All authors

Claude Skills by claude-dev-suite
github.com/claude-dev-suite740 skills14 installs1,174 views
- Rag ProductionOperational concerns for RAG at scale. Incremental indexing (CDC, doc diffing), blue-green re-indexing, index aliases/versioning, embedding-model hot-swap, cost optimization (dimension reduction, cheaper embed models), capacity and token budgets, p50/p95/p99 SLAs, horizontal scaling, multi-tenant isolation, async ingestion (Kafka/Pub-Sub). USE WHEN: user mentions "incremental indexing", "reindex", "index alias", "blue-green reindex", "RAG cost optimization", "multi-tenant RAG", "RAG capacity...Votes: 0GitHub stars: 31
- Rag SecuritySecurity controls for RAG. Indirect prompt-injection via retrieved documents, PII detection/redaction (Microsoft Presidio, AWS Comprehend), multi-tenant isolation, ACL-aware retrieval with row-level/metadata filtering, data-leakage prevention, jailbreak hardening on retrieved context, GDPR right-to-be-forgotten in vector DBs. USE WHEN: user mentions "prompt injection RAG", "indirect prompt injection", "PII redaction", "Presidio", "ACL RAG", "row-level security", "multi-tenant RAG isolation",...Votes: 0GitHub stars: 31
- RerankingReranking retrieved documents with cross-encoders and LLM rerankers. Cohere Rerank v3, Voyage rerank-2, BGE reranker, ColBERT late interaction, Jina reranker. Cost and latency tradeoffs, top-K in / top-N out strategy. USE WHEN: user mentions "rerank", "reranker", "cross-encoder", "Cohere Rerank", "Voyage rerank", "BGE reranker", "ColBERT", "Jina reranker", "bi-encoder" DO NOT USE FOR: initial retrieval - use `advanced-retrieval` or `hybrid-search`; query rewriting - use `query-transformatio...Votes: 0GitHub stars: 31
- Self Querying RetrieverLangChain SelfQueryRetriever pattern. LLM infers structured metadata filters from natural language ("books by Asimov after 2000" -> filter author=Asimov AND year>2000). Metadata schema declaration, comparators and operators, LlamaIndex AutoRetriever equivalent, combining with hybrid search, evaluation of filter correctness. USE WHEN: user mentions "self-querying retriever", "SelfQueryRetriever", "auto retriever", "metadata filter from query", "NL to filter", "AutoRetriever" DO NOT USE FOR: ...Votes: 0GitHub stars: 31
- Shadow Mode DeploymentShadow and canary deployment of RAG pipeline changes: dual-execute new + old, offline LLM-judge comparison, gradual traffic ramp, auto-rollback guardrails, multi-armed bandits, per-component feature flags (retriever, reranker, generator). USE WHEN: user mentions "shadow mode", "canary deployment", "dual execute", "shadow traffic RAG", "feature flags RAG", "multi-armed bandit", "auto rollback", "LaunchDarkly RAG", "Unleash RAG" DO NOT USE FOR: CI pre-merge eval - use `continuous-evaluation`;...Votes: 0GitHub stars: 31
- Streaming RagStreaming LLM responses with inline citations. Token-level source attribution, SSE vs WebSocket, TTFT optimization, progressive disclosure (retrieval status then tokens), Python async generators, Vercel AI SDK streaming with sources, LangChain streaming callbacks, client-side citation rendering. USE WHEN: user mentions "streaming RAG", "streaming citations", "SSE RAG", "TTFT", "progressive disclosure", "AI SDK streaming", "token streaming", "inline citations" DO NOT USE FOR: generic RAG pip...Votes: 0GitHub stars: 31
- Tabular RagStructured data + RAG. NL2SQL hybrid patterns (text-to-SQL then execute vs embed rows), table embedding strategies (row-level, schema-level, hybrid), semantic layer integration (Cube, dbt metrics), LangChain SQLDatabaseChain, LlamaIndex PandasQueryEngine, safe SQL execution (read-only, sandboxed), schema-aware retrieval. Full PostgreSQL + pgvector hybrid code. USE WHEN: user mentions "tabular RAG", "NL2SQL", "text to SQL", "RAG on tables", "database RAG", "SQL RAG", "semantic layer", "struct...Votes: 0GitHub stars: 31
