All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulessecurity-misconfiguration.md

≈749 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Misconfiguration

Check for insecure default configurations, unnecessary features enabled, verbose error messages, and missing security patches.

Why

  • Information disclosure: Verbose errors reveal system details
  • Unauthorized access: Default credentials still active
  • Attack surface: Unnecessary features expose vulnerabilities
  • Known vulnerabilities: Outdated software with public exploits

What to Check

Vulnerability Indicators:

  • Debug mode enabled in production
  • Default credentials not changed
  • Unnecessary features/endpoints enabled
  • Detailed error messages in production
  • Directory listing enabled
  • Outdated dependencies
  • Missing security patches

Bad Patterns

// Bad: Debug mode in production
const DEBUG = true; // Should be from env
if (DEBUG) {
  console.log("Detailed system info:", process.env);
}

// Bad: Verbose error messages
catch (error) {
  return Response.json({
    error: error.message,
    stack: error.stack,
    query: sqlQuery,
    env: process.env
  }, { status: 500 });
}

// Bad: Default credentials
const ADMIN_PASSWORD = "admin123";

// Bad: Unnecessary admin endpoints exposed
async function debugInfo(req: Request): Promise<Response> {
  return Response.json({
    env: process.env,
    config: appConfig,
    routes: allRoutes
  });
}

Good Patterns

// Good: Environment-aware configuration
const isProduction = process.env.NODE_ENV === "production";

const config = {
  debug: !isProduction,
  logLevel: isProduction ? "error" : "debug",
  errorDetails: !isProduction
};

// Good: Generic error messages in production
catch (error) {
  console.error("Error:", error);

  let message = isProduction
    ? "An error occurred"
    : error.message;

  return Response.json({ error: message }, { status: 500 });
}

// Good: Strong credentials from environment
const ADMIN_PASSWORD = process.env.ADMIN_PASSWORD;
if (!ADMIN_PASSWORD || ADMIN_PASSWORD.length < 20) {
  throw new Error("ADMIN_PASSWORD must be set and strong");
}

// Good: Disable debug endpoints in production
async function debugInfo(req: Request): Promise<Response> {
  if (process.env.NODE_ENV === "production") {
    return new Response("Not found", { status: 404 });
  }

  return Response.json({ routes: publicRoutes });
}

Rules

  1. Disable debug mode in production - No verbose logging or errors
  2. Change default credentials - Require strong passwords
  3. Disable unnecessary features - Minimize attack surface
  4. Generic error messages - Don't reveal system details
  5. Keep dependencies updated - Regularly patch vulnerabilities
  6. Remove development endpoints - No debug/admin routes in production
  7. Secure default configurations - Fail securely by default
  8. Regular security audits - npm audit, dependency checks

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check