Install
$ agentstack add skill-edfenton-claude-skills-nean-sec ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Purpose
Ensure NEAN code is secure by default. For security output format and core refusal policy, see /shared-sec-baseline.
NEAN-specific security concerns (always check)
- SQL injection — use TypeORM parameterized queries; never interpolate user input into raw SQL
- Input validation — class-validator decorators on all DTOs at every API boundary
- XSS — Angular sanitizes by default; audit
[innerHTML]andbypassSecurityTrust*usage - CSRF — required when using cookie-based auth; implement CSRF tokens or use SameSite=Strict
- Auth/authz gaps — verify authorization in NestJS guards on every protected endpoint, not just frontend
- Token storage — avoid localStorage for sensitive tokens; prefer httpOnly cookies for refresh tokens
- Mass assignment — use DTOs with explicit properties; never spread request body directly into entities
Standard security (brief check)
- Error responses: safe exception filters, no stack traces or internal details
- Rate limiting: on auth endpoints, expensive operations, public APIs
- Dependencies: lockfile committed, no known critical vulnerabilities
- Security headers: Helmet middleware configured
Reference
For detailed OWASP/CWE mitigation patterns, see reference/nean-sec-reference.md
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: edfenton
- Source: edfenton/claude-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.