# Security General

> Security checklist: OWASP top 10, secret scanning, input validation, and auth patterns

- **Type:** Skill
- **Install:** `agentstack add skill-ucdavis-ai-skills-registry-security-general`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [ucdavis](https://agentstack.voostack.com/s/ucdavis)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [ucdavis](https://github.com/ucdavis)
- **Source:** https://github.com/ucdavis/ai-skills-registry/tree/main/skills/security-general

## Install

```sh
agentstack add skill-ucdavis-ai-skills-registry-security-general
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Security Checklist

## Input Validation
- Validate all inputs at system boundaries: API endpoints, CLI args, file uploads, env vars.
- Use allowlists, not denylists, for permitted values.
- Reject oversized inputs (prevent DoS via resource exhaustion).
- Validate content type, not just file extension.

## Injection Prevention
- **SQL**: parameterized queries only. Never concatenate user input into SQL strings.
- **Command injection**: never pass user input to `exec`, `spawn`, or shell commands unsanitized.
- **Path traversal**: normalize and validate file paths. Reject `../` sequences.
- **LDAP/XPath/NoSQL**: use parameterized queries where available.

## Authentication & Authorization
- Deny by default: if no explicit permission grant, deny the request.
- Validate JWTs: signature, `exp`, `iss`, `aud` claims.
- Use short-lived access tokens (15 min) + refresh tokens.
- Never roll your own crypto — use established, audited libraries.
- Rate-limit login and sensitive endpoints.

## Secrets Management
- Never hardcode secrets in source code or config files.
- Use environment variables or a secrets manager (Vault, AWS Secrets Manager, GCP Secret Manager).
- Scan commits for secrets with `git-secrets`, `truffleHog`, or `gitleaks` in CI.
- Rotate leaked secrets immediately — assume they are compromised.

## Output Encoding
- Encode for the context: HTML entities for HTML, URL encoding for URLs.
- Use framework-provided escaping — never write your own.
- Set `Content-Security-Policy`, `X-Content-Type-Options`, `X-Frame-Options` headers.

## Error Handling
- Never expose stack traces or internal details to end users.
- Log full errors server-side with correlation IDs; return generic messages to clients.

## Dependencies
- Audit regularly: `npm audit`, `pip-audit`, `trivy`, `OWASP Dependency-Check`.
- Pin versions in production. Review changelogs before upgrading.
- Remove unused dependencies.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ucdavis](https://github.com/ucdavis)
- **Source:** [ucdavis/ai-skills-registry](https://github.com/ucdavis/ai-skills-registry)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-ucdavis-ai-skills-registry-security-general
- Seller: https://agentstack.voostack.com/s/ucdavis
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
