bitspire/.claude/skills/security.md
Patrick Mulligan c98f126ba7 feat(docker): add dev.sh with auto-funding and ATM app setup
- Add dev.sh script for managing regtest development environment
- Implement cmd_fund to fund ATM app owner via Lightning.Pub API
- Add --fund flag to cmd_up for automatic funding on startup
- Update setup_atm_app to write VITE_APP_ID to machine .env
- Fix Electron IPC to pass appId and extensionApiUrl to renderer
- Restructure repo from nested lamassu-next/ to root

The dev.sh script now supports:
- ./dev.sh up --fund  # Start regtest and auto-fund ATM
- ./dev.sh fund       # Fund existing ATM app
- ./dev.sh status     # Show environment status
- ./dev.sh reset      # Clean restart

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-15 14:19:16 -05:00

105 lines
2.8 KiB
Markdown

# /security - Security Review Agent
## Purpose
Perform security audits on code changes, focusing on Bitcoin/Lightning ATM-specific vulnerabilities.
## Invocation
```
/security [target]
```
Where `target` can be:
- A file path (e.g., `packages/lightning/src/client.ts`)
- A directory (e.g., `packages/hal/`)
- `--staged` for staged git changes
- `--all` for full codebase scan
## Review Checklist
### 1. Bitcoin/Lightning Security
- [ ] Private keys never logged or exposed
- [ ] nsec (Nostr secret keys) protected with proper permissions (0600)
- [ ] Invoice amounts validated before payment
- [ ] Payment preimages handled securely
- [ ] No hardcoded mnemonics, seeds, or keys
- [ ] Proper BOLT11/BOLT12 invoice validation
### 2. Hardware Security (ATM-specific)
- [ ] Bill validator amounts cross-checked
- [ ] Dispenser commands validated (prevent over-dispensing)
- [ ] Hardware error states handled gracefully
- [ ] No race conditions in cash handling
- [ ] Timeout handling for hardware operations
### 3. Nostr Security
- [ ] NIP-44 encryption used for sensitive messages
- [ ] Event signatures verified before processing
- [ ] Relay URLs validated (no injection)
- [ ] NIP-42 auth implemented for private relay
- [ ] No pubkey/npub confusion (proper type safety)
### 4. General Security
- [ ] Input validation on all external data
- [ ] SQL injection prevention (parameterized queries)
- [ ] No command injection in Bash/shell calls
- [ ] Proper error handling (no sensitive data in errors)
- [ ] Rate limiting on API endpoints
- [ ] HTTPS/WSS enforced in production
### 5. Rust-specific (HAL)
- [ ] No `unsafe` blocks without justification
- [ ] Error handling with Result, no unwrap() in production
- [ ] Buffer bounds checking for serial communication
- [ ] Proper lifetime management
### 6. TypeScript-specific
- [ ] Strict null checks honored
- [ ] No `any` types
- [ ] Zod validation on external data
- [ ] No eval() or dynamic code execution
## Output Format
```markdown
## Security Review: [target]
### Critical Issues
- [ ] Issue description with file:line reference
### High Priority
- [ ] Issue description with file:line reference
### Medium Priority
- [ ] Issue description with file:line reference
### Low Priority / Suggestions
- [ ] Suggestion with rationale
### Passed Checks
- [x] Check that passed
```
## Example Usage
```
/security packages/lightning/src/client.ts
```
Output:
```markdown
## Security Review: packages/lightning/src/client.ts
### Critical Issues
None found.
### High Priority
- [ ] `client.ts:45` - Invoice amount not validated before `payInvoice()` call
### Medium Priority
- [ ] `client.ts:78` - Error message includes full stack trace, may leak internal paths
### Passed Checks
- [x] Private keys not exposed in logs
- [x] NIP-44 encryption used for DMs
- [x] Proper TypeScript strict mode
```