Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/Objective-Arts/lens-dist --skill owasp명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | owasp |
| description | OWASP Top 10 and security vulnerability patterns |
Apply OWASP (Open Web Application Security Project) guidelines: the industry standard for web application security.
// BAD: No authorization check
[HttpGet("/api/users/{id}")]
public User GetUser(int id) => _db.Users.Find(id);
// GOOD: Verify ownership
[HttpGet("/api/users/{id}")]
[Authorize]
public User GetUser(int id) {
var user = _db.Users.Find(id);
if (user.Id != CurrentUserId && !IsAdmin)
throw new ForbiddenException();
return user;
}
// BAD: SQL Injection
const query = `SELECT * FROM users WHERE id = ${userId}`;
// GOOD: Parameterized query
const query = 'SELECT * FROM users WHERE id = @id';
await db.query(query, { id: userId });
# Check for vulnerabilities
npm audit
dotnet list package --vulnerable
// Log security events
_logger.LogWarning("Failed login attempt for {User} from {IP}",
username, Request.RemoteIp);
_logger.LogCritical("Privilege escalation attempt by {User}",
CurrentUser.Id);
// BAD: User controls URL
var response = await _http.GetAsync(userProvidedUrl);
// GOOD: Allowlist domains
if (!_allowedDomains.Contains(new Uri(url).Host))
throw new SecurityException("Domain not allowed");