All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulessecurity-headers.md

≈874 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Headers

Check for proper HTTP security headers that protect against XSS, clickjacking, MIME sniffing, and downgrade attacks.

Related: XSS input validation in injection-attacks.md. CORS in cors-configuration.md.

Why

  • XSS protection: CSP prevents script injection
  • Clickjacking prevention: X-Frame-Options stops iframe embedding
  • HTTPS enforcement: HSTS ensures encrypted connections
  • MIME sniffing attacks: X-Content-Type-Options prevents content confusion
  • Information leakage: Referrer-Policy controls referrer data

What to Check

  • Missing Content-Security-Policy header
  • Missing Strict-Transport-Security (HSTS)
  • Missing X-Frame-Options
  • Missing X-Content-Type-Options
  • Overly permissive CSP (unsafe-inline, unsafe-eval)
  • No Permissions-Policy
  • Missing Referrer-Policy

Bad Patterns

// Bad: No security headers
async function handler(req: Request): Promise<Response> {
  let html = "<html><body>Hello</body></html>";

  // VULNERABLE: Missing all security headers
  return new Response(html, {
    headers: { "Content-Type": "text/html" },
  });
}

// Bad: Permissive CSP
const headers = {
  // VULNERABLE: unsafe-inline allows XSS
  "Content-Security-Policy": "default-src * 'unsafe-inline' 'unsafe-eval'",
};

Good Patterns

// Good: Comprehensive security headers
function getSecurityHeaders(): Record<string, string> {
  return {
    "Content-Security-Policy": [
      "default-src 'self'",
      "script-src 'self'",
      "style-src 'self' 'unsafe-inline'",
      "img-src 'self' data: https:",
      "font-src 'self'",
      "connect-src 'self'",
      "frame-ancestors 'none'",
      "base-uri 'self'",
      "form-action 'self'",
    ].join("; "),
    "X-Frame-Options": "DENY",
    "Strict-Transport-Security": "max-age=31536000; includeSubDomains; preload",
    "X-Content-Type-Options": "nosniff",
    "Referrer-Policy": "strict-origin-when-cross-origin",
    "Permissions-Policy": "camera=(), microphone=(), geolocation=()",
  };
}

async function handler(req: Request): Promise<Response> {
  let html = "<html><body>Hello</body></html>";

  return new Response(html, {
    headers: {
      "Content-Type": "text/html",
      ...getSecurityHeaders(),
    },
  });
}

// Good: CSP with nonces for inline scripts
async function renderPage(req: Request): Promise<Response> {
  let nonce = crypto.randomBytes(16).toString("base64");

  let html = `
    <!DOCTYPE html>
    <html>
      <head>
        <script nonce="${nonce}">
          console.log('This script is allowed');
        </script>
      </head>
      <body>Content</body>
    </html>
  `;

  return new Response(html, {
    headers: {
      "Content-Type": "text/html",
      "Content-Security-Policy": `default-src 'self'; script-src 'self' 'nonce-${nonce}'`,
    },
  });
}

Rules

  1. Always set CSP - Strict policy without unsafe-inline/unsafe-eval
  2. Enable HSTS - Minimum 1 year, include subdomains
  3. Set X-Frame-Options - Use DENY or SAMEORIGIN
  4. Set X-Content-Type-Options - Always nosniff
  5. Configure Referrer-Policy - strict-origin-when-cross-origin
  6. Use nonces for inline scripts - When inline scripts are needed
  7. Set Permissions-Policy - Restrict unnecessary browser features

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check