- Time Aware RetrievalTemporal awareness in RAG. Recency bias weighting, exponential decay scoring, time-range filtering, LLM-based date extraction ("last quarter", "yesterday"), temporal knowledge graphs, freshness vs authority tradeoff, event-based retrieval, timestamp metadata, differential reindexing of old vs fresh docs. USE WHEN: user mentions "time-aware RAG", "recency bias", "temporal retrieval", "freshness", "date filter", "temporal knowledge graph", "exponential decay" DO NOT USE FOR: static metadata f...Votes: 0GitHub stars: 31
- Socket IoSocket.IO real-time bidirectional communication. Rooms, namespaces, acknowledgments, middleware, scaling with Redis adapter, and TypeScript types. USE WHEN: user mentions "Socket.IO", "socket.io", "real-time chat", "live updates", "bidirectional WebSocket", "rooms", "namespaces" DO NOT USE FOR: SSE (server-sent events) - use `sse`; WebRTC - use `webrtc`; raw WebSocket without Socket.IO - use framework WS skillsVotes: 0GitHub stars: 31
- SseServer-Sent Events for real-time server-to-client streaming. Express, Fastify, FastAPI, Spring WebFlux SSE implementations. Event streams, reconnection, and EventSource API. USE WHEN: user mentions "SSE", "Server-Sent Events", "EventSource", "event stream", "text/event-stream", "live feed", "streaming updates" DO NOT USE FOR: bidirectional communication - use `socket-io`; WebRTC - use `webrtc`; LLM streaming - use AI SDK skillsVotes: 0GitHub stars: 31
- WebrtcWebRTC peer-to-peer communication. Signaling, ICE/STUN/TURN, media streams, data channels, screen sharing, and SFU integration (mediasoup, LiveKit). USE WHEN: user mentions "WebRTC", "video call", "peer-to-peer", "P2P", "screen sharing", "data channel", "STUN", "TURN", "mediasoup", "LiveKit" DO NOT USE FOR: server-to-client streaming - use `sse`; chat messaging - use `socket-io`Votes: 0GitHub stars: 31
- Bm25 TuningBM25 deep tuning. k1 and b parameters with defaults per collection, field boosts, stopwords, language-specific analyzers (Italian, French, German, non-English), stemming vs lemmatization, tokenization gotchas, Elasticsearch vs Lucene vs rank_bm25. When BM25 alone beats vectors. USE WHEN: user mentions "BM25", "BM25 tuning", "k1 b parameter", "Elasticsearch analyzer", "stemming", "lemmatization", "rank_bm25", "TF-IDF", "lexical search" DO NOT USE FOR: learned sparse - use `retrieval/splade-d...Votes: 0GitHub stars: 31
- Colbert RetrievalColBERT / ColBERTv2 late interaction as a first-stage retriever — not just a reranker. MaxSim scoring, PLAID index, Ragatouille for deployment, storage cost of token-level embeddings, when to pick ColBERT over dense-plus-rerank, and fine-tuning for domain. USE WHEN: user mentions "ColBERT", "ColBERTv2", "late interaction", "MaxSim", "PLAID", "Ragatouille", "token-level embeddings", "multi-vector retrieval" DO NOT USE FOR: single-vector dense retrieval - use `vector-stores/qdrant-advanced` o...Votes: 0GitHub stars: 31
- Cross Encoder TrainingFine-tuning cross-encoders for domain-specific reranking. Training data (query-doc relevance labels, MS MARCO format), sentence-transformers CrossEncoder API, loss functions (BCE, margin), hard negative mining from BM25 and dense retrievers, distillation from strong teacher rerankers (BGE-reranker-v2, Cohere) into small models, NDCG@10 evaluation. USE WHEN: user mentions "fine-tune cross-encoder", "train reranker", "hard negative mining", "MS MARCO triples", "knowledge distillation reranker"...Votes: 0GitHub stars: 31
- Rank GptLLM-as-reranker patterns. RankGPT listwise / pairwise / pointwise prompting, sliding window for long candidate lists, cost-latency vs Cohere Rerank, calibration tricks, structured output for rank lists. Code uses the Anthropic SDK. USE WHEN: user mentions "LLM reranker", "RankGPT", "listwise reranking", "pairwise reranking", "pointwise reranking", "GPT reranker", "Claude reranker" DO NOT USE FOR: standard cross-encoder reranking - use `rag/reranking`; fine-tuning cross-encoders - use `retri...Votes: 0GitHub stars: 31
- Splade DeepSPLADE / SPLADE++ learned sparse retrieval in depth. How SPLADE differs from BM25 (learned term expansion), FLOPS regularization, indexing in Qdrant sparse vectors and Elasticsearch, hybrid with dense, efficiency tradeoffs, and when SPLADE beats BM25. USE WHEN: user mentions "SPLADE", "SPLADE++", "learned sparse", "neural sparse", "FLOPS regularization", "sparse vector retrieval", "naver/splade" DO NOT USE FOR: classical BM25 tuning - use `retrieval/bm25-tuning`; dense retrieval - use `vect...Votes: 0GitHub stars: 31
- CppReviewing C++ code - what to flag, and what the compiler, clang-tidy and sanitizers already flag for you USE WHEN: you are reviewing, critiquing or auditing existing C++ code - a "code review", a "review" of a .cpp/.hpp/.cc/.h file, a diff, a PR or a pull request; deciding what to comment on in C++; avoiding false positives on C++ DO NOT USE FOR: writing, explaining or learning C++ - use `languages/cpp`; anything `-Wall -Wextra`, clang-tidy or a sanitizer run already reports (this skill lis...Votes: 0GitHub stars: 31
- CsharpReviewing C# code - what to flag, and what Roslyn analyzers and nullable reference types already flag for you USE WHEN: you are reviewing, critiquing or auditing existing C# code - a "code review", a "review" of a .cs file, a diff, a PR or a pull request; deciding what to comment on in C#; avoiding false positives on C# code DO NOT USE FOR: writing, explaining or learning C# - use `languages/csharp`; anything the built-in Roslyn analyzers or nullable reference types already report (this ski...Votes: 0GitHub stars: 31
- GoReviewing Go code - what to flag, and what the toolchain already flags for you USE WHEN: you are reviewing, critiquing or auditing existing Go code - a "code review", a "review" of a .go file, a diff, a PR or a pull request; deciding what to comment on in Go; avoiding false positives on Go code DO NOT USE FOR: writing, explaining or learning Go - use `languages/go`; anything `go vet` or a default golangci-lint run already reports (this skill lists those so you can stay silent about them); f...Votes: 0GitHub stars: 31
- JavaReviewing Java code - what to flag, and what javac, the IDE and SpotBugs already flag for you USE WHEN: you are reviewing, critiquing or auditing existing Java code - a "code review", a "review" of a .java file, a diff, a PR or a pull request; deciding what to comment on in Java; avoiding false positives on Java code DO NOT USE FOR: writing, explaining or learning Java - use `languages/java`; anything javac warnings, SpotBugs or a standard Checkstyle run already report (this skill lists tho...Votes: 0GitHub stars: 31
- KotlinReviewing Kotlin code - what to flag, and what the compiler, detekt and ktlint already flag for you USE WHEN: you are reviewing, critiquing or auditing existing Kotlin code - a "code review", a "review" of a .kt file, a diff, a PR or a pull request; deciding what to comment on in Kotlin; avoiding false positives on Kotlin code DO NOT USE FOR: writing, explaining or learning Kotlin - use `languages/kotlin`; anything the compiler, detekt or ktlint already reports (this skill lists those so yo...Votes: 0GitHub stars: 31
- NodejsReviewing Node.js runtime code - what to flag beyond the language, and what the toolchain already flags USE WHEN: you are reviewing, critiquing or auditing existing Node.js code - a "code review" of server code, a CLI, a script, a diff or a PR - and the concern is the RUNTIME: the event loop, streams, processes, file handles, EventEmitter, unhandled rejections DO NOT USE FOR: language-level review - use `review/typescript` for typed code; Express/NestJS/Fastify routing - use the framework s...Votes: 0GitHub stars: 31
