aif-security-checklist

Solid

Security audit checklist based on OWASP Top 10 and best practices. Covers authentication, injection, XSS, CSRF, secrets management, and more. Use when reviewing security, before deploy, asking "is this secure", "security check", "vulnerability".

AI & Automation 3 stars 0 forks Updated today MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
20
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Security Checklist Comprehensive security checklist based on OWASP Top 10 (2021) and industry best practices. ## Quick Reference - `$aif-security-checklist` — Full audit checklist - `$aif-security-checklist auth` — Authentication & sessions - `$aif-security-checklist injection` — SQL/NoSQL/Command injection - `$aif-security-checklist xss` — Cross-site scripting - `$aif-security-checklist csrf` — Cross-site request forgery - `$aif-security-checklist secrets` — Secrets & credentials - `$aif-security-checklist api` — API security - `$aif-security-checklist infra` — Infrastructure security - `$aif-security-checklist prompt-injection` — LLM prompt injection - `$aif-security-checklist race-condition` — Race conditions & TOCTOU - `$aif-security-checklist ignore <item>` — Ignore a specific check item ## Config **FIRST:** Read `.ai-factory/config.yaml` if it exists to resolve: - **Paths:** `paths.security` - **Language:** `language.ui` for prompts If config.yaml doesn't exist, use defaults: - SECURITY.md: `.ai-factory/SECURITY.md` - Language: `en` (English) ## Ignored Items (SECURITY.md) Before running any audit, **always read** the resolved SECURITY.md path (default: `.ai-factory/SECURITY.md`). If it exists, it contains a list of security checks the team has decided to ignore. ### How ignoring works **When the user runs `$aif-security-checklist ignore <item>`:** 1. Read the current resolved SECURITY.md file (create if it doesn't exist) 2. Ask the user for the reason why ...

Details

Author
maister-dev
Repository
maister-dev/maister
Created
2 weeks ago
Last Updated
today
Language
TypeScript
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category