All skills
sergiodxa avatar

/owasp-security-check

@40e21b4

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

Use this Skill: https://skilld.dev/gh/sergiodxa/agent-skills/owasp-security-check

This session only. Nothing lands on disk.

rulesvulnerable-dependencies.md

≈747 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Vulnerable and Outdated Dependencies

Check for outdated packages with known security vulnerabilities and supply chain risks.

Why

  • Known exploits: Public CVEs make attacks easy
  • Supply chain attacks: Compromised packages
  • Transitive dependencies: Vulnerabilities deep in dependency tree
  • Maintenance risk: Unmaintained packages won't get patches

What to Check

  • Dependencies with known CVEs or security advisories
  • Severely outdated packages (major versions behind current)
  • Packages without recent updates (abandoned/unmaintained)
  • Missing dependency lockfiles
  • Wildcard or loose version constraints in production
  • Unused dependencies bloating the project
  • Development dependencies bundled in production builds
  • Transitive vulnerabilities in indirect dependencies

Bad Patterns

// Bad: Wildcard versions allow unexpected updates
// package.json
{
  "dependencies": {
    "express": "*",           // Any version can be installed
    "react": "^18.0.0"        // Minor/patch versions can change
  }
}

// Bad: No lockfile means versions drift between installs
// Missing: package-lock.json, yarn.lock, pnpm-lock.yaml, etc.

// Bad: Dev dependencies mixed with production
{
  "dependencies": {
    "express": "4.18.2",
    "jest": "29.5.0",         // Should be devDependency
    "eslint": "8.40.0"        // Should be devDependency
  }
}

Good Patterns

// Good: Pinned versions with lockfile
{
  "dependencies": {
    "express": "4.18.2",      // Exact version pinned
    "react": "18.2.0"
  },
  "devDependencies": {
    "jest": "29.5.0",
    "eslint": "8.40.0"
  }
}
// Plus: Lockfile committed (package-lock.json, yarn.lock, etc.)

// Good: Regular dependency audits in CI/CD
// .github/workflows/security.yml
```yaml
name: Security Audit
on: [push, pull_request]
jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - run: npm audit --production  # Or: pip-audit, bundle audit, etc.

Before installing new packages:

  • Check package age and download stats
  • Review maintainer history
  • Scan for known vulnerabilities
  • Verify package scope matches intent (avoid typosquatting)

Rules

  1. Always use lockfiles - Commit dependency lockfiles for reproducible builds
  2. Pin production versions - Use exact versions for production dependencies
  3. Audit regularly - Run security audits in CI/CD and before deployments
  4. Keep dependencies updated - Use automated update tools
  5. Separate dev dependencies - Keep development tools separate from production
  6. Remove unused packages - Regularly clean up unused dependencies
  7. Review before adding - Check package age, maintainers, and reputation
  8. Monitor advisories - Subscribe to security advisories for critical dependencies

Source: SKILL.md on GitHub

2 warnings15d5 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    The skill is a comprehensive security audit guide based on OWASP standards. It provides examples of vulnerable and secure code patterns for pedagogical use. The only identified risk is the inherent surface for indirect prompt injection when the agent processes untrusted user-provided code, although the skill lacks dangerous autonomous capabilities.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    21/21 files flagged

  • ZeroLeaks5mo

    3 findings · Score: 69/100

Signed by skilld at 40e21b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Dormantupdated 8 months ago

README badge

README badge for sergiodxa/agent-skills/owasp-security-check