All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulesinsecure-design.md

≈977 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Insecure Design

Check for security anti-patterns and flaws in application architecture that can't be fixed by implementation alone.

Why

  • Fundamental flaws: Can't be patched, require redesign
  • Business logic bypass: Attackers exploit workflow flaws
  • Privilege escalation: Design allows unauthorized access
  • Data corruption: Race conditions and logic errors

What to Check

Vulnerability Indicators:

  • Security by obscurity instead of proper access control
  • Missing rate limiting on expensive operations
  • No input validation on business logic
  • Race conditions in multi-step workflows
  • Trust boundaries not defined
  • Missing defense in depth
  • No threat modeling performed

Bad Patterns

// Bad: Security by obscurity
if (req.headers.get("x-admin-secret") === "admin123") {
  // Admin operations
}

// Bad: Race condition in balance check
const balance = await getBalance(from);
if (balance >= amount) {
  // Race: balance could change here!
  await updateBalance(from, balance - amount);
}

// Bad: No rate limiting
async function generateReport(req: Request): Promise<Response> {
  const report = await runExpensiveQuery(); // Can DoS
  return new Response(report);
}

// Bad: Trust user role from client
const { isAdmin } = await req.json();
if (isAdmin) {
  await db.users.delete({ where: { id } }); // User can claim admin!
}

Good Patterns

// Good: Proper RBAC
async function adminEndpoint(req: Request): Promise<Response> {
  let session = await getSession(req);
  let user = await db.users.findUnique({
    where: { id: session.userId },
    select: { role: true },
  });

  if (user.role !== "ADMIN") {
    return new Response("Forbidden", { status: 403 });
  }

  // Admin operations
}

// Good: Transaction for atomic operations
async function transferMoney(from: string, to: string, amount: number) {
  await db.$transaction(async (tx) => {
    let fromAccount = await tx.account.findUnique({
      where: { id: from },
      select: { balance: true },
    });

    if (!fromAccount || fromAccount.balance < amount) {
      throw new Error("Insufficient funds");
    }

    await tx.account.update({
      where: { id: from },
      data: { balance: { decrement: amount } },
    });

    await tx.account.update({
      where: { id: to },
      data: { balance: { increment: amount } },
    });
  });
}

// Good: Rate limiting on expensive operations
async function generateReport(req: Request): Promise<Response> {
  let session = await getSession(req);

  let { success } = await reportLimit.limit(session.userId);
  if (!success) {
    return new Response("Rate limit exceeded", { status: 429 });
  }

  let report = await runExpensiveQuery();
  return new Response(report);
}

// Good: Server-side role verification
async function deleteUser(req: Request): Promise<Response> {
  let session = await getSession(req);

  let user = await db.users.findUnique({
    where: { id: session.userId },
    select: { role: true },
  });

  if (user.role !== "ADMIN") {
    return new Response("Forbidden", { status: 403 });
  }

  let { targetUserId } = await req.json();
  await db.users.delete({ where: { id: targetUserId } });

  return new Response("Deleted");
}

Rules

  1. Don't rely on security by obscurity - Use proper authentication
  2. Use transactions for atomic operations - Prevent race conditions
  3. Rate limit expensive operations - Prevent resource exhaustion
  4. Verify privileges server-side - Never trust client data
  5. Implement defense in depth - Multiple layers of security
  6. Perform threat modeling - Identify risks in design phase
  7. Define trust boundaries - Know what to validate
  8. Fail securely - Default deny, not default allow

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check