# Login and permissions review (/security--auth-review)

/security--auth-review is a Claude Code skill in the Code section. Reviews your app's login, sessions, tokens and access rules and returns severity-rated findings, each with a specific fix.

- Web version: https://skills.sgomez.dev/en/s/security--auth-review
- Section: [Code](https://skills.sgomez.dev/en/code.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/security/auth-review.md
- Updated 26 Mar 2026

## How to ask for it

- `/security--auth-review check our app's login flow for issues`
- `/security--auth-review review admin panel permission checks`
- `/security--auth-review are there flaws in how we verify JWT tokens?`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install security-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: —
- Runs: —
- Network: No
- Destructive: No

## Author's description

Review authentication and authorization implementation for vulnerabilities

## Pairs well with

- [Leaked secrets scan (/security--secrets-scan)](https://skills.sgomez.dev/en/s/security--secrets-scan.md): Scans your code, config files and recent git history for API keys, tokens, passwords and private keys, and explains how to remediate each.
- [Dependency vulnerability check (/security--dependency-vuln)](https://skills.sgomez.dev/en/s/security--dependency-vuln.md): Runs your package manager's audit and lists each vulnerable dependency with its CVE, severity, fixed version and a remediation plan.
- [OWASP security audit (/security--security-audit)](https://skills.sgomez.dev/en/s/security--security-audit.md): Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.
- [Input sanitization review (/security--sanitize)](https://skills.sgomez.dev/en/s/security--sanitize.md): Traces where user input enters your code and where it ends up, flags SQL injection, XSS and similar flaws, and proposes the fix.
- [Environment and headers hardening (/security--env-hardening)](https://skills.sgomez.dev/en/s/security--env-hardening.md): Reviews .env files, server settings and HTTP security headers, then generates a hardened configuration with a before and after comparison.
- [CORS configuration review (/security--cors-review)](https://skills.sgomez.dev/en/s/security--cors-review.md): Reviews your CORS setup in Express, FastAPI, Django or Nginx, tightens overly permissive origins and headers, and verifies them with curl.
- Recipe: [/pipeline--security-hardening](https://github.com/sgomez-dev/claude-skills/blob/main/pipelines/security-hardening.yaml): Security Hardening

- [How we review this](https://skills.sgomez.dev/en/methodology.md)
