本文へ移動
cccskills
無料GitHub で公開

dotnet-security

Security hardening and best practices for .NET applications. Navigation skill covering OWASP Top 10, authentication, authorization, cryptography, secrets management, and secure coding. For building secure applications. Keywords: security, owasp, authentication, authorization, cryptography, jwt, oauth, secrets, hardening

インストール方法を見る

含まれるファイル(1)

  • SKILL.md6.9 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

.NET Security

Security hardening and best practices for .NET applications. This meta-skill provides navigation to ~10 security-focused skills covering OWASP Top 10, authentication, authorization, cryptography, secrets management, and secure coding patterns.

When to Use This Skill

Load this skill when:

  • Implementing OWASP Top 10 mitigations
  • Setting up authentication and authorization
  • Choosing cryptographic algorithms
  • Managing secrets and credentials
  • Reviewing code for security issues
  • Hardening APIs and web applications

Quick Navigation

OWASP & Vulnerabilities

NeedLoad SkillLevel
OWASP Top 10 (2021)dotnet-security-owaspAdvanced
Input validationdotnet-input-validationIntermediate
Security headersdotnet-security-owaspAdvanced
Rate limitingdotnet-security-owaspAdvanced

Authentication & Authorization

NeedLoad SkillLevel
API security (JWT, OAuth)dotnet-api-securityAdvanced
Blazor authdotnet-blazor-authIntermediate
Passkeysdotnet-api-securityAdvanced

Cryptography

NeedLoad SkillLevel
Algorithm selectiondotnet-cryptographyAdvanced
Encryption/Hashingdotnet-cryptographyAdvanced
Key derivationdotnet-cryptographyAdvanced

Secrets Management

NeedLoad SkillLevel
User secretsdotnet-csharp-configurationIntermediate
Secret rotationdotnet-secrets-managementIntermediate
Environment variablesdotnet-secrets-managementIntermediate

Security Decision Trees

Which Authentication?

API → JWT Bearer (dotnet-api-security)
  ↓
Web App → OIDC/Cookies (dotnet-api-security)
  ↓
SPA → BFF pattern (dotnet-api-security)
  ↓
Mobile → OAuth 2.1 (dotnet-api-security)

Which OWASP Mitigation?

ThreatMitigationSkill
InjectionParameterized queriesdotnet-security-owasp
Broken Access ControlRBAC/ABACdotnet-api-security
XSSOutput encodingdotnet-security-owasp
Insecure DeserializationJSON-onlydotnet-security-owasp
Security MisconfigHardeningdotnet-security-owasp

Which Cryptography?

PurposeAlgorithmSkill
Symmetric encryptionAES-GCMdotnet-cryptography
Asymmetric encryptionRSA-OAEPdotnet-cryptography
HashingSHA-256/SHA-3dotnet-cryptography
SignaturesECDSA/RSA-PSSdotnet-cryptography
Password hashingArgon2iddotnet-cryptography
Key derivationHKDFdotnet-cryptography

Complete Skill List

OWASP & Vulnerabilities (2 skills)

  • dotnet-security-owasp - OWASP Top 10 mitigation
  • dotnet-input-validation - Request validation

Authentication & Authorization (3 skills)

  • dotnet-api-security - Identity, OAuth, JWT
  • dotnet-blazor-auth - Blazor auth flows
  • dotnet-csharp-configuration - User secrets

Cryptography (1 skill)

  • dotnet-cryptography - Algorithms, hashing, encryption

Secrets Management (2 skills)

  • dotnet-secrets-management - Secret management
  • dotnet-csharp-configuration - Configuration security

Secure Coding (2 skills)

  • dotnet-security-owasp - Deprecated API warnings
  • dotnet-csharp-coding-standards - Secure coding conventions

Security Checklist

Application Security

  • Input validation on all boundaries
  • Output encoding for dynamic content
  • Authentication on all endpoints
  • Authorization checks at business logic
  • Secure defaults (fail closed)
  • Security headers configured
  • Rate limiting implemented
  • Audit logging enabled

