security-checklist

Solid

OWASP Top 10, input validation, SQL injection prevention, rate limiting, CORS. Use when reviewing code for security issues, setting up a new API, or doing a pre-deploy security audit.

AI & Automation 30 stars 9 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
50
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Security Checklist ## OWASP Top 10 — Quick Reference | # | Risk | Mitigation | |---|------|-----------| | A01 | Broken Access Control | Always authorize, not just authenticate | | A02 | Cryptographic Failures | TLS everywhere, bcrypt passwords, no MD5/SHA1 | | A03 | Injection | Parameterized queries, ORM, input validation | | A04 | Insecure Design | Threat model, rate limiting, abuse cases | | A05 | Security Misconfiguration | Disable defaults, review headers | | A06 | Vulnerable Components | `npm audit`, `pnpm audit`, Dependabot | | A07 | Auth Failures | MFA, account lockout, secure sessions | | A08 | Integrity Failures | Verify build artifacts, signed commits | | A09 | Logging Failures | Log auth events, anomaly detection | | A10 | SSRF | Validate URLs, block internal IPs | ## Input Validation ```typescript // ALWAYS validate at every system boundary using Zod or class-validator // NestJS — enable globally app.useGlobalPipes( new ValidationPipe({ whitelist: true, // strip unknown properties forbidNonWhitelisted: true, // throw on unknown props transform: true, // auto-coerce types transformOptions: { enableImplicitConversion: false, }, }) ) // Zod at service boundaries const CreateOrderSchema = z.object({ userId: z.string().uuid(), items: z.array(z.object({ productId: z.string().uuid(), quantity: z.number().int().min(1).max(100), })).min(1).max(50), couponCode: z.string().max(20).opti...

Details

Author
sabahattink
Repository
sabahattink/antigravity-fullstack-hq
Created
8 months ago
Last Updated
5 days ago
Language
PowerShell
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category