AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Security

skill-xiaobei930-cc-best-security · by xiaobei930

Security review skill: comprehensive security checklist and patterns. Use when adding authentication, handling user input, working with secrets, or creating API endpoints.

No reviews yet
0 installs
34 views
0.0% view→install

Install

$ agentstack add skill-xiaobei930-cc-best-security

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution Used
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-xiaobei930-cc-best-security)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

安全审查技能

> 关联 Agent: security-reviewer(安全审查主力)、code-reviewer(代码审查中的安全维度)

本技能确保所有代码遵循安全最佳实践,识别潜在漏洞。

快速参考

  • 核心职责: 确保代码遵循安全最佳实践,识别潜在漏洞
  • 覆盖范围: 密钥管理、输入验证、SQL 注入、认证授权、XSS/CSRF 防护、速率限制、敏感数据、依赖安全、命令注入、路径遍历
  • 关键原则: 安全不是可选项,有疑问时选择更安全的方案

触发条件

  • 实现认证或授权
  • 处理用户输入或文件上传
  • 创建新的 API 端点
  • 使用密钥或凭证
  • 实现支付功能
  • 存储或传输敏感数据
  • 集成第三方 API

安全检查速查

| 类别 | 核心规则 | 检查项 | | ------------ | ----------------------------------- | ------------------------------------------ | | 密钥管理 | 环境变量,不硬编码 | .env.local 在 .gitignore,Git 历史无密钥 | | 输入验证 | Schema 验证(zod/pydantic),白名单 | 文件上传限制(大小/类型/扩展名) | | SQL 注入 | 参数化查询,不拼接 SQL | ORM 正确使用 | | 认证授权 | httpOnly cookies,RBAC | Token 不放 localStorage | | XSS | DOMPurify 净化,CSP 头 | 无未验证的动态渲染 | | CSRF | CSRF Token,SameSite=Strict | 状态变更操作有保护 | | 速率限制 | 所有 API 有限制 | 昂贵操作更严格 | | 敏感数据 | 日志脱敏,通用错误消息 | 堆栈跟踪不暴露 | | 依赖 | npm audit clean,Lock 已提交 | 启用 Dependabot | | 命令注入 | execFile 非 exec,shell=False | 不拼接用户输入 | | 路径遍历 | os.path.basename 过滤 | 不直接拼接路径 |

子文件索引

| 文件 | 内容 | | -------------------------------------------- | ----------------------------------- | | [owasp-patterns.md](./owasp-patterns.md) | OWASP Top 10 详细防护模式和代码示例 | | [verify-checklist.md](./verify-checklist.md) | 安全测试示例 + 部署前安全检查清单 | | [cloud-security.md](./cloud-security.md) | IAM、密钥管理、CI/CD、网络安全 | | [config-audit.md](./config-audit.md) | 配置审计清单 |

参考资源


> 记住:安全不是可选项。一个漏洞可能危及整个平台。有疑问时,选择更安全的方案。

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.