Skip to main content
security-review Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Zur Installation springen Skills Marktplatz Entdecken und erkunden Sie KI-Skills, die von der Community erstellt wurden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Prompt kopierenPrompt-Details anzeigen Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
npx skills add https://github.com/davila7/claude-code-templates --skill security-reviewDer Befehl bleibt in einer Zeile. Scrollen Sie horizontal, um ihn vor dem Kopieren vollständig zu prüfen.
Sie bevorzugen eine lokale Kopie? Laden Sie die Dateien herunter, die SkillsMP derzeit vorliegen.
ZIP herunterladen Herunterladen... Mehr aus diesem Repository Build AI agents that interact with computers like humans do - viewing screens, moving cursors, clicking buttons, and typing text. Covers Anthropic's Computer Use, OpenAI's Operator/CUA, and open-source alternatives. Critical focus on sandboxing, security, and handling the unique challenges of vision-based control. Use when: computer use, desktop automation agent, screen control AI, vision-based agent, GUI automation.
Expert in building products that wrap AI APIs (OpenAI, Anthropic, etc.) into focused tools people will pay for. Not just 'ChatGPT but different' - products that solve specific problems with AI. Covers prompt engineering for products, cost management, rate limiting, and building defensible AI businesses. Use when: AI wrapper, GPT product, AI tool, wrap AI, AI SaaS.
github-workflow-automation Automate GitHub workflows with AI assistance. Includes PR reviews, issue triage, CI/CD integration, and Git operations. Use when automating GitHub workflows, setting up PR review automation, creating GitHub Actions, or triaging issues.
Verwandte Berufe SOC
Basierend auf der SOC-Berufsklassifikation
name security-review description Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns. author affaan-m version 1.0
Security Review Skill
This skill ensures all code follows security best practices and identifies potential vulnerabilities.
When to Activate
Implementing authentication or authorization
Handling user input or file uploads
Creating new API endpoints
Working with secrets or credentials
Implementing payment features
Storing or transmitting sensitive data
Integrating third-party APIs
Security Checklist
1. Secrets Management
❌ NEVER Do This
const apiKey = "sk-proj-xxxxx"
const dbPassword = "password123"
✅ ALWAYS Do This
const apiKey = process.env .OPENAI_API_KEY
dbUrl = process. .
(!apiKey) {
( )
}
const
env
DATABASE_URL
if
throw
new
Error
'OPENAI_API_KEY not configured'
Verification Steps
2. Input Validation
Always Validate User Input import { z } from 'zod'
const CreateUserSchema = z.object ({
email : z.string ().email (),
name : z.string ().min (1 ).max (100 ),
age : z.number ().int ().min (0 ).max (150 )
})
export async function createUser (input : unknown ) {
try {
const validated = CreateUserSchema .parse (input)
return await db.users .create (validated)
} catch (error) {
if (error instanceof z.ZodError ) {
return { success : false , errors : error.errors }
}
throw error
}
}
File Upload Validation function validateFileUpload (file : File ) {
const maxSize = 5 * 1024 * 1024
if (file.size > maxSize) {
throw new Error ('File too large (max 5MB)' )
}
const allowedTypes = ['image/jpeg' , 'image/png' , 'image/gif' ]
if (!allowedTypes.includes (file.type )) {
throw new Error ('Invalid file type' )
}
const allowedExtensions = ['.jpg' , '.jpeg' , '.png' , '.gif' ]
const extension = file.name .toLowerCase ().match (/\.[^.]+$/ )?.[0 ]
if (!extension || !allowedExtensions.includes (extension)) {
throw new Error ('Invalid file extension' )
}
return true
}
Verification Steps
3. SQL Injection Prevention
❌ NEVER Concatenate SQL
const query = `SELECT * FROM users WHERE email = '${userEmail} '`
await db.query (query)
✅ ALWAYS Use Parameterized Queries
const { data } = await supabase
.from ('users' )
.select ('*' )
.eq ('email' , userEmail)
await db.query (
'SELECT * FROM users WHERE email = $1' ,
[userEmail]
)
Verification Steps
4. Authentication & Authorization
JWT Token Handling
localStorage .setItem ('token' , token)
res.setHeader ('Set-Cookie' ,
`token=${token} ; HttpOnly; Secure; SameSite=Strict; Max-Age=3600` )
Authorization Checks export async function deleteUser (userId : string , requesterId : string ) {
const requester = await db.users .findUnique ({
where : { id : requesterId }
})
