While TLS is important for production deployments, most development work will be with TLS disabled or provided by some out-of-scope TLS proxy. Due to this, be very careful about not reporting lack of TLS as a security issue. Also be very careful around use of "secure" cookies. They should only be set if the application will actually be over TLS. If they are set on non-TLS applications (such as when deployed for local dev or testing), it will break the application. You can provide a env or other flag to override setting secure as a way to keep it off until on a TLS production deployment. Additionally avoid recommending HSTS. It is dangerous to use without full understanding of the lasting impacts (can cause major outages and user lockout) and it is not generally recommended for the scope of projects being reviewed by codex.
38:["$","div",null,{"className":"relative z-10 mx-auto max-w-[1400px] px-4 pb-16 sm:px-8 lg:px-16","children":[["$","$L3b",null,{"skillId":"1793aa67-96e6-4ec0-9dc0-198733e47379","skillTitle":"Security Review","skillStatus":"active","skillVisibility":"listed","slug":"security-review-openai","shareToken":null,"settingsShareToken":null,"fileTree":["references/","LICENSE.txt","references/golang-general-backend-security.md","references/javascript-express-web-server-security.md","references/javascript-general-web-frontend-security.md","references/javascript-jquery-web-frontend-security.md","references/javascript-typescript-nextjs-web-server-security.md","references/javascript-typescript-react-web-frontend-security.md","references/javascript-typescript-vue-web-frontend-security.md","references/python-django-web-server-security.md","references/python-fastapi-web-server-security.md","references/python-flask-web-server-security.md","SKILL.md"],"textContents":{"LICENSE.txt":"$3c","references/golang-general-backend-security.md":"$3d","references/javascript-express-web-server-security.md":"$3e","references/javascript-general-web-frontend-security.md":"$3f","references/javascript-jquery-web-frontend-security.md":"$40","references/javascript-typescript-nextjs-web-server-security.md":"$41","references/javascript-typescript-react-web-frontend-security.md":"$42","references/javascript-typescript-vue-web-frontend-security.md":"$43","references/python-django-web-server-security.md":"$44","references/python-fastapi-web-server-security.md":"$45","references/python-flask-web-server-security.md":"$46","SKILL.md":"$47"},"fileSizes":{"LICENSE.txt":10776,"references/golang-general-backend-security.md":38659,"references/javascript-express-web-server-security.md":49357,"references/javascript-general-web-frontend-security.md":38638,"references/javascript-jquery-web-frontend-security.md":33581,"references/javascript-typescript-nextjs-web-server-security.md":43423,"references/javascript-typescript-react-web-frontend-security.md":41686,"references/javascript-typescript-vue-web-frontend-security.md":31445,"references/python-django-web-server-security.md":38661,"references/python-fastapi-web-server-security.md":44926,"references/python-flask-web-server-security.md":31748,"SKILL.md":8682},"hasShowcase":false,"hasSandbox":false,"canEdit":false,"isAdmin":false,"demoFiles":[],"sandboxConfig":"$undefined","initialDependencies":[],"initialMcpServers":[],"initialOauthConnections":[],"initialAccessGrants":[],"showcase":null,"about":{"locale":"en","sections":[{"title":"What this skill does","body":"Perform language and framework specific security best-practice reviews and suggest improvements. Covers Python, JavaScript/TypeScript, and Go. Use when the user requests security best practices guidance, a security review or report, or secure-by-default coding help."},{"title":"How to use","body":"Once you're comfortable, download the skill files and drop them into any AI assistant — Claude (Anthropic), ChatGPT (OpenAI), Gemini (Google), or Mistral. The same skill file works across all of them, so you are never locked into a single provider."}],"requiredSkills":[],"dependentSkills":[],"author":{"name":"OpenAI