aif-security-checklist
SolidSecurity audit checklist based on OWASP Top 10 and best practices. Covers authentication, injection, XSS, CSRF, secrets management, and more. Use when reviewing security, before deploy, asking "is this secure", "security check", "vulnerability".
AI & Automation 3 stars
0 forks Updated today MIT
Install
Quality Score: 82/100
Stars 20%
Recency 20%
Frontmatter 20%
Documentation 15%
Issue Health 10%
License 10%
Description 5%
Skill Content
# Security Checklist
Comprehensive security checklist based on OWASP Top 10 (2021) and industry best practices.
## Quick Reference
- `$aif-security-checklist` — Full audit checklist
- `$aif-security-checklist auth` — Authentication & sessions
- `$aif-security-checklist injection` — SQL/NoSQL/Command injection
- `$aif-security-checklist xss` — Cross-site scripting
- `$aif-security-checklist csrf` — Cross-site request forgery
- `$aif-security-checklist secrets` — Secrets & credentials
- `$aif-security-checklist api` — API security
- `$aif-security-checklist infra` — Infrastructure security
- `$aif-security-checklist prompt-injection` — LLM prompt injection
- `$aif-security-checklist race-condition` — Race conditions & TOCTOU
- `$aif-security-checklist ignore <item>` — Ignore a specific check item
## Config
**FIRST:** Read `.ai-factory/config.yaml` if it exists to resolve:
- **Paths:** `paths.security`
- **Language:** `language.ui` for prompts
If config.yaml doesn't exist, use defaults:
- SECURITY.md: `.ai-factory/SECURITY.md`
- Language: `en` (English)
## Ignored Items (SECURITY.md)
Before running any audit, **always read** the resolved SECURITY.md path (default: `.ai-factory/SECURITY.md`). If it exists, it contains a list of security checks the team has decided to ignore.
### How ignoring works
**When the user runs `$aif-security-checklist ignore <item>`:**
1. Read the current resolved SECURITY.md file (create if it doesn't exist)
2. Ask the user for the reason why ...
Details
- Author
- maister-dev
- Repository
- maister-dev/maister
- Created
- 2 weeks ago
- Last Updated
- today
- Language
- TypeScript
- License
- MIT
Integrates with
Similar Skills
Semantically similar based on skill content — not just same category
AI & Automation Listed
security-audit-checklist
A PASS/FAIL/N/A checklist covering injection, authorization, secrets handling, dependency risk, and input validation for reviewing a diff or codebase.
1 Updated 5 days ago
niels-emmer AI & Automation Listed
add-security-audit
Security audit: OWASP Top 10, multi-tenancy, injection, auth, XSS, dependencies.
9 Updated today
brabos-ai AI & Automation Listed
qa-security
Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.
5 Updated today
christopherlouet