Skip to main content
security-review Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Zur Installation springen Skills Marktplatz Entdecken und erkunden Sie KI-Skills, die von der Community erstellt wurden.
Verwandte Berufe SOC
Basierend auf der SOC-Berufsklassifikation
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Prompt kopierenPrompt-Details anzeigen Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
npx skills add https://github.com/Muneshige1567/self-improvement-app --skill security-reviewDer Befehl bleibt in einer Zeile. Scrollen Sie horizontal, um ihn vor dem Kopieren vollständig zu prüfen.
Sie bevorzugen eine lokale Kopie? Laden Sie die Dateien herunter, die SkillsMP derzeit vorliegen.
ZIP herunterladen Herunterladen... cloud-infrastructure-security.md 10.0 KB Mehr aus diesem Repository name security-review description Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Security Review Skill
This skill ensures all code follows security best practices and identifies potential vulnerabilities.
When to Activate
Implementing authentication or authorization
Handling user input or file uploads
Creating new API endpoints
Working with secrets or credentials
Implementing payment features
Storing or transmitting sensitive data
Integrating third-party APIs
Security Checklist
1. Secrets Management
❌ NEVER Do This
const apiKey = "sk-proj-xxxxx"
const dbPassword = "password123"
✅ ALWAYS Do This
const apiKey = process.env .OPENAI_API_KEY
const dbUrl = process.env .DATABASE_URL
if (!apiKey) {
throw new Error ('OPENAI_API_KEY not configured' )
}
Verification Steps
No hardcoded API keys, tokens, or passwords
All secrets in environment variables
.env.local in .gitignore
No secrets in git history
Production secrets in hosting platform (Vercel, Railway)
2. Input Validation
Always Validate User Input import { z } from 'zod'
const CreateUserSchema = z.object ({
email : z.string ().email (),
name : z.string ().min (1 ).max (100 ),
age : z.number ().int ().min (0 ).max (150 )
})
export async function createUser (input : unknown ) {
try {
const validated = CreateUserSchema .parse (input)
return await db.users .create (validated)
} catch (error) {
if (error instanceof z.ZodError ) {
return { success : false , errors : error.errors }
}
throw error
}
}
File Upload Validation function validateFileUpload (file : File ) {
const maxSize = 5 * 1024 * 1024
if (file.size > maxSize) {
throw new Error ('File too large (max 5MB)' )
}
const allowedTypes = ['image/jpeg' , 'image/png' , 'image/gif' ]
if (!allowedTypes.includes (file.type )) {
throw new Error ('Invalid file type' )
}
const allowedExtensions = ['.jpg' , '.jpeg' , '.png' , '.gif' ]
const extension = file.name .toLowerCase ().match (/\.[^.]+$/ )?.[0 ]
if (!extension || !allowedExtensions.includes (extension)) {
throw new Error ('Invalid file extension' )
}
return true
}
Verification Steps
3. SQL Injection Prevention
❌ NEVER Concatenate SQL
const query = `SELECT * FROM users WHERE email = '${userEmail} '`
await db.query (query)
✅ ALWAYS Use Parameterized Queries
const { data } = await supabase
.from ('users' )
.select ('*' )
.eq ('email' , userEmail)
await db.query (
'SELECT * FROM users WHERE email = $1' ,
[userEmail]
)
Verification Steps
4. Authentication & Authorization
JWT Token Handling
localStorage .setItem ('token' , token)
res.setHeader ('Set-Cookie' ,
`token=${token} ; HttpOnly; Secure; SameSite=Strict; Max-Age=3600` )
Authorization Checks export async function deleteUser (userId : string , requesterId : string ) {
const requester = await db.users .findUnique ({
where : { id : requesterId }
})
if (requester.role !== 'admin' ) {
return NextResponse .json (
{ error : 'Unauthorized' },
{ status : 403 }
)
}
await db.users .delete ({ where : { id : userId } })
}
Row Level Security (Supabase)
ALTER TABLE users ENABLE ROW LEVEL SECURITY;
CREATE POLICY "Users view own data"
ON users FOR SELECT
USING (auth.uid() = id);
CREATE POLICY "Users update own data"
ON users FOR UPDATE
USING (auth.uid() = id);
Verification Steps
