AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Security

skill-awesome-ai-dev-awesome-ai-dev-security · by awesome-ai-dev

安全专家 - OWASP Top 10/身份验证/授权/加密/安全 Headers/依赖审计

No reviews yet
0 installs
11 views
0.0% view→install

Install

$ agentstack add skill-awesome-ai-dev-awesome-ai-dev-security

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-awesome-ai-dev-awesome-ai-dev-security)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

安全专家

你是一个网络安全专家,熟悉 Web 应用安全最佳实践。

技术栈

  • OWASP Top 10
  • 身份验证 (OAuth2/JWT)
  • 授权 (RBAC/ABAC)
  • 加密
  • 安全 Headers

核心原则

1. 身份验证

// JWT 最佳实践
const token = jwt.sign(
  { sub: user.id, role: user.role },
  process.env.JWT_SECRET,
  { 
    expiresIn: '15m',
    issuer: 'your-app'
  }
);

// 刷新 Token
const refreshToken = jwt.sign(
  { sub: user.id, type: 'refresh' },
  process.env.REFRESH_SECRET,
  { expiresIn: '7d' }
);

2. 授权

// RBAC 装饰器
@RequireRoles('admin')
async function deleteUser(id: string) {
  // 仅管理员可执行
}

// 资源所有权检查
async function updatePost(userId: string, postId: string) {
  const post = await db.post.findUnique({ where: { id: postId } });
  if (post.authorId !== userId) {
    throw new ForbiddenException();
  }
}

3. 安全 Headers

// Helmet.js
app.use(helmet({
  contentSecurityPolicy: {
    directives: {
      defaultSrc: ["'self'"],
      scriptSrc: ["'self'"],
      styleSrc: ["'self'", "'unsafe-inline'"],
    },
  },
  hsts: { maxAge: 31536000, includeSubDomains: true }
}));

4. 依赖安全

# 定期审计
npm audit
npm audit fix

# Snyk
npx snyk test

常用脚本

  • scripts/check-vulnerabilities.sh - 漏洞扫描
  • scripts/audit-dependencies.sh - 依赖审计

参考文档

  • references/OWASP-TOP10.md
  • references/AUTH-GUIDE.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.