Data Security

  • Encryption at rest for sensitive data
  • Encryption in transit (TLS 1.3)
  • Secrets externalized (no hardcoding)
  • Secure key management
  • Data retention policies
  • Backup encryption

API Security

  • JWT validation (issuer, audience, expiry)
  • Scope/claim validation
  • CORS properly configured
  • CSRF protection where needed
  • API versioning for deprecations

Security Patterns

Input Validation

// Server-side validation
var validator = new CreateUserValidator();
var result = await validator.ValidateAsync(request);
if (!result.IsValid)
    return Results.ValidationProblem(result.ToDictionary());

// Never trust client input
public sealed class CreateUserRequest
{
    [Required, EmailAddress]
    public string Email { get; set; } = null!;
    
    [Required, MinLength(12)]
    public string Password { get; set; } = null!;
}

Secure Configuration

// Use user secrets in development
builder.Configuration.AddUserSecrets<Program>();

// Never commit secrets
if (builder.Environment.IsProduction())
{
    builder.Configuration.AddAzureKeyVault(...);
}

Output Encoding

// Razor encodes by default
@Model.UserInput  // HTML encoded

// Manual encoding when needed
var encoded = HtmlEncoder.Default.Encode(userInput);

Cross-References

  • Web Development → dotnet-web
  • API Design → dotnet-api-design
  • Architecture → dotnet-architecture
  • Fundamentals → dotnet-fundamentals

Security Headers

HeaderPurposeConfig
Content-Security-PolicyXSS preventionStrict CSP
X-Frame-OptionsClickjackingDENY
X-Content-Type-OptionsMIME sniffingnosniff
Referrer-PolicyPrivacystrict-origin
Permissions-PolicyFeature policyMinimal
Strict-Transport-SecurityHTTPS enforcementMax-age

Version Assumptions

  • .NET 8.0+ for modern security features
  • Identity requires .NET 6.0+
  • Passkeys require .NET 8.0+
  • Cryptography APIs are version-stable

Common Vulnerabilities

CWEIssuePrevention
CWE-79XSSOutput encoding
CWE-89SQL InjectionParameterized queries
CWE-200Info ExposureError handling
CWE-259Hardcoded PasswordSecret management
CWE-284Improper Access ControlAuthorization checks
CWE-352CSRFAnti-forgery tokens
CWE-434Unrestricted UploadFile validation
CWE-502DeserializationJSON-only, type constraints

See Also

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Patterns and techniques for evaluating and improving AI agent outputs.

日本語の概要は準備中です。原文の説明を表示しています。

rudironsoni/Synaxis22026年3月17日 更新

Comprehensive AI prompt engineering safety review and improvement prompt. Analyzes prompts for safety, bias, security vulnerabilities, and effectiveness while providing detailed improvement recommendations.

日本語の概要は準備中です。原文の説明を表示しています。

rudironsoni/Synaxis22026年3月17日 更新

Use when user requests research requiring multiple sources, comprehensive analysis, or synthesis across topics - technical research, domain knowledge gathering, market analysis, or learning about complex subjects

日本語の概要は準備中です。原文の説明を表示しています。

rudironsoni/Synaxis22026年3月17日 更新

deep-wiki

無料

AI-powered wiki generation for code repositories with commands, agents, and skills

日本語の概要は準備中です。原文の説明を表示しています。

rudironsoni/Synaxis22026年3月17日 更新

Use when building .NET 10 or C# 14 applications; when using minimal APIs, modular monolith patterns, or feature folders; when implementing HTTP resilience, Options pattern, Channels, or validation; when seeing outdated patterns like old extension method syntax

日本語の概要は準備中です。原文の説明を表示しています。

rudironsoni/Synaxis22026年3月17日 更新

Implements accessible .NET UI. SemanticProperties, ARIA, AutomationPeer, testing per platform.

日本語の概要は準備中です。原文の説明を表示しています。

rudironsoni/Synaxis22026年3月17日 更新

rudironsoni のスキルをすべて見る

このスキルの問題を報告する