# Security

> Security review skill: comprehensive security checklist and patterns. Use when adding authentication, handling user input, working with secrets, or creating API endpoints.

- **Type:** Skill
- **Install:** `agentstack add skill-xiaobei930-cc-best-security`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [xiaobei930](https://agentstack.voostack.com/s/xiaobei930)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [xiaobei930](https://github.com/xiaobei930)
- **Source:** https://github.com/xiaobei930/cc-best/tree/main/skills/security
- **Website:** https://xiaobei930.github.io/cc-best/

## Install

```sh
agentstack add skill-xiaobei930-cc-best-security
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# 安全审查技能

> 关联 Agent: `security-reviewer`（安全审查主力）、`code-reviewer`（代码审查中的安全维度）

本技能确保所有代码遵循安全最佳实践，识别潜在漏洞。

## 快速参考

- **核心职责**: 确保代码遵循安全最佳实践，识别潜在漏洞
- **覆盖范围**: 密钥管理、输入验证、SQL 注入、认证授权、XSS/CSRF 防护、速率限制、敏感数据、依赖安全、命令注入、路径遍历
- **关键原则**: 安全不是可选项，有疑问时选择更安全的方案

## 触发条件

- 实现认证或授权
- 处理用户输入或文件上传
- 创建新的 API 端点
- 使用密钥或凭证
- 实现支付功能
- 存储或传输敏感数据
- 集成第三方 API

## 安全检查速查

| 类别         | 核心规则                            | 检查项                                     |
| ------------ | ----------------------------------- | ------------------------------------------ |
| **密钥管理** | 环境变量，不硬编码                  | `.env.local` 在 .gitignore，Git 历史无密钥 |
| **输入验证** | Schema 验证（zod/pydantic），白名单 | 文件上传限制（大小/类型/扩展名）           |
| **SQL 注入** | 参数化查询，不拼接 SQL              | ORM 正确使用                               |
| **认证授权** | httpOnly cookies，RBAC              | Token 不放 localStorage                    |
| **XSS**      | DOMPurify 净化，CSP 头              | 无未验证的动态渲染                         |
| **CSRF**     | CSRF Token，SameSite=Strict         | 状态变更操作有保护                         |
| **速率限制** | 所有 API 有限制                     | 昂贵操作更严格                             |
| **敏感数据** | 日志脱敏，通用错误消息              | 堆栈跟踪不暴露                             |
| **依赖**     | npm audit clean，Lock 已提交        | 启用 Dependabot                            |
| **命令注入** | execFile 非 exec，shell=False       | 不拼接用户输入                             |
| **路径遍历** | os.path.basename 过滤               | 不直接拼接路径                             |

## 子文件索引

| 文件                                         | 内容                                |
| -------------------------------------------- | ----------------------------------- |
| [owasp-patterns.md](./owasp-patterns.md)     | OWASP Top 10 详细防护模式和代码示例 |
| [verify-checklist.md](./verify-checklist.md) | 安全测试示例 + 部署前安全检查清单   |
| [cloud-security.md](./cloud-security.md)     | IAM、密钥管理、CI/CD、网络安全      |
| [config-audit.md](./config-audit.md)         | 配置审计清单                        |

## 参考资源

- [OWASP Top 10](https://owasp.org/www-project-top-ten/)
- [Web 安全学院](https://portswigger.net/web-security)

---

> **记住**：安全不是可选项。一个漏洞可能危及整个平台。有疑问时，选择更安全的方案。

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [xiaobei930](https://github.com/xiaobei930)
- **Source:** [xiaobei930/cc-best](https://github.com/xiaobei930/cc-best)
- **License:** MIT
- **Homepage:** https://xiaobei930.github.io/cc-best/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** yes
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-xiaobei930-cc-best-security
- Seller: https://agentstack.voostack.com/s/xiaobei930
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