- PythonReviewing Python code - what to flag, and what ruff, mypy and the interpreter already flag for you USE WHEN: you are reviewing, critiquing or auditing existing Python code - a "code review", a "review" of a .py file, a diff, a PR or a pull request; deciding what to comment on in Python; avoiding false positives on Python code DO NOT USE FOR: writing, explaining or learning Python - use `languages/python`; anything ruff's default rules or a configured mypy already reports (this skill lists t...Votes: 0GitHub stars: 31
- RustReviewing Rust code - what to flag, and what rustc and clippy already flag for you USE WHEN: you are reviewing, critiquing or auditing existing Rust code - a "code review", a "review" of a .rs file, a diff, a PR or a pull request; deciding what to comment on in Rust; avoiding false positives on Rust code DO NOT USE FOR: writing, explaining or learning Rust - use `languages/rust`; anything rustc or a default clippy run already reports (this skill lists those so you can stay silent about them...Votes: 0GitHub stars: 31
- SqlReviewing SQL - what to flag, and what the database and linters actually check for you USE WHEN: you are reviewing, critiquing or auditing existing SQL - a "code review" of a query, a migration, a stored procedure, a view, or ORM-generated SQL in a diff or a PR; deciding what to comment on in SQL; judging whether a query is correct under concurrency and at scale DO NOT USE FOR: writing or learning SQL - use `databases/sql-fundamentals` or `databases/sql-advanced`; vendor-specific tuning - u...Votes: 0GitHub stars: 31
- SwiftReviewing Swift code - what to flag, and what the compiler and SwiftLint already flag for you USE WHEN: you are reviewing, critiquing or auditing existing Swift code - a "code review", a "review" of a .swift file, a diff, a PR or a pull request; deciding what to comment on in Swift; avoiding false positives on Swift code DO NOT USE FOR: writing, explaining or learning Swift - use `languages/swift`; anything the compiler or a configured SwiftLint already reports (this skill lists those so yo...Votes: 0GitHub stars: 31
- TypescriptReviewing TypeScript code - what to flag, and what the compiler and linter already flag for you USE WHEN: you are reviewing, critiquing or auditing existing TypeScript or TSX code - a "code review", a "review" of a .ts/.tsx file, a diff, a PR or a pull request; deciding what to comment on in TypeScript; avoiding false positives on typed JavaScript DO NOT USE FOR: writing, explaining or learning TypeScript - use `languages/typescript`; anything `tsc` under `strict` or a default typescript-es...Votes: 0GitHub stars: 31
- Age Encryptionage — modern file encryption format and tool by Filippo Valsorda. Replaces GPG for most use cases (encrypted backups, exports, secrets in CI). Covers age CLI, X25519 + Scrypt-based recipients, SSH key recipients, plugin system (YubiKey, Secure Enclave, age-keyring), Rust (`age` crate), Go (filippo.io/age), encrypted backup workflows for wallets. USE WHEN: user mentions "age", "age-encryption", "rage", "filippo.io/age", "ssh-rsa age", "age plugin", "age-yubikey", "age recipient", "age identit...Votes: 0GitHub stars: 31
- Ai Code SecuritySecurity review of AI-generated code, and secure practices for working with coding assistants. USE WHEN: reviewing AI-generated code (GitHub Copilot, ChatGPT, Claude, etc.) for security vulnerabilities, or establishing secure AI coding practices DO NOT USE FOR: AI/ML model security, prompt injection attacks on AI systems, or general code reviewVotes: 0GitHub stars: 31
- Api SecurityAPI security across REST, GraphQL and gRPC, organised around the OWASP API Security Top 10:2023. USE WHEN: designing, implementing, or auditing REST, GraphQL, or gRPC APIs for security vulnerabilities DO NOT USE FOR: general API design patterns (use the `rest-api` / `graphql` skills), authentication setup (use the `jwt` / `oauth2` skills)Votes: 0GitHub stars: 31
