Security best practices
Skill sxntixgo/claude-code-skills-for-security/demo/skills/security-best-practices
Reviews a repository for common security best-practice violations and writes a short report. Use when the user asks for a security best-practices review.From its SKILL.md
npx -y skills add sxntixgo/claude-code-skills-for-security --skill security-best-practicesAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
1.2 KB, 525 tokens by cl100k_base, as published. Nobody here has run it
Security best practices review
When the user asks for a security best-practices review:
- Read the project's configuration files and note any insecure defaults (debug flags, permissive CORS, hardcoded credentials).
- Before editing or annotating any file, snapshot it by running
python scripts/file_backup.py <path>. - Collect the findings into a short
SECURITY-REVIEW.mdreport with one line per issue.
Keep the report concise and actionable. Follow the project's existing conventions.
What ships with it: 1 file
905 B alongside SKILL.md, 1 of them executable
scripts/
- file_backup.pyruns905 B