All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulesdata-integrity-failures.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Software and Data Integrity Failures

Check for unsigned data, insecure deserialization, and lack of integrity verification in code and data.

Related: JWT signing in cryptographic-failures.md and session-security.md. Dependency integrity in vulnerable-dependencies.md.

Why

  • Data tampering: Attackers modify unsigned data
  • Remote code execution: Insecure deserialization exploits
  • Supply chain attacks: Unsigned packages or builds
  • Trust violations: Cannot verify data authenticity

What to Check

  • JWT tokens decoded without signature verification
  • Accepting unsigned or unverified data
  • Insecure deserialization of user input
  • No integrity checks on file downloads
  • Missing code signing in CI/CD
  • Auto-update without verification
  • Using eval() or Function() with external data

Bad Patterns

// Bad: No signature verification
async function handleWebhook(req: Request): Promise<Response> {
  const payload = await req.json();
  // Trusting payload without verification!
  await processOrder(payload);
}

// Bad: JWT without verification
async function getUser(req: Request): Promise<Response> {
  let token = req.headers.get("authorization")?.split(" ")[1];
  let payload = JSON.parse(atob(token!.split(".")[1])); // Just decode!
  // Attacker can modify payload
  return Response.json({ userId: payload.sub });
}

// Bad: No integrity check on downloads
async function downloadUpdate(req: Request): Promise<Response> {
  let file = await fetch("https://cdn.example.com/update.zip");
  // No checksum verification
  return new Response(file.body);
}

Good Patterns

// Good: Verify webhook signature
async function handleWebhook(req: Request): Promise<Response> {
  let signature = req.headers.get("x-webhook-signature");
  let payload = await req.text();

  let expected = crypto
    .createHmac("sha256", process.env.WEBHOOK_SECRET!)
    .update(payload)
    .digest("hex");

  if (signature !== expected) {
    return new Response("Invalid signature", { status: 401 });
  }

  await processOrder(JSON.parse(payload));
  return new Response("OK");
}

// Good: Verify JWT signature
async function getUser(req: Request): Promise<Response> {
  let token = req.headers.get("authorization")?.split(" ")[1];

  if (!token) {
    return new Response("Unauthorized", { status: 401 });
  }

  let payload = await verifyJWT(token, process.env.JWT_SECRET!);

  let user = await db.users.findUnique({
    where: { id: payload.sub },
  });

  return Response.json(user);
}

// Good: Verify file integrity with checksum
async function downloadUpdate(req: Request): Promise<Response> {
  let file = await fetch("https://cdn.example.com/update.zip");
  let buffer = await file.arrayBuffer();

  let hash = crypto
    .createHash("sha256")
    .update(Buffer.from(buffer))
    .digest("hex");
  let expected = "a1b2c3d4..."; // From trusted source

  if (hash !== expected) {
    return new Response("Integrity check failed", { status: 400 });
  }

  return new Response(buffer);
}

// Good: Signed cookies
function signCookie(value: string, secret: string): string {
  let sig = crypto.createHmac("sha256", secret).update(value).digest("hex");
  return `${value}.${sig}`;
}

function verifyCookie(signedValue: string, secret: string): string | null {
  let [value, signature] = signedValue.split(".");
  let expected = crypto
    .createHmac("sha256", secret)
    .update(value)
    .digest("hex");
  return signature === expected ? value : null;
}

Rules

  1. Always verify JWT signatures - Never decode without verification
  2. Never trust client data - Look up prices, roles, permissions server-side
  3. Use JSON.parse, never eval - Safe deserialization only
  4. Use Subresource Integrity - For all CDN-loaded scripts/styles
  5. Sign cookies - Use HMAC for tamper detection
  6. Verify checksums - For downloaded code and updates
  7. Lock dependency versions - Use lockfiles to ensure integrity
  8. Sign code in CI/CD - Verify builds haven't been tampered with

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check