Skills Plugins MCP Prompt Model 博客 我的中心
开发编程 #api #security

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

DeepseekModel 官方收录技能 质量 优秀 · 90 v1.0.0

获取

https://deepseekmodel.com/api/download.php?id=affaan-m-ecc-kiro-skills-security-review-skill-md&format=skill
下载 .skill 标准格式,含 system_prompt 与 model_config,导入任意 Agent 框架即可使用
.skill 文件中 system_prompt 字段的实际内容。
name security-review description Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns. metadata {"origin":"ECC"} Security Review Skill This skill ensures all code follows security best practices and identifies potential vulnerabilities. When to Activate Implementing authentication or authorization Handling user input or file uploads Creating new API endpoints Working with secrets or credentials Implementing payment features Storing or transmitting sensitive data Integrating third-party APIs Security Checklist 1. Secrets Management FAIL: NEVER Do This const apiKey = "sk-proj-xxxxx" // Hardcoded secret const dbPassword = "password123" // In source code PASS: ALWAYS Do This const apiKey = process. env . OPENAI_API_KEY const dbUrl = process. env . DATABASE_URL // Verify secrets exist if (!apiKey) { throw new Error ( 'OPENAI_API_KEY not configured' ) } Verification Steps No hardcoded API keys, tokens, or passwords All secrets in environment variables .env.local in .gitignore No secrets in git history Production secrets in hosting platform (Vercel, Railway) 2. Input Validation Always Validate User Input import { z } from 'zod' // Define validation schema const CreateUserSchema = z. object ({ email : z. string (). email (), name : z. string (). min ( 1 ). max ( 100 ), age : z. number (). int (). min ( 0 ). max ( 150 ) }) // Validate before processing export async function createUser ( input : unknown ) { try { const validated = CreateUserSchema . parse (input) return await db. users . create (validated) } catch (error) { if (error instanceof z. ZodError ) { return { success : false , errors : error. errors } } throw error } } File Upload Validation function validateFileUpload ( file : File ) { // Size check (5MB max) const maxSize = 5 * 1024 * 1024 if (file. size > maxSize) { throw new Error ( 'File too large (max 5MB)' ) } // Type check const allowedTypes = [ 'image/jpeg' , 'image/png' , 'image/gif' ] if (!allowedTypes. includes (file. type )) { throw new Error ( 'Invalid file type' ) } // Extension check const allowedExtensions = [ '.jpg' , '.jpeg' , '.png' , '.gif' ] const extension = file. name . toLowerCase (). match ( /\.[^.]+$/ )?.[ 0 ] if (!extension || !allowedExtensions. includes (extension)) { throw new Error ( 'Invalid file extension' ) } return true } Verification Steps All user inputs validated with schemas File uploads restricted (size, type, extension) No direct use of user input in queries Whitelist validation (not blacklist) Error messages don't leak sensitive info 3. SQL Injection Prevention FAIL: NEVER Concatenate SQL // DANGEROUS - SQL Injection vulnerability const query = `SELECT * FROM users WHERE email = ' ${userEmail} '` await db. query (query) PASS: ALWAYS Use Parameterized Queries // Safe - parameterized query const { data } = await supabase . from ( 'users' ) . select ( '*' ) . eq ( 'email' , userEmail) // Or with raw SQL await db. query ( 'SELECT * FROM users WHERE email = $1' , [userEmail] ) Verification Steps All database queries use parameterized queries No string concatenation in SQL ORM/query builder used correctly Supabase queries properly sanitized 4. Authentication & Authorization JWT Token Handling // FAIL: WRONG: localStorage (vulnerable to XSS) localStorage . setItem ( 'token' , token) // PASS: CORRECT: httpOnly cookies res. setHeader ( 'Set-Cookie' , `token= ${token} ; HttpOnly; Secure; SameSite=Strict; Max-Age=3600` ) Authorization Checks export async function deleteUser ( userId : string , requesterId : string ) { // ALWAYS verify authorization first const requester = await db. users . findUnique ({ where : { id : requesterId } }) if (requester. role !== 'admin' ) { return NextResponse . json ( { error : 'Unauthorized' }, { status : 403 } ) } // Proceed with deletion await db. users . delete ({ where : { id : userId } }) } Row Level Security (Supabase) -- Enable RLS on all tables ALTER TABLE users ENABLE ROW LEVEL SECURITY; -- Users can only view their own data CREATE POLICY "Users view own data" ON users FOR SELECT USING (auth.uid() = id); -- Users can only update their own data CREATE POLICY "Users update own data" ON users FOR UPDATE USING (auth.uid() = id); Verification Steps Tokens stored in httpOnly cookies (not localStorage) Authorization checks before sensitive operations Row Level Security enabled in Supabase Role-based access control implemented Session management secure 5. XSS Prevention Sanitize HTML import DOMPurify from 'isomorphic-dompurify' // ALWAYS sanitize user-provided HTML function renderUserContent ( html : string ) { const clean = DOMPurify . sanitize (html, { ALLOWED_TAGS : [ 'b' , 'i' , 'em' , 'strong' , 'p' ], ALLOWED_ATTR : [] }) return < div dangerouslySetInnerHTML = {{ __html: clean }} /> } Content Security Policy // next.config.js const securityHeaders = [ { key : 'Content-Security-Policy' , value : ` default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'; connect-src 'self' https://api.example.com; ` . replace ( /\s{2,}/g , ' ' ). trim () } ] Verification Steps User-provided HTML sanitized CSP headers configured No unvalidated dynamic content rendering React's built-in XSS protection used 6. CSRF Protection CSRF Tokens import { csrf } from '@/lib/csrf' export async function POST ( request : Request ) { const token = request. headers . get ( 'X-CSRF-Token' ) if (!csrf. verify (token)) { return NextResponse . json ( { error : 'Invalid CSRF token' }, { status : 403 } ) } // Process request } SameSite Cookies res. setHeader ( 'Set-Cookie' , `session= ${sessionId} ; HttpOnly; Secure; SameSite=Strict` ) Verification Steps CSRF tokens on state-changing operations SameSite=Strict on all cookies Double-submit cookie pattern implemented 7. Rate Limiting API Rate Limiting import rateLimit from 'express-rate-limit' const limiter = rateLimit ({ windowMs : 15 * 60 * 1000 , // 15 minutes max : 100 , // 100 requests per window message : 'Too many requests' }) // Apply to routes app. use ( '/api/' , limiter) Expensive Operations // Aggressive rate limiting for searches const searchLimiter = rateLimit ({ windowMs : 60 * 1000 , // 1 minute max : 10 , // 10 requests per minute message : 'Too many search requests' }) app. use ( '/api/search' , searchLimiter) Verification Steps Rate limiting on all API endpoints Stricter limits on expensive operations IP-based rate limiting User-based rate limiting (authenticated) 8. Sensitive Data Exposure Logging // FAIL: WRONG: Logging sensitive data console . log ( 'User login:' , { email, password }) console . log ( 'Payment:' , { cardNumber, cvv }) // PASS: CORRECT: Redact sensitive data console . log ( 'User login:' , { email, userId }) console . log ( 'Payment:' , { last4 : card. last4 , userId }) Error Messages // FAIL: WRONG: Exposing internal details catch (error) { return NextResponse . json ( { error : error. message , stack : error. stack }, { status : 500 } ) } // PASS: CORRECT: Generic error messages catch (error) { console . error ( 'Internal error:' , error) return NextResponse . json ( { error : 'An error occurred. Please try again.' }, { status : 500 } ) } Verification Steps No passwords, tokens, or secrets in logs Error messages generic for users Detailed errors only in server logs No stack traces exposed to users 9. Blockchain Security (Solana) Wallet Verification import { verify } from '@solana/web3.js' async function verifyWalletOwnership ( publicKey : string , signature : string , message : string ) { try { const isValid = verify ( Buffer . from (message), Buffer . from (signature, 'base64' ), Buffer . from (publicKey, 'base64' ) ) return isValid } catch (error) { return false } } Transaction Verification async function verifyTransaction ( transaction : Transaction ) { // Verify recipient if (transaction. to !== expectedRecipient) { throw new Error ( 'Invalid recipient' ) } // Verify amount if (transaction. amount > maxAmount) { throw new Error ( 'Amount exceeds limit' ) } // Verify user has sufficient balance const balance = await getBalance (transaction. from ) if (balance < transaction. amount ) { throw new Error ( 'Insufficient balance' ) } return true } Verification Steps Wallet signatures verified Transaction details validated Balance checks before transactions No blind transaction signing 10. Dependency Security Regular Updates # Check for vulnerabilities npm audit # Fix automatically fixable issues npm audit fix # Update dependencies npm update # Check for outdated packages npm outdated Lock Files # ALWAYS commit lock files git add package-lock.json # Use in CI/CD for reproducible builds npm ci # Instead of npm install Verification Steps Dependencies up to date No known vulnerabilities (npm audit clean) Lock files committed Dependabot enabled on GitHub Regular security updates Security Testing Automated Security Tests // Test authentication test ( 'requires authentication' , async () => { const response = await fetch ( '/api/protected' ) expect (response. status ). toBe ( 401 ) }) // Test authorization test ( 'requires admin role' , async () => { const response = await fetch ( '/api/admin' , { headers : { Authorization : `Bearer ${userToken} ` } }) expect (response. status ). toBe ( 403 ) }) // Test input validation test ( 'rejects invalid input' , async () => { const response = await fetch ( '/api/users' , { method : 'POST' , body : JSON . stringify ({ email : 'not-an-email' }) }) expect (response. status ). toBe ( 400 ) }) // Test rate limiting test ( 'enforces rate limits' , async () => { const requests = Array ( 101 ). fill ( null ). map ( () => fetch ( '/api/endpoint' ) ) const responses = await Promise . all (requests) const tooManyRequests = responses. filter ( r => r. status === 429 ) expect (tooManyRequests. length ). toBeGreaterThan ( 0 ) }) Pre-Deployment Security Checklist Before ANY production deployment: Secrets : No hardcoded secrets, all in env vars Input Validation : All user inputs validated SQL Injection : All queries parameterized XSS : User content sanitized CSRF : Protection enabled Authentication : Proper token handling
Agent 识别该技能的关键词,点击任意一个即可复制。

该技能未提供触发词。

下载的 .skill 包内含以下字段。
字段 说明
format格式标识(skill/v1)
skill_id技能唯一 ID
name技能名称
version版本号
description技能描述
category所属分类(数组)
trigger_words触发词列表
tags标签列表
source来源标识
source_url来源链接(本页地址)
exported_at导出时间(每次下载生成)
system_prompt系统提示词正文
model_config模型参数:provider / model / temperature / max_tokens / top_p
examples示例
install_guide各平台导入说明(Coze / Dify / Claude / 自定义框架)
同一份技能可按不同平台格式导出。
.skill 标准格式,含 system_prompt 与 model_config,导入任意 Agent 框架即可使用 下载
.skillpro 增强格式,额外含脚本 / 工具 / 依赖 / 钩子占位 下载
.json 纯 JSON 导出,只含 system_prompt 与模型参数 下载
Coze 带 frontmatter 的 Markdown,Coze 平台导入用 下载
Dify Dify DSL,创建应用后直接导入 下载

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

验证码 --

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。