All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulessecrets-management.md

≈839 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Secrets Management

Check for hardcoded secrets, exposed API keys, and improper credential management.

Related: Encryption key management in cryptographic-failures.md. Sensitive data exposure in sensitive-data-exposure.md.

Why

  • Credential exposure: API keys in code can be stolen
  • Repository leaks: Committed secrets in Git history
  • Unauthorized access: Exposed keys grant system access
  • Compliance violations: Regulations require secret protection

What to Check

  • Hardcoded API keys, passwords, tokens in code
  • Secrets committed to version control
  • .env files committed to repository
  • API keys in client-side code
  • Secrets in logs or error messages
  • No secret rotation policy

Bad Patterns

// Bad: Hardcoded API key
const STRIPE_SECRET_KEY = "sk_live_51H..."; // VULNERABLE!

// Bad: Hardcoded database password
const db = createConnection({
  host: "localhost",
  user: "admin",
  password: "SuperSecret123!" // VULNERABLE!
});

// Bad: Secret in client-side code
const config = {
  apiKey: "AIzaSyB..." // VULNERABLE: Exposed in browser
};

// Bad: .env file committed to Git
// .env (in repository) - VULNERABLE!
DATABASE_URL=postgresql://user:password@localhost/db
API_SECRET=my-secret-key

// Bad: Logging secrets
console.log("Connecting with API key:", process.env.API_KEY);

Good Patterns

// Good: Use environment variables
const STRIPE_SECRET_KEY = process.env.STRIPE_SECRET_KEY;

if (!STRIPE_SECRET_KEY) {
  throw new Error("STRIPE_SECRET_KEY not set");
}

// Good: Validate env vars at startup
function validateEnv() {
  let required = ["DATABASE_URL", "JWT_SECRET", "STRIPE_SECRET_KEY"];
  let missing = required.filter((key) => !process.env[key]);
  if (missing.length > 0) {
    throw new Error(`Missing env vars: ${missing.join(", ")}`);
  }
}

// Good: Add .env to .gitignore (never commit secrets)
// Good: Provide .env.example for documentation (safe to commit)

// Good: Secret rotation
async function rotateApiKey(userId: string) {
  let newKey = crypto.randomBytes(32).toString("hex");
  await db.apiKeys.create({
    data: {
      userId,
      key: newKey,
      expiresAt: new Date(Date.now() + 90 * 24 * 60 * 60 * 1000),
    },
  });
  return newKey;
}

// Good: Use secret management service
async function getSecret(name: string): Promise<string> {
  if (process.env.NODE_ENV === "production") {
    return await secretsManager.getSecretValue(name);
  }
  let value = process.env[name];
  if (!value) throw new Error(`Secret ${name} not found`);
  return value;
}

Rules

  1. Never hardcode secrets - Use environment variables or secret managers
  2. Add .env to .gitignore - Never commit secret files
  3. Rotate secrets regularly - Implement expiration and rotation
  4. Validate env vars at startup - Fail fast if secrets missing
  5. Don't log secrets - Sanitize logs to remove sensitive values
  6. No secrets in client code - Keep API keys server-side only
  7. Use secret management services - For production (AWS Secrets Manager, Vault, etc.)
  8. Scan Git history - Use tools to find accidentally committed secrets

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check