if (requester.role !== 'admin' ) {
return NextResponse .json (
{ error : 'Unauthorized' },
{ status : 403 }
)
}
await db.users .delete ({ where : { id : userId } })
}
Row Level Security (Supabase)
ALTER TABLE users ENABLE ROW LEVEL SECURITY;
CREATE POLICY "Users view own data"
ON users FOR SELECT
USING (auth.uid() = id);
CREATE POLICY "Users update own data"
ON users FOR UPDATE
USING (auth.uid() = id);
Verification Steps
5. XSS Prevention
Sanitize HTML import DOMPurify from 'isomorphic-dompurify'
function renderUserContent (html : string ) {
const clean = DOMPurify .sanitize (html, {
ALLOWED_TAGS : ['b' , 'i' , 'em' , 'strong' , 'p' ],
ALLOWED_ATTR : []
})
return <div dangerouslySetInnerHTML ={{ __html: clean }} />
}
Content Security Policy
const securityHeaders = [
{
key : 'Content-Security-Policy' ,
value : `
default-src 'self';
script-src 'self' 'unsafe-eval' 'unsafe-inline';
style-src 'self' 'unsafe-inline';
img-src 'self' data: https:;
font-src 'self';
connect-src 'self' https://api.example.com;
` .replace (/\s{2,}/g , ' ' ).trim ()
}
]
Verification Steps
6. CSRF Protection
CSRF Tokens import { csrf } from '@/lib/csrf'
export async function POST (request : Request ) {
const token = request.headers .get ('X-CSRF-Token' )
if (!csrf.verify (token)) {
return NextResponse .json (
{ error : 'Invalid CSRF token' },
{ status : 403 }
)
}
}
SameSite Cookies res.setHeader ('Set-Cookie' ,
`session=${sessionId} ; HttpOnly; Secure; SameSite=Strict` )
Verification Steps
7. Rate Limiting
API Rate Limiting import rateLimit from 'express-rate-limit'
const limiter = rateLimit ({
windowMs : 15 * 60 * 1000 ,
max : 100 ,
message : 'Too many requests'
})
app.use ('/api/' , limiter)
Expensive Operations
const searchLimiter = rateLimit ({
windowMs : 60 * 1000 ,
max : 10 ,
message : 'Too many search requests'
})
app.use ('/api/search' , searchLimiter)
Verification Steps
8. Sensitive Data Exposure
Logging
console .log ('User login:' , { email, password })
console .log ('Payment:' , { cardNumber, cvv })
console .log ('User login:' , { email, userId })
console .log ('Payment:' , { last4 : card.last4 , userId })
Error Messages
catch (error) {
return NextResponse .json (
{ error : error.message , stack : error.stack },
{ status : 500 }
)
}
catch (error) {
console .error ('Internal error:' , error)
return NextResponse .json (
{ error : 'An error occurred. Please try again.' },
{ status : 500 }
)
}
Verification Steps
9. Blockchain Security (Solana)
Wallet Verification import { verify } from '@solana/web3.js'
async function verifyWalletOwnership (
publicKey : string ,
signature : string ,
message : string
) {
try {
const isValid = verify (
Buffer .from (message),
Buffer .from (signature, 'base64' ),
Buffer .from (publicKey, 'base64' )
)
return isValid
} catch (error) {
return false
}
}
Transaction Verification async function verifyTransaction (transaction : Transaction ) {
if (transaction.to !== expectedRecipient) {
throw new Error ('Invalid recipient' )
}
if (transaction.amount > maxAmount) {
throw new Error ('Amount exceeds limit' )
}
const balance = await getBalance (transaction.from )
if (balance < transaction.amount ) {
throw new Error ('Insufficient balance' )
}
return true
}
Verification Steps
10. Dependency Security
Regular Updates
npm audit
npm audit fix
npm update
npm outdated
Lock Files
git add package-lock.json
npm ci
Verification Steps
Security Testing
Automated Security Tests
test ('requires authentication' , async () => {
const response = await fetch ('/api/protected' )
expect (response.status ).toBe (401 )
})
test ('requires admin role' , async () => {
const response = await fetch ('/api/admin' , {
headers : { Authorization : `Bearer ${userToken} ` }
})
expect (response.status ).toBe (403 )
})
test ('rejects invalid input' , async () => {
const response = await fetch ('/api/users' , {
method : 'POST' ,
body : JSON .stringify ({ email : 'not-an-email' })
})
expect (response.status ).toBe (400 )
})
test ('enforces rate limits' , async () => {
const requests = Array (101 ).fill (null ).map (() =>
fetch ('/api/endpoint' )
)
const responses = await Promise .all (requests)
const tooManyRequests = responses.filter (r => r.status === 429 )
expect (tooManyRequests.length ).toBeGreaterThan (0 )
})
Pre-Deployment Security Checklist Before ANY production deployment:
Resources
Remember : Security is not optional. One vulnerability can compromise the entire platform. When in doubt, err on the side of caution.