All skills
jeffallan avatar

/fullstack-guardian

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Builds security-focused full-stack web applications by implementing integrated frontend and backend components with layered security at every level. Covers the complete stack from database to UI, enforcing auth, input validation, output encoding, and parameterized queries across all layers. Use when implementing features across frontend and backend, building REST APIs with corresponding UI, connecting frontend components to backend endpoints, creating end-to-end data flows from database to UI, or implementing CRUD operations with UI forms. Distinct from frontend-only, backend-only, or API-only skills in that it simultaneously addresses all three perspectives—Frontend, Backend, and Security—within a single implementation workflow. Invoke for full-stack feature work, web app development, authenticated API routes with views, microservices, real-time features, monorepo architecture, or technology selection decisions.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/fullstack-guardian

This session only. Nothing lands on disk.

referencessecurity-checklist.md

≈634 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Checklist

Per-Feature Security Checklist

Category Check Action
Auth Endpoint requires authentication? Add auth middleware/guard
Authz User authorized for this action? Check ownership/role
Input All input validated and sanitized? Use schemas, sanitize
Output Sensitive data excluded from response? Filter response fields
Rate Limit Endpoint rate limited? Add rate limiter
Logging Security events logged? Log auth failures, changes

Authentication Patterns

// NestJS Guard
@UseGuards(JwtAuthGuard)
@Get('profile')
async getProfile(@CurrentUser() user: User) {
  return this.userService.findById(user.id);
}

// Express Middleware
app.get('/profile', authenticate, (req, res) => {
  res.json(req.user);
});
# FastAPI Dependency
@router.get("/profile")
async def get_profile(current_user: User = Depends(get_current_user)):
    return current_user

Authorization Patterns

// Resource ownership check
async updatePost(postId: string, userId: string, data: UpdatePostDto) {
  const post = await this.postRepo.findById(postId);

  if (post.authorId !== userId) {
    throw new ForbiddenException('Not authorized to edit this post');
  }

  return this.postRepo.update(postId, data);
}

// Role-based check
@Roles('admin')
@UseGuards(RolesGuard)
@Delete(':id')
async deleteUser(@Param('id') id: string) {
  return this.userService.delete(id);
}

Input Validation

// Zod schema
const CreateUserSchema = z.object({
  email: z.string().email(),
  name: z.string().min(1).max(100),
  password: z.string().min(12),
});

// Use in endpoint
const validated = CreateUserSchema.parse(req.body);
# Pydantic model
class CreateUser(BaseModel):
    email: EmailStr
    name: str = Field(min_length=1, max_length=100)
    password: str = Field(min_length=12)

Rate Limiting

// Express rate-limit
import rateLimit from 'express-rate-limit';

const authLimiter = rateLimit({
  windowMs: 15 * 60 * 1000, // 15 minutes
  max: 5, // 5 attempts
  message: 'Too many login attempts',
});

app.post('/login', authLimiter, loginHandler);

Quick Reference

Risk Mitigation
SQL Injection Parameterized queries
XSS Output encoding, CSP
CSRF CSRF tokens, SameSite cookies
IDOR Authorization checks
Brute Force Rate limiting
Data Exposure Response filtering

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The skill consists exclusively of Markdown documentation and templates for full-stack security guidance, containing no executable code. The automated scan alerts are false positives caused by the presence of security code snippets and terminology.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/11 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.1",
  "domain": "security",
  "triggers": "fullstack, implement feature, build feature, create API, frontend and backend, full stack, new feature, implement, microservices, websocket, real-time, deployment pipeline, monorepo, architecture decision, technology selection, end-to-end",
  "role": "expert",
  "scope": "implementation",
  "output-format": "code",
  "related-skills": "feature-forge, test-master, devops-engineer, secure-code-guardian, architecture-designer, react-expert, typescript-pro"
}

README badge

README badge for jeffallan/claude-skills/fullstack-guardian