All skills
grasmash avatar

/ivangrynenko-cursorrules-drupal

@76e6435

Drupal development and security patterns from Ivan Grynenko's cursor rules. Covers OWASP Top 10, authentication, access control, injection prevention, cryptography, configuration, database standards, file permissions, and more.

Use this Skill: https://skilld.dev/gh/grasmash/drupal-claude-skills/ivangrynenko-cursorrules-drupal

This session only. Nothing lands on disk.

referencesdependency-security.md

≈1.7k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Drupal Vulnerable and Outdated Components Standards (OWASP A06:2021)

Source: Ivan Grynenko - drupal-vulnerable-components.mdc Author: Ivan Grynenko License: MIT OWASP Reference: OWASP A06:2021


Full Documentation

View online: https://github.com/ivangrynenko/cursorrules/blob/main/.cursor/rules/drupal-vulnerable-components.mdc

This security pattern covers:

  • OWASP Top 10 classification
  • Common vulnerabilities and anti-patterns
  • Enforcement checks for code review
  • Secure coding examples
  • Best practices and remediation

Raw Content

---
description: Detect and prevent vulnerabilities related to outdated or vulnerable components in Drupal as defined in OWASP Top 10:2021-A06
globs: *.php, *.install, *.module, *.inc, *.theme, *.yml, *.info
alwaysApply: false
---
# Drupal Vulnerable and Outdated Components Standards (OWASP A06:2021)

This rule enforces security best practices to prevent vulnerabilities related to outdated or vulnerable components in Drupal applications, as defined in OWASP Top 10:2021-A06.

## Rule Details

- **Name:** drupal_vulnerable_components

- **Description:** Detect and prevent vulnerabilities related to outdated or vulnerable components in Drupal as defined in OWASP Top 10:2021-A06

## Filters
- file extension pattern: `\\.(php|inc|module|install|info\\.yml|json)$`
- file path pattern: `.*`

## Enforcement Checks
- Conditions:
  - pattern `core:\\s*('|\")8\\.[0-6](mdc:'|\")|core_version_requirement:\\s*('|\")[^9].+('|\")` – Potentially outdated Drupal core version detected. Consider upgrading to the latest secure version of Drupal 9 or 10.
    - Pattern 1: Outdated Drupal core version declaration
  - pattern `drupal_set_message\\(|format_date\\(|drupal_render\\(|entity_load\\(|variable_get\\(|variable_set\\(` – Deprecated function detected. Use modern replacements to ensure compatibility and security updates.
    - Pattern 2: Usage of deprecated functions
  - pattern `jquery\\.min\\.js\\?v=1\\.|jquery-1\\.|jquery-2\\.|ckeditor/|tinymce/|angular\\.js@1\\.` – Potentially vulnerable JavaScript library version detected. Update to the latest secure version.
    - Pattern 3: Known vulnerable libraries referenced
  - pattern `<script\\s+src=['\"]http|<script\\s+src=['\"]//|<link\\s+[^>]*href=['\"]http` – External scripts or stylesheets without Subresource Integrity (SRI) checks detected. Add integrity and crossorigin attributes.
    - Pattern 4: Direct inclusion of external scripts without SRI
  - pattern `module:\\s*('[^']*captcha'|'recaptcha'|'xmlrpc'|'openid'|'php')` – Potentially vulnerable or deprecated module detected. Consider using more secure alternatives.
    - Pattern 5: Use of obsolete or removed modules
  - pattern `\"drupal/[^\"]+\":\\s*\"(~|\\^)?[0-9]\\.[0-9]\\.[0-9]\"` – Hard-coded specific version detected in composer.json. Consider using version ranges to receive security updates.
    - Pattern 6: Hard-coded versions in composer.json
  - pattern `mysql_|split\\(|ereg\\(|eregi\\(|create_function\\(|each\\(` – Deprecated or insecure PHP function detected. Use modern alternatives for better security.
    - Pattern 7: Outdated or insecure PHP API usage
  - pattern `type:\\s*module\\s*\\nname:` – Ensure your module specifies core_version_requirement to prevent installation on unsupported Drupal versions.
    - Pattern 8: Usage of contrib modules without version constraints
  - pattern `composer\\.json` – Consider adding drupal/core-security-advisories as a dev dependency to detect known vulnerable packages.
    - Pattern 9: Missing security advisories handling in composer.json
  - pattern `check_plain\\(|filter_xss\\(|filter_xss_admin\\(` – Legacy text sanitization function detected. Use Html::escape() or Xss::filter() instead.
    - Pattern 10: Direct usage of vulnerable sanitization functions

