Skip to main content
Run any Skill in Manus
with one click

web-security-baseline

Stars6
Forks1
UpdatedJune 8, 2026 at 19:57

OWASP Top 10 (web, not agentic) baseline review for any web application code change — auth, sessions, headers, CSRF, XSS, SQL injection, CORS, rate limits, secret handling, file upload, SSRF. Use this skill on any PR or diff that touches HTTP handlers, auth flows, session/cookie logic, file uploads, redirect/URL parsing, database queries with user input, or proxying/fetching external URLs. Catches the bug classes that ship to production and become public CVEs. Distinct from the security-auditor agent (which is invoked explicitly); this skill auto-triggers when relevant code is in scope.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly