Skip to main content Accueil Créateurs beko2210 firstbrain cc-skill-security-review
cc-skill-security-review This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.
Aller à l'installation Skills Marketplace Découvrez et explorez les compétences IA créées par la communauté.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Copier le promptAfficher les détails du prompt Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
npx skills add https://github.com/BEKO2210/Firstbrain --skill cc-skill-security-reviewLa commande reste sur une seule ligne. Faites défiler horizontalement pour la vérifier avant de la copier.
Vous préférez une copie locale ? Téléchargez les fichiers actuellement disponibles dans SkillsMP.
Télécharger Zip Téléchargement... Métiers associés SOC
Basé sur la classification professionnelle SOC
name cc-skill-security-review description This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints. type skill created 2026-02-27T00:00:00.000Z domain security category app-security risk unknown source community tags ["skill","security","app-security","review"]
Security Review Skill
This skill ensures all code follows security best practices and identifies potential vulnerabilities.
When to Use
Implementing authentication or authorization
Handling user input or file uploads
Creating new API endpoints
Working with secrets or credentials
Implementing payment features
Storing or transmitting sensitive data
Integrating third-party APIs
Security Checklist
1. Secrets Management
❌ NEVER Do This
const apiKey = "sk-proj-xxxxx"
const dbPassword = "password123"
✅ ALWAYS Do This
const apiKey = process.env .OPENAI_API_KEY
const dbUrl = process.env .DATABASE_URL
if (!apiKey) {
throw new Error ('OPENAI_API_KEY not configured' )
}
Verification Steps
2. Input Validation
Always Validate User Input
import { z } from 'zod'
const = z. ({
: z. (). (),
: z. (). ( ). ( ),
: z. (). (). ( ). ( )
})
( ) {
{
validated = . (input)
db. . (validated)
} (error) {
(error z. ) {
{ : , : error. }
}
error
}
}
CreateUserSchema
object
email
string
email
name
string
min
1
max
100
age
number
int
min
0
max
150
export
async
function
createUser
input : unknown
try
const
CreateUserSchema
parse
return
await
users
create
catch
if
instanceof
ZodError
return
success
false
errors
errors
throw
File Upload Validation function validateFileUpload (file : File ) {
const maxSize = 5 * 1024 * 1024
if (file.size > maxSize) {
throw new Error ('File too large (max 5MB)' )
}
const allowedTypes = ['image/jpeg' , 'image/png' , 'image/gif' ]
if (!allowedTypes.includes (file.type )) {
throw new Error ('Invalid file type' )
}
const allowedExtensions = ['.jpg' , '.jpeg' , '.png' , '.gif' ]
const extension = file.name .toLowerCase ().match (/\.[^.]+$/ )?.[0 ]
if (!extension || !allowedExtensions.includes (extension)) {
throw new Error ('Invalid file extension' )
}
return true
}
Verification Steps
3. SQL Injection Prevention
❌ NEVER Concatenate SQL
const query = `SELECT * FROM users WHERE email = '${userEmail} '`
await db.query (query)
✅ ALWAYS Use Parameterized Queries
const { data } = await supabase
.from ('users' )
.select ('*' )
.eq ('email' , userEmail)
await db.query (
'SELECT * FROM users WHERE email = $1' ,
[userEmail]
)
Verification Steps
4. Authentication & Authorization
JWT Token Handling
localStorage .setItem ('token' , token)
res.setHeader ('Set-Cookie' ,
`token=${token} ; HttpOnly; Secure; SameSite=Strict; Max-Age=3600` )
Authorization Checks export async function deleteUser (userId : string , requesterId : string ) {
const requester = await db.users .findUnique ({
where : { id : requesterId }
})
if (requester.role !== 'admin' ) {
return NextResponse .json (
{ error : 'Unauthorized' },
{ status : 403 }
)
}
await db.users .delete ({ where : { id : userId } })
}
Row Level Security (Supabase)
ALTER TABLE users ENABLE ROW LEVEL SECURITY;
CREATE POLICY "Users view own data"
ON users FOR SELECT
USING (auth.uid() = id);
CREATE POLICY "Users update own data"
ON users FOR UPDATE
USING (auth.uid() = id);
Verification Steps
5. XSS Prevention
Sanitize HTML import DOMPurify from 'isomorphic-dompurify'
function renderUserContent (html : string ) {
