All skills
jeffallan avatar

/secure-code-guardian

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/secure-code-guardian

This session only. Nothing lands on disk.

referencesowasp-prevention.md

≈834 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OWASP Top 10 Prevention

OWASP Top 10 Quick Reference

# Vulnerability Prevention
1 Injection Parameterized queries, ORMs
2 Broken Auth Strong passwords, MFA, secure sessions
3 Sensitive Data Encryption at rest/transit
4 XXE Disable DTDs, use JSON
5 Broken Access Deny by default, server-side validation
6 Misconfig Security headers, disable defaults
7 XSS Output encoding, CSP
8 Insecure Deserialization Schema validation, allowlists
9 Known Vulnerabilities Dependency scanning
10 Insufficient Logging Log security events

A01: Injection Prevention

// SQL Injection - Use parameterized queries
// ❌ Bad
const bad = `SELECT * FROM users WHERE id = ${userId}`;

// ✅ Good
const good = await db.query('SELECT * FROM users WHERE id = $1', [userId]);

// ✅ Good - Use ORM
const user = await prisma.user.findUnique({ where: { id: userId } });

// Command Injection - Avoid shell execution
// ❌ Bad
exec(`ls ${userInput}`);

// ✅ Good - Use library functions
const files = fs.readdirSync(safeDirectory);

A02: Broken Authentication

// Use bcrypt for passwords
const hash = await bcrypt.hash(password, 12);
const isValid = await bcrypt.compare(password, hash);

// Implement account lockout
if (failedAttempts >= 5) {
  await lockAccount(userId, 15 * 60 * 1000); // 15 min
}

// Use secure session configuration
app.use(session({
  secret: process.env.SESSION_SECRET,
  cookie: {
    httpOnly: true,
    secure: true,
    sameSite: 'strict',
    maxAge: 15 * 60 * 1000, // 15 minutes
  },
}));

A03: Sensitive Data Exposure

// Encrypt sensitive data at rest
import crypto from 'crypto';

function encrypt(text: string, key: Buffer): string {
  const iv = crypto.randomBytes(16);
  const cipher = crypto.createCipheriv('aes-256-gcm', key, iv);
  // ... encryption logic
}

// Use HTTPS only
app.use((req, res, next) => {
  if (!req.secure) {
    return res.redirect(`https://${req.hostname}${req.url}`);
  }
  next();
});

A05: Broken Access Control

// Always validate on server side
async function getResource(userId: string, resourceId: string) {
  const resource = await db.resource.findUnique({ where: { id: resourceId } });

  // Verify ownership
  if (resource.ownerId !== userId) {
    throw new ForbiddenError('Access denied');
  }

  return resource;
}

// Use role-based access
function requireRole(...roles: string[]) {
  return (req: Request, res: Response, next: NextFunction) => {
    if (!roles.includes(req.user.role)) {
      return res.status(403).json({ error: 'Forbidden' });
    }
    next();
  };
}

A07: XSS Prevention

// Use Content Security Policy
app.use(helmet.contentSecurityPolicy({
  directives: {
    defaultSrc: ["'self'"],
    scriptSrc: ["'self'"],
    styleSrc: ["'self'", "'unsafe-inline'"],
  },
}));

// Sanitize user input for HTML
import DOMPurify from 'dompurify';
const clean = DOMPurify.sanitize(userInput);

Quick Reference

Attack Defense
SQL Injection Parameterized queries
XSS Output encoding, CSP
CSRF CSRF tokens
IDOR Authorization checks
Command Injection Avoid exec(), validate input

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    The skill is a comprehensive security reference guide that promotes industry-standard best practices such as parameterized queries, salted password hashing, and strict input validation. Automated scanner detections for the documentation URL and the skill file appear to be false positives triggered by the inclusion of standard attack strings used for educational demonstration and security validation checkpoints. The skill's content is defensive in nature and follows established secure coding guidelines.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    2/6 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 82/100

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "security",
  "triggers": "security, authentication, authorization, encryption, OWASP, vulnerability, secure coding, password, JWT, OAuth",
  "role": "specialist",
  "scope": "implementation",
  "output-format": "code",
  "related-skills": "fullstack-guardian, security-reviewer, architecture-designer"
}

README badge

README badge for jeffallan/claude-skills/secure-code-guardian