agentsclimarketplace

Security

Skill tyecode/skills/skills/engineering/security

Passive guardrail that enforces a security checklist for full-stack development. Install globally — automatically runs before any feature touching user input, auth, data storage, or API endpoints is marked complete.From its SKILL.md

Install
npx -y skills add tyecode/skills --skill security

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

3.5 KB, 729 tokens by cl100k_base, as published. Nobody here has run it

Skill: security

When to Use This Skill

This is a passive guardrail — install it globally and it applies automatically. The agent runs this checklist before marking any feature complete that involves user input, auth, data storage, file uploads, or API endpoints. You do not need to invoke it explicitly.

Input Validation

Never trust user input. Validate and sanitize at every boundary.

  • Use parameterized queries or an ORM — never concatenate user input into SQL strings
  • Validate shape and type with Zod (Node.js) or Pydantic (Python) at the API boundary
  • Never pass raw user input to eval(), exec(), shell commands, or file paths
  • Strip or encode HTML in any user-supplied content that will be rendered
// Bad
db.query(`SELECT * FROM users WHERE email = '${email}'`);

// Good
db.query('SELECT * FROM users WHERE email = $1', [email]);

Authentication & Authorization

  • Every protected route must check auth — don't rely on the frontend to hide routes
  • Check authorization (can this user access this resource?) separately from authentication (is this user logged in?)
  • Never store passwords in plain text — use bcrypt or argon2
  • Lock accounts after 5 consecutive failed login attempts
  • Set token expiry. Refresh tokens should be rotated on use.
  • Set session timeouts — 30 minutes of inactivity is a reasonable default
  • Use httpOnly and Secure flags on auth cookies
// Check both: who are you, and can you do this?
const user = await getAuthenticatedUser(req); // authentication
if (user.id !== resource.ownerId) throw new ForbiddenError(); // authorization

Sensitive Data

  • Never log passwords, tokens, API keys, or PII
  • Never return sensitive fields in API responses — explicitly whitelist what goes out
  • Never hardcode secrets in source code — use environment variables
  • Check .env files are in .gitignore before every first commit on a project
  • Encrypt PII at rest — don't just avoid logging it, don't store it in plain text either
  • Never store raw credit card numbers — use Stripe or equivalent and store only tokens

API Security

  • Rate limit all public endpoints — 100 requests per user per minute is a reasonable default
  • Configure CORS to allow only known domains, never * in production
  • Return generic error messages to clients — never expose stack traces, DB errors, or internal paths
// Bad — leaks implementation details
res.status(500).json({ error: err.message, stack: err.stack });

// Good — generic to client, full details in server logs
console.error(err);
res.status(500).json({ error: 'Something went wrong' });

Dependencies

  • Don't add a package to solve a trivial problem — every dependency is an attack surface
  • Run npm audit (or equivalent) before shipping. Fix critical and high severity issues.

Pre-Ship Checklist

Before calling a feature done, ask:

  • What happens if a user sends an empty, null, or extremely large input?
  • What happens if a user tries to access another user's data by changing an ID in the URL?
  • What happens if this endpoint is called 1000 times per second?
  • Is there anything in the response that a user shouldn't be able to see?
  • Are error messages generic enough that they don't reveal system internals?

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 326,835. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.