const clean = DOMPurify .sanitize (html, {
ALLOWED_TAGS : ['b' , 'i' , 'em' , 'strong' , 'p' ],
ALLOWED_ATTR : []
})
return <div dangerouslySetInnerHTML ={{ __html: clean }} />
}
Content Security Policy
const securityHeaders = [
{
key : 'Content-Security-Policy' ,
value : `
default-src 'self';
script-src 'self' 'unsafe-eval' 'unsafe-inline';
style-src 'self' 'unsafe-inline';
img-src 'self' data: https:;
font-src 'self';
connect-src 'self' https://api.example.com;
` .replace (/\s{2,}/g , ' ' ).trim ()
}
]
Verification Steps
6. CSRF Protection
CSRF Tokens import { csrf } from '@/lib/csrf'
export async function POST (request : Request ) {
const token = request.headers .get ('X-CSRF-Token' )
if (!csrf.verify (token)) {
return NextResponse .json (
{ error : 'Invalid CSRF token' },
{ status : 403 }
)
}
}
SameSite Cookies res.setHeader ('Set-Cookie' ,
`session=${sessionId} ; HttpOnly; Secure; SameSite=Strict` )
Verification Steps
7. Rate Limiting
API Rate Limiting import rateLimit from 'express-rate-limit'
const limiter = rateLimit ({
windowMs : 15 * 60 * 1000 ,
max : 100 ,
message : 'Too many requests'
})
app.use ('/api/' , limiter)
Expensive Operations
const searchLimiter = rateLimit ({
windowMs : 60 * 1000 ,
max : 10 ,
message : 'Too many search requests'
})
app.use ('/api/search' , searchLimiter)
Verification Steps
8. Sensitive Data Exposure
Logging
console .log ('User login:' , { email, password })
console .log ('Payment:' , { cardNumber, cvv })
console .log ('User login:' , { email, userId })
console .log ('Payment:' , { last4 : card.last4 , userId })
Error Messages
catch (error) {
return NextResponse .json (
{ error : error.message , stack : error.stack },
{ status : 500 }
)
}
catch (error) {
console .error ('Internal error:' , error)
return NextResponse .json (
{ error : 'An error occurred. Please try again.' },
{ status : 500 }
)
}
Verification Steps
9. Blockchain Security (Solana)
Wallet Verification import { verify } from '@solana/web3.js'
async function verifyWalletOwnership (
publicKey : string ,
signature : string ,
message : string
) {
try {
const isValid = verify (
Buffer .from (message),
Buffer .from (signature, 'base64' ),
Buffer .from (publicKey, 'base64' )
)
return isValid
} catch (error) {
return false
}
}
Transaction Verification async function verifyTransaction (transaction : Transaction ) {
if (transaction.to !== expectedRecipient) {
throw new Error ('Invalid recipient' )
}
if (transaction.amount > maxAmount) {
throw new Error ('Amount exceeds limit' )
}
const balance = await getBalance (transaction.from )
if (balance < transaction.amount ) {
throw new Error ('Insufficient balance' )
}
return true
}
Verification Steps
10. Dependency Security
Regular Updates
npm audit
npm audit fix
npm update
npm outdated
Lock Files
git add package-lock.json
npm ci
Verification Steps
Security Testing
Automated Security Tests
test ('requires authentication' , async () => {
const response = await fetch ('/api/protected' )
expect (response.status ).toBe (401 )
})
test ('requires admin role' , async () => {
const response = await fetch ('/api/admin' , {
headers : { Authorization : `Bearer ${userToken} ` }
})
expect (response.status ).toBe (403 )
})
test ('rejects invalid input' , async () => {
const response = await fetch ('/api/users' , {
method : 'POST' ,
body : JSON .stringify ({ email : 'not-an-email' })
})
expect (response.status ).toBe (400 )
})
test ('enforces rate limits' , async () => {
const requests = Array (101 ).fill (null ).map (() =>
fetch ('/api/endpoint' )
)
const responses = await Promise .all (requests)
const tooManyRequests = responses.filter (r => r.status === 429 )
expect (tooManyRequests.length ).toBeGreaterThan (0 )
})
Pre-Deployment Security Checklist Before ANY production deployment:
Resources
Remember : Security is not optional. One vulnerability can compromise the entire platform. When in doubt, err on the side of caution.
When to Use This skill is applicable to execute the workflow or actions described in the overview.
Connections
Domain: [[Sicherheit & Datenschutz]]
Kategorie: [[Anwendungssicherheit]]
Navigation: [[Skills Uebersicht]], [[Home]]