> Security Standards

Universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, or any security-sensitive feature.

fetch
$curl "https://skillshub.wtf/HoangNguyen0403/agent-skills-standard/security-standards?format=md"
SKILL.mdSecurity Standards

Security Standards - High-Density Standards

Universal security protocols for building safe and resilient software.

Priority: P0 (CRITICAL)

🛡 Data Safeguarding

  • Zero Trust: Never trust external input. Sanitize and validate every data boundary (API, UI, CSV).
  • Least Privilege: Grant minimum necessary permissions to users, services, and containers.
  • No Hardcoded Secrets: Use environment variables or secret managers. Never commit keys or passwords.
  • Encryption: Use modern, collision-resistant algorithms (AES-256 for data-at-rest; TLS 1.3 for data-in-transit).
  • PII Logging: Never log PII (email, phone, names). Mask sensitive fields before logging.

🧱 Secure Coding Practices

  • Injection Prevention: Use parameterized queries or ORMs to stop SQL, Command, and XSS injections.
  • Dependency Management: Regularly scan (audit) and update third-party libraries to patch CVEs.
  • Secure Auth: Implement Multi-Factor Authentication (MFA) and secure session management.
  • Error Privacy: Never leak stack traces or internal implementation details to the end-user.

🔍 Continuous Security

  • Shift Left: Integrate security scanners (SAST/DAST) early in the CI/CD pipeline.
  • Data Minimization: Collect and store only the absolute minimum data required for the business logic.
  • Logging: Maintain audit logs for sensitive operations (Auth, Deletion, Admin changes).

🚫 Anti-Patterns

  • Hardcoded Secrets: **No Secrets in Git**: Use Secret Managers or Env variables.
  • Raw SQL: **No String Concatenation**: Use Parameterized queries or ORMs.
  • Leaking Context: **No Stacktraces in Prod**: Return generic error codes to clients.
  • Insecure Defaults: **No Default Passwords**: Force rotation and strong entropy.

📚 References

> related_skills --same-repo

> common-store-changelog

Generate user-facing release notes for the Apple App Store and Google Play Store by collecting git history, triaging user-impacting changes, and drafting store-compliant changelogs. Enforces character limits (App Store ≤4000, Google Play ≤500), tone, and bullet format. Use when generating release notes, app store changelog, play store release, what's new, or version release notes for any mobile app. (triggers: generate changelog, app store notes, play store release, what's new, release notes, ve

> golang-tooling

Go developer toolchain — gopls LSP diagnostics, linting, formatting, and vet. Use when setting up Go tooling, running linters, or integrating gopls with Claude Code. (triggers: gopls, golangci-lint, golangci.yml, go vet, goimports, staticcheck, go tooling, go lint)

> common-ui-design

Design distinctive, production-grade frontend UI with bold aesthetic choices. Use when building web components, pages, interfaces, dashboards, or applications in any framework (React, Next.js, Angular, Vue, HTML/CSS). (triggers: build a page, create a component, design a dashboard, landing page, UI for, build a layout, make it look good, improve the design, build UI, create interface, design screen)

> common-owasp

OWASP Top 10 audit checklist for Web Applications (2021) and APIs (2023). Load during any security review, PR review, or codebase audit touching web, mobile backend, or API code. (triggers: security review, OWASP, broken access control, IDOR, BOLA, injection, broken auth, API review, authorization, access control)

┌ stats

installs/wk0
░░░░░░░░░░
github stars452
██████████
first seenMar 17, 2026
└────────────

┌ repo

HoangNguyen0403/agent-skills-standard
by HoangNguyen0403
└────────────

┌ tags

└────────────