code introduce security vulnerabilities?
- Are API contracts maintained or properly versioned?
- Is sensitive data properly protected?
- Are there any breaking changes for API consumers?
- Do schemas and interfaces align across layers?
What a valid finding looks like
A Contracts & Security finding relates to:
- Security vulnerabilities (injection, XSS, etc.)
- Breaking API changes
- Missing input validation
- Schema mismatches
- Authentication / authorization gaps
- Data-exposure risks
- Contract violations
Signals
- GitHub stars
- 40k
- Forks
- 3k
- Last commit
- Sep 2026
Questions
- Does this skill report logic or performance issues?
- No. It reports security and contract issues only. Logic and performance are covered by other review perspectives.
- What does it check for API contracts?
- It checks changed request and response formats, removed or renamed fields, data-type changes, version compatibility, and GraphQL or REST contract compliance.
- What security vulnerabilities does it look for?
- It looks for SQL injection, XSS, prompt-injection risks in LLM code, missing authentication or authorization checks, and exposed sensitive data.
- How does it find relevant code?
- It uses search commands to locate API endpoints, input validation, SQL queries, auth checks, and schema definitions.
Advanced
- Item type
- skill
- Key
review-hog-perspective-contracts-security- Source
- github.com/posthog/posthog
Related picks
Skill · mattpocock
Does the same job in other wordsbmad-code-review
Skill · bmad-code-org
Does the same job in other wordsmulti-reviewer-patterns
Skill · wshobson
Does the same job in other wordssetup-ts-deep-modules
Skill · mattpocock
The pick for TypeScripttypescript-pro
Skill · jeffallan
The pick for TypeScriptanalyzing-ethereum-smart-contract-vulnerabilities
Skill · mukul975
The pick for Vulnerabilities