Review LitRev backend trust boundaries for security findings using repo-owned backend and admin contracts. Advisory only and non-blocking. Use for auth, platform-admin, uploads/storage, route/API/server-action, and backend validation reviews.
Perform a focused, evidence-backed security review of LitRev backend trust boundaries.
This skill is advisory only. It complements tests, typecheck, release gates, and normal code review.
Before reviewing, read:
AGENTS.mddocs/plans/plan-backend.mddocs/runbooks/admin-access.mddocs/reviews/repo-health.mdIf the review touches DB semantics or migration-driven access controls, also read:
docs/runbooks/db-architecture.mddocs/runbooks/db-ops.mdlitrev-runtime-boundary-review instead.cursed-lite-* instead.docs/runbooks/external-pattern-intake.md.ownerId, workspaceId, project access, admin-only guards).env filesReturn markdown in this order:
plan-backend.mdIf no findings are discovered, say so explicitly and note any residual testing or review gaps.
.env, .env.*, credentials, tokens, or private keys.End with:
Advisory only: promote repeated security findings into tests, rules, runbooks, or owner-plan updates.