security
Harden Web Security Boundaries
Security reviews often miss validation, authorization, session, and secret-handling weaknesses. This skill gives developers a practical defensive checklist for safer web changes.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "security" from https://skillstore.io/skills/shreyam1008-security.md and its manifest at https://skillstore.io/api/skills/shreyam1008-security/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "security". Review a login endpoint that accepts credentials and creates a session cookie.
Expected outcome:
- Validate credentials on the server.
- Use a maintained password hashing library.
- Rotate the session after login and set Secure, HttpOnly, and SameSite attributes.
- Add rate limiting and tests for failed authorization.
Using "security". Assess a profile page that renders a user biography and accepts a redirect parameter.
Expected outcome:
Encode biography content for its output context, sanitize approved rich text, and allow redirects only to trusted destinations.
Security Audit
SafeAll 12 static findings are false positives caused by security terms, Markdown code spans, and a legitimate OWASP reference in SKILL.md. The file provides defensive guidance and contains no executable commands, secret access, malicious network behavior, or prompt injection evidence.
Risk Factors
โ๏ธ External commands (8)
๐ Network access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/shreyam1008-security/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/shreyam1008-security?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/shreyam1008-security?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/shreyam1008-security/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/shreyam1008-security.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
shreyam1008. (2026). security security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/shreyam1008-security/audits/1BibTeX citation
@techreport{shreyam1008-shreyam1008-security-2026,
author = {shreyam1008},
title = {security security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/shreyam1008-security/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "security security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "shreyam1008"
date-released: "2026-10-02"
url: "https://skillstore.io/skills/shreyam1008-security/audits/1"
identifiers:
- type: other
value: "skillstore:shreyam1008-security:audit:1"
description: "Skillstore immutable audit report identifier"
Compare variants
2 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
byronwilliamscpa-security
2026-09-09
shreyam1008-security
2026-10-04
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Review a Web Feature
Use the checklist to examine validation, output encoding, authorization, sessions, and secrets before merging a feature.
Assess an API Endpoint
Check an endpoint for injection, CSRF, object-level authorization, redirect, SSRF, and sensitive logging risks.
Prepare a Security Review
Turn common application-security controls into a structured review agenda for a team or release.
Try These Prompts
Review this web change for input validation, output encoding, authorization, sessions, CSRF, and secret-handling issues.
Analyze this API route. Identify trust boundaries, validation gaps, injection risks, authorization failures, and unsafe response handling.
Assess this authentication flow for password storage, session rotation, token lifetime, logout invalidation, and constant-time comparisons.
Build a prioritized remediation plan from this security review. Include evidence, impact, recommended controls, tests, and residual risk.
Best Practices
- Validate and normalize untrusted input at the server boundary.
- Use framework protections and vetted libraries before custom security code.
- Test authorization, error paths, secure headers, logging, and secret handling.
Avoid
- Trusting client-side validation or identifiers for authorization.
- Concatenating untrusted input into queries, commands, HTML, or URLs.
- Storing plaintext passwords or logging secrets, tokens, and full authorization headers.
Frequently Asked Questions
What does this skill review?
Does it scan my application automatically?
Can it review authentication flows?
Does it replace penetration testing?
Which applications benefit most?
How should teams use the recommendations?
Developer Details
Author
shreyam1008License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
bbec03cf10354f3aaccd6dd24eda4ac9ceeceac5
Maintenance freshness
10/2/2026
Usage
0 downloads ยท 0 views
File structure
๐ SKILL.md