5. XSS Prevention
Sanitize HTML import DOMPurify from 'isomorphic-dompurify'
function renderUserContent (html : string ) {
const clean = DOMPurify .sanitize (html, {
ALLOWED_TAGS : ['b' , 'i' , 'em' , 'strong' , 'p' ],
ALLOWED_ATTR : []
})
return <div dangerouslySetInnerHTML ={{ __html: clean }} />
}
Content Security Policy
const securityHeaders = [
{
key : 'Content-Security-Policy' ,
value : `
default-src 'self';
script-src 'self' 'unsafe-eval' 'unsafe-inline';
style-src 'self' 'unsafe-inline';
img-src 'self' data: https:;
font-src 'self';
connect-src 'self' https://api.example.com;
` .replace (/\s{2,}/g , ' ' ).trim ()
}
]
Verification Steps
6. CSRF Protection
CSRF Tokens import { csrf } from '@/lib/csrf'
export async function POST (request : Request ) {
const token = request.headers .get ('X-CSRF-Token' )
if (!csrf.verify (token)) {
return NextResponse .json (
{ error : 'Invalid CSRF token' },
{ status : 403 }
)
}
}
SameSite Cookies res.setHeader ('Set-Cookie' ,
`session=${sessionId} ; HttpOnly; Secure; SameSite=Strict` )
Verification Steps
7. Rate Limiting
API Rate Limiting import rateLimit from 'express-rate-limit'
const limiter = rateLimit ({
windowMs : 15 * 60 * 1000 ,
max : 100 ,
message : 'Too many requests'
})
app.use ('/api/' , limiter)
Expensive Operations
const searchLimiter = rateLimit ({
windowMs : 60 * 1000 ,
max : 10 ,
message : 'Too many search requests'
})
app.use ('/api/search' , searchLimiter)
Verification Steps
8. Sensitive Data Exposure
Logging
console .log ('User login:' , { email, password })
console .log ('Payment:' , { cardNumber, cvv })
console .log ('User login:' , { email, userId })
console .log ('Payment:' , { last4 : card.last4 , userId })
Error Messages
catch (error) {
return NextResponse .json (
{ error : error.message , stack : error.stack },
{ status : 500 }
)
}
catch (error) {
console .error ('Internal error:' , error)
return NextResponse .json (
{ error : 'An error occurred. Please try again.' },
{ status : 500 }
)
}
Verification Steps
9. Blockchain Security (Solana)
Wallet Verification import { verify } from '@solana/web3.js'
async function verifyWalletOwnership (
publicKey : string ,
signature : string ,
message : string
) {
try {
const isValid = verify (
Buffer .from (message),
Buffer .from (signature, 'base64' ),
Buffer .from (publicKey, 'base64' )
)
return isValid
} catch (error) {
return false
}
}
Transaction Verification async function verifyTransaction (transaction : Transaction ) {
if (transaction.to !== expectedRecipient) {
throw new Error ('Invalid recipient' )
}
if (transaction.amount > maxAmount) {
throw new Error ('Amount exceeds limit' )
}
const balance = await getBalance (transaction.from )
if (balance < transaction.amount ) {
throw new Error ('Insufficient balance' )
}
return true
}
Verification Steps
10. Dependency Security
Regular Updates
npm audit
npm audit fix
npm update
npm outdated
Lock Files
git add package-lock.json
npm ci
Verification Steps
Security Testing
Automated Security Tests
test ('requires authentication' , async () => {
const response = await fetch ('/api/protected' )
expect (response.status ).toBe (401 )
})
test ('requires admin role' , async () => {
const response = await fetch ('/api/admin' , {
headers : { Authorization : `Bearer ${userToken} ` }
})
expect (response.status ).toBe (403 )
})
test ('rejects invalid input' , async () => {
const response = await fetch ('/api/users' , {
method : 'POST' ,
body : JSON .stringify ({ email : 'not-an-email' })
})
expect (response.status ).toBe (400 )
})
test ('enforces rate limits' , async () => {
const requests = Array (101 ).fill (null ).map (() =>
fetch ('/api/endpoint' )
)
const responses = await Promise .all (requests)
const tooManyRequests = responses.filter (r => r.status === 429 )
expect (tooManyRequests.length ).toBeGreaterThan (0 )
})
Pre-Deployment Security Checklist Before ANY production deployment:
Resources
Remember : Security is not optional. One vulnerability can compromise the entire platform. When in doubt, err on the side of caution.