本文へ移動
cccskills
無料GitHub で公開

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md2.9 KB
  • assets/security-checklist.md3.2 KB
  • references/vulnerability-patterns.md8.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security Review Skill

Ensures all code follows security best practices and identifies potential vulnerabilities.

When to Activate

  • Implementing authentication or authorization
  • Handling user input or file uploads
  • Creating new API endpoints
  • Working with secrets or credentials
  • Implementing payment features
  • Storing or transmitting sensitive data
  • Integrating third-party APIs

Security Checklist Categories

Review each category. See references/vulnerability-patterns.md for WRONG/CORRECT code examples.

  1. Secrets Management -- No hardcoded secrets; all in env vars; .env* gitignored
  2. Input Validation -- Schema validation; file upload size/type/extension checks
  3. SQL Injection -- Parameterized queries only; no string concatenation
  4. Auth & Authorization -- httpOnly cookies; RBAC; row-level/object-level authorization where needed
  5. XSS Prevention -- DOMPurify for user HTML; CSP headers configured
  6. CSRF Protection -- CSRF tokens on state-changing ops; SameSite=Strict cookies
  7. Rate Limiting -- All endpoints rate-limited; stricter on expensive operations
  8. Data Exposure -- No secrets in logs; generic error messages to users
  9. High-Risk Integrations -- Payments, wallets, third-party APIs, and webhooks validated when present
  10. Dependencies -- npm audit clean; lock files committed; Dependabot enabled

Full checkbox checklist: assets/security-checklist.md

Pre-Deployment Checklist

Before ANY production deployment, confirm ALL of the following:

  • No hardcoded secrets, all in env vars
  • All user inputs validated
  • All queries parameterized
  • User content sanitized (XSS)
  • CSRF protection enabled
  • Proper token handling (httpOnly cookies)
  • Authorization role checks in place
  • Rate limiting on all endpoints
  • HTTPS enforced
  • Security headers configured (CSP, X-Frame-Options)
  • No sensitive data in error messages or logs
  • Dependencies up to date, no vulnerabilities
  • CORS properly configured
  • File uploads validated (size, type)

References


Security is not optional. One vulnerability can compromise the entire platform. When in doubt, err on the side of caution.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.

日本語の概要は準備中です。原文の説明を表示しています。

cloudnative-co/claude-code-starter-kit1532026年10月8日 更新

ClickHouse database patterns, query optimization, analytics, and data engineering best practices for high-performance analytical workloads.

日本語の概要は準備中です。原文の説明を表示しています。

cloudnative-co/claude-code-starter-kit1532026年10月8日 更新

cloudnative-writing-baseline

無料日本語概要

日本語の業務文書を作成・修正するときに使用する共通品質基準。事実性、確度、論理、簡潔さ、自然な日本語を守る。提案書、報告、技術説明、議事録、メール、Slack、要約、レビューに適用する。創作、広告コピー、コードや構造化データだけの生成には使用しない。

cloudnative-co/claude-code-starter-kit1532026年10月8日 更新

Universal coding standards, best practices, and patterns for TypeScript, JavaScript, React, and Node.js development.

日本語の概要は準備中です。原文の説明を表示しています。

cloudnative-co/claude-code-starter-kit1532026年10月8日 更新

Formal evaluation framework for Claude Code sessions implementing eval-driven development (EDD) principles.

日本語の概要は準備中です。原文の説明を表示しています。

cloudnative-co/claude-code-starter-kit1532026年10月8日 更新

Frontend development patterns for React, Next.js, state management, performance optimization, and UI best practices.

日本語の概要は準備中です。原文の説明を表示しています。

cloudnative-co/claude-code-starter-kit1532026年10月8日 更新

cloudnative-co のスキルをすべて見る

このスキルの問題を報告する