## Suggestions
- Guidance:
**Drupal Component Security Best Practices:**

1. **Update Management:**
   - Keep Drupal core updated to the latest secure version
   - Subscribe to the Drupal Security Newsletter
   - Implement a regular update schedule (monthly at minimum)
   - Use security advisories checking in your development workflow
   - Implement Composer's security-advisories metadata

2. **Dependency Management:**
   - Use Composer for managing all dependencies
   - Specify version constraints that allow security updates
   - Add drupal/core-security-advisories as a dev dependency
   - Regularly run `composer update --with-dependencies`
   - Use `composer outdated` to identify outdated packages

3. **API Usage:**
   - Use modern Drupal APIs rather than deprecated functions
   - Migrate away from jQuery to modern JavaScript where possible
   - Implement Subresource Integrity (SRI) for external resources
   - Update custom code to use current best practices
   - Follow the Drupal API deprecation policies

4. **Security Monitoring:**
   - Implement automated vulnerability scanning in CI/CD
   - Use tools like Drupal Check or Upgrade Status module
   - Monitor the Drupal security advisories page
   - Implement automated updates for non-critical dependencies
   - Set up alerts for security issues in used components

5. **Module Management:**
   - Remove unused modules from your codebase
   - Prefer well-maintained modules with security teams
   - Implement proper version constraints in module info files
   - Consider the security impact before adding new dependencies
   - Document your dependency management practices

## Validation Checks
- Conditions:
  - pattern `core_version_requirement:\\s*[\"']\\^(8\\.8|8\\.9|9|10)\\.[0-9]+[\"']` – Using proper core version requirements.
    - Check 1: Proper core version requirement
  - pattern `\\\\Drupal::messenger\\(\\)|->messenger\\(\\)|\\\\Drupal::service\\('messenger'\\)` – Using modern message API instead of deprecated functions.
    - Check 2: Use of modern APIs
  - pattern `\"require\":\\s*\\{[^}]*\"drupal/core(-recommended)?\":\\s*\"\\^[0-9]+\\.[0-9]+\"` – Using proper version constraints in Composer.
    - Check 3: Proper composer usage
  - pattern `integrity=[\"'][a-zA-Z0-9\\+/=\\-_]+[\"']\\s+crossorigin=[\"']anonymous[\"']` – Properly implementing Subresource Integrity.
    - Check 4: SRI implementation

## Metadata
- Priority: high
- Version: 1.1
- Tags: security, drupal, dependencies, vulnerable-components, owasp, language:php, framework:drupal, category:security, subcategory:dependencies, standard:owasp-top10, risk:a06-vulnerable-components
## References
- https://owasp.org/Top10/A06_2021-Vulnerable_and_Outdated_Components/
- https://www.drupal.org/docs/security-in-drupal/staying-up-to-date
- https://www.drupal.org/docs/upgrading-drupal
- https://www.drupal.org/docs/develop/using-composer/managing-dependencies-for-a-drupal-project

 


Last verified: 2025-10-31

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive suite of security auditing rules for Drupal development, modeled after OWASP Top 10 guidelines. It serves as a defensive tool to help AI agents identify and remediate common vulnerabilities such as SQL injection, broken access control, and insecure configurations. No malicious patterns or safety risks were identified within the skill instructions or scripts.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 76e6435. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago

README badge

README badge for grasmash/drupal-claude-skills/ivangrynenko-cursorrules-drupal