All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulesapi-security.md

≈952 tokens on demand. Your agent reads this file only when SKILL.md points to it.

REST API Security

Check for REST API vulnerabilities including mass assignment, lack of validation, and missing resource limits.

Related: Input validation in injection-attacks.md. Authentication in authentication-failures.md. Rate limiting in rate-limiting.md.

Why

  • Mass assignment: Users modify protected fields
  • Over-fetching: Expose unnecessary data
  • Resource exhaustion: Unlimited result sets
  • API abuse: Missing versioning and documentation

What to Check

  • Mass assignment in update operations
  • No pagination on list endpoints
  • Missing Content-Type validation
  • No API versioning
  • Excessive data in responses
  • Missing rate limits

Bad Patterns

// Bad: Mass assignment
async function updateUser(req: Request): Promise<Response> {
  let session = await getSession(req);
  let data = await req.json();

  // VULNERABLE: User can set isAdmin, role, etc.!
  await db.users.update({
    where: { id: session.userId },
    data, // Dangerous - accepts all fields!
  });

  return new Response("Updated");
}

// Bad: No pagination
async function getUsers(req: Request): Promise<Response> {
  // VULNERABLE: Could return millions of records
  let users = await db.users.findMany();

  return Response.json(users);
}

// Bad: No input validation
async function createPost(req: Request): Promise<Response> {
  let data = await req.json();

  // VULNERABLE: No validation of data types or values
  await db.posts.create({ data });

  return new Response("Created", { status: 201 });
}

Good Patterns

// Good: Explicit field allowlist
async function updateUser(req: Request): Promise<Response> {
  let session = await getSession(req);
  let body = await req.json();

  let allowedFields = {
    displayName: body.displayName,
    bio: body.bio,
    avatar: body.avatar,
  };

  if (
    allowedFields.displayName &&
    typeof allowedFields.displayName !== "string"
  ) {
    return new Response("Invalid displayName", { status: 400 });
  }

  await db.users.update({
    where: { id: session.userId },
    data: allowedFields,
  });

  return new Response("Updated");
}

// Good: Pagination with limits
async function getUsers(req: Request): Promise<Response> {
  let url = new URL(req.url);
  let page = parseInt(url.searchParams.get("page") || "1");
  let limit = Math.min(parseInt(url.searchParams.get("limit") || "20"), 100);

  let users = await db.users.findMany({
    take: limit,
    skip: (page - 1) * limit,
  });

  return Response.json({ data: users, page, limit });
}

// Good: Input validation
async function createPost(req: Request): Promise<Response> {
  let session = await getSession(req);
  let body = await req.json();

  if (
    !body.title ||
    typeof body.title !== "string" ||
    body.title.length > 200
  ) {
    return new Response("Invalid title", { status: 400 });
  }

  if (
    !body.content ||
    typeof body.content !== "string" ||
    body.content.length > 50000
  ) {
    return new Response("Invalid content", { status: 400 });
  }

  await db.posts.create({
    data: {
      title: body.title,
      content: body.content,
      authorId: session.userId,
    },
  });

  return new Response("Created", { status: 201 });
}

Rules

  1. Prevent mass assignment - Explicitly define allowed fields
  2. Always paginate lists - Enforce maximum page size
  3. Validate input types - Check types and constraints
  4. Version your API - Use /api/v1/ prefix for versioning
  5. Limit response data - Return only necessary fields
  6. Validate Content-Type - Ensure correct headers

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check