AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Moai Ref Owasp Checklist

skill-modu-ai-moai-adk-moai-ref-owasp-checklist · by modu-ai

>

No reviews yet
0 installs
3 views
0.0% view→install

Install

$ agentstack add skill-modu-ai-moai-adk-moai-ref-owasp-checklist

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-modu-ai-moai-adk-moai-ref-owasp-checklist)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Moai Ref Owasp Checklist? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

OWASP Security Checklist Reference

Target Agents

  • expert-security - Primary: applies checklist during security audits
  • expert-backend - Secondary: applies during API implementation

OWASP API Security Top 10

| Rank | Vulnerability | Check | Defense | |------|-------------|-------|---------| | A1 | BOLA (Broken Object Level Authorization) | Can user A access user B's resources? | Verify object ownership at every endpoint | | A2 | Broken Authentication | Weak passwords, unlimited login attempts? | bcrypt (cost 12+), rate limit, MFA | | A3 | Broken Object Property Level Authorization | Are hidden fields exposed in responses? | Response DTOs, field-level filtering | | A4 | Unrestricted Resource Consumption | Can mass requests crash the server? | Rate limiting, enforce pagination limits | | A5 | Broken Function Level Authorization | Can regular users call admin APIs? | RBAC middleware, permission checks | | A6 | SSRF (Server-Side Request Forgery) | Can URL input access internal resources? | URL whitelist, block internal IPs | | A7 | Security Misconfiguration | Debug mode, default accounts exposed? | Separate prod config, inspect headers | | A8 | Lack of Automated Threat Protection | Can APIs be called in abnormal sequences? | State machine validation, business rules | | A9 | Improper Asset Management | Unused APIs, old versions exposed? | API inventory, version deprecation | | A10 | Unsafe API Consumption | Are external API responses trusted blindly? | Validate external responses, set timeouts |

Authentication Checklist

Password Policy

  • Minimum 8 characters, show strength meter (not strict rules)
  • bcrypt (cost factor 12+) or Argon2id
  • Temporary lock after 5 failed attempts (15 min) or CAPTCHA
  • Prevent reuse of last 5 passwords

JWT Configuration

| Setting | Recommended Value | |---------|------------------| | Access Token Expiry | 15-30 minutes | | Refresh Token Expiry | 7-14 days | | Algorithm | RS256 (asymmetric) or HS256 | | Storage | httpOnly + secure + sameSite cookie | | Payload | Minimal: userId, role only (no PII) | | Renewal | Silent refresh or token rotation |

Session Security

  • Regenerate session ID after login
  • Invalidate session on logout (server-side)
  • Set session timeout (30 min idle)
  • Bind session to IP/User-Agent (optional, strict)

HTTP Security Headers

| Header | Value | Purpose | |--------|-------|---------| | Strict-Transport-Security | max-age=31536000; includeSubDomains | Force HTTPS | | X-Content-Type-Options | nosniff | Prevent MIME sniffing | | X-Frame-Options | DENY or SAMEORIGIN | Prevent clickjacking | | Content-Security-Policy | default-src 'self' | Prevent XSS | | Referrer-Policy | strict-origin-when-cross-origin | Limit referrer | | Permissions-Policy | camera=(), microphone=() | Restrict browser features |

Input Validation Checklist

| Type | Method | Tool | |------|--------|------| | Schema validation | Type + structure check | Zod, Joi, pydantic, Go validator | | Length limits | Min/max constraints | Schema definitions | | SQL Injection | Parameterized queries | ORM (Prisma, GORM, SQLAlchemy) | | XSS Prevention | HTML escaping | DOMPurify (client), server escape | | Path Traversal | Path normalization | filepath.Clean + whitelist | | File Upload | Type + size validation | MIME type + magic number check | | CORS | Origin whitelist | Never origin: '*' with credentials |

Sensitive Data Handling

| Data Type | Storage | Transmission | Logging | |----------|---------|-------------|---------| | Passwords | bcrypt hash only | HTTPS only | NEVER | | API Keys | Environment variables | Header (Authorization) | Masked (first 4 chars) | | PII | Encrypted (AES-256) | HTTPS only | Masked | | Credit Cards | Tokenized (payment provider) | Provider SDK | NEVER | | Sessions | httpOnly cookie | HTTPS only | NEVER |

Security Review Severity Levels

| Level | Label | Action | Example | |-------|-------|--------|---------| | P0 | CRITICAL | Block release | SQL injection, auth bypass | | P1 | HIGH | Fix before merge | Missing authorization check | | P2 | MEDIUM | Fix within sprint | Weak password policy | | P3 | LOW | Track in backlog | Missing security header |

Common Rationalizations

| Rationalization | Reality | |---|---| | "This is an internal application, OWASP does not apply" | Internal applications are reachable from compromised internal services. OWASP applies to all web applications. | | "The framework handles XSS protection" | Frameworks protect default rendering paths. Dynamic HTML insertion, innerHTML, and template literals bypass the protection. | | "We do not store sensitive data, so encryption is unnecessary" | Session tokens, API keys, and PII are sensitive data. If the application has users, it has sensitive data. | | "Security headers are just defense-in-depth, not critical" | Each security header blocks a specific attack class. Missing CSP enables XSS even when output is escaped. | | "I will do a security review before release" | Late security reviews find issues that are expensive to fix. Secure coding practices prevent them from the start. |

Red Flags

  • User input rendered in HTML without escaping or sanitization
  • SQL query built with string concatenation instead of parameterized queries
  • Authentication token stored in localStorage instead of httpOnly cookie
  • Missing Content-Security-Policy header on response
  • Secrets (API keys, passwords) found in source code or configuration files committed to git

Verification

  • [ ] OWASP Top 10 checklist reviewed for the change (show which items were evaluated)
  • [ ] User input sanitized before rendering in HTML output
  • [ ] All database queries use parameterized statements
  • [ ] Security headers present (CSP, X-Frame-Options, X-Content-Type-Options)
  • [ ] No secrets found in source code (show grep results for common secret patterns)
  • [ ] Authentication tokens use httpOnly, Secure, SameSite cookie attributes

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.