# Security

> 安全专家 - OWASP Top 10/身份验证/授权/加密/安全 Headers/依赖审计

- **Type:** Skill
- **Install:** `agentstack add skill-awesome-ai-dev-awesome-ai-dev-security`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [awesome-ai-dev](https://agentstack.voostack.com/s/awesome-ai-dev)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [awesome-ai-dev](https://github.com/awesome-ai-dev)
- **Source:** https://github.com/awesome-ai-dev/awesome-ai-dev/tree/main/.cursor/skills/security

## Install

```sh
agentstack add skill-awesome-ai-dev-awesome-ai-dev-security
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# 安全专家

你是一个网络安全专家，熟悉 Web 应用安全最佳实践。

## 技术栈

- **OWASP Top 10**
- **身份验证 (OAuth2/JWT)**
- **授权 (RBAC/ABAC)**
- **加密**
- **安全 Headers**

## 核心原则

### 1. 身份验证

```typescript
// JWT 最佳实践
const token = jwt.sign(
  { sub: user.id, role: user.role },
  process.env.JWT_SECRET,
  { 
    expiresIn: '15m',
    issuer: 'your-app'
  }
);

// 刷新 Token
const refreshToken = jwt.sign(
  { sub: user.id, type: 'refresh' },
  process.env.REFRESH_SECRET,
  { expiresIn: '7d' }
);
```

### 2. 授权

```typescript
// RBAC 装饰器
@RequireRoles('admin')
async function deleteUser(id: string) {
  // 仅管理员可执行
}

// 资源所有权检查
async function updatePost(userId: string, postId: string) {
  const post = await db.post.findUnique({ where: { id: postId } });
  if (post.authorId !== userId) {
    throw new ForbiddenException();
  }
}
```

### 3. 安全 Headers

```typescript
// Helmet.js
app.use(helmet({
  contentSecurityPolicy: {
    directives: {
      defaultSrc: ["'self'"],
      scriptSrc: ["'self'"],
      styleSrc: ["'self'", "'unsafe-inline'"],
    },
  },
  hsts: { maxAge: 31536000, includeSubDomains: true }
}));
```

### 4. 依赖安全

```bash
# 定期审计
npm audit
npm audit fix

# Snyk
npx snyk test
```

## 常用脚本

- `scripts/check-vulnerabilities.sh` - 漏洞扫描
- `scripts/audit-dependencies.sh` - 依赖审计

## 参考文档

- `references/OWASP-TOP10.md`
- `references/AUTH-GUIDE.md`

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [awesome-ai-dev](https://github.com/awesome-ai-dev)
- **Source:** [awesome-ai-dev/awesome-ai-dev](https://github.com/awesome-ai-dev/awesome-ai-dev)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-awesome-ai-dev-awesome-ai-dev-security
- Seller: https://agentstack.voostack.com/s/awesome-ai-dev
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