- Audit LoggingAudit logging for compliance and security. Structured audit events, immutable logs, user action tracking, database change tracking, and regulatory compliance (SOC2, HIPAA, GDPR). USE WHEN: user mentions "audit log", "audit trail", "activity log", "change tracking", "compliance logging", "who changed what", "SOC2 logging" DO NOT USE FOR: application logging - use logging skills; error tracking - use observability skillsVotes: 0GitHub stars: 31
- Container SecurityContainer and Kubernetes security: hardening images, runtime configuration and deployment manifests. USE WHEN: securing Docker containers, Kubernetes deployments, or reviewing container configurations DO NOT USE FOR: general Docker usage (use the `docker` skill), Kubernetes architecture (use the `kubernetes` skill)Votes: 0GitHub stars: 31
- Cors Security HeadersCORS configuration and HTTP security headers. CORS middleware, preflight requests, Content-Security-Policy, CSRF protection, Helmet.js, and secure cookie configuration. USE WHEN: user mentions "CORS", "cross-origin", "CSP", "Content-Security-Policy", "CSRF", "security headers", "Helmet", "preflight", "Access-Control" DO NOT USE FOR: authentication tokens - use `jwt` or `oauth2`; encryption - use `cryptography`Votes: 0GitHub stars: 31
- Cpp SecurityC++ memory and concurrency safety: AddressSanitizer (ASan), UndefinedBehaviorSanitizer (UBSan), ThreadSanitizer (TSan), MemorySanitizer (MSan), MSVC `/sdl` and `/guard:cf`, CERT C++ secure coding rules, integer-overflow safe arithmetic, and Control Flow Integrity. USE WHEN: user mentions "ASan", "AddressSanitizer", "UBSan", "TSan", "MSan", "use-after-free", "buffer overflow", "undefined behavior", "data race", "CERT C++", "secure C++", "/sdl", "/GS", "ASLR", "DEP", "stack canary" DO NOT USE...Votes: 0GitHub stars: 31
- CryptographyApplication-level cryptography. Password hashing (bcrypt, argon2), encryption (AES-GCM), digital signatures, key management, and secure random generation. USE WHEN: user mentions "encryption", "hashing", "bcrypt", "argon2", "AES", "cryptography", "digital signature", "key management", "HMAC" DO NOT USE FOR: TLS/HTTPS configuration - use infrastructure skills; JWT tokens - use `jwt`; OAuth flows - use `oauth2`Votes: 0GitHub stars: 31
- Dotnet Security.NET and ASP.NET Core security patterns. Covers Identity, authentication, dependency auditing, secure coding practices, and OWASP for .NET ecosystem. USE WHEN: user works with "C#", ".NET", "ASP.NET Core", "Entity Framework", asks about ".NET vulnerabilities", "NuGet security", ".NET authentication", "Blazor security" DO NOT USE FOR: general OWASP concepts - use `owasp` or `owasp-top-10` instead, Java/Python security - use language-specific skillsVotes: 0GitHub stars: 31
- GdprGDPR compliance implementation. Data subject rights (access, deletion, portability), consent management, data processing records, PII handling, and privacy by design patterns. USE WHEN: user mentions "GDPR", "data privacy", "right to be forgotten", "data deletion", "consent management", "PII", "data subject request", "privacy policy", "cookie consent" DO NOT USE FOR: authentication - use auth skills; encryption - use `cryptography`; audit logging - use `audit-logging`Votes: 0GitHub stars: 31
- Go SecurityGo security patterns for web applications. Covers dependency auditing, secure coding practices, crypto, and OWASP for Go ecosystem. USE WHEN: user works with "Go", "Golang", "Gin", "Fiber", "Echo", asks about "Go vulnerabilities", "Go modules security", "Go injection", "Go authentication" DO NOT USE FOR: general OWASP concepts - use `owasp` or `owasp-top-10` instead, other language security - use language-specific skillsVotes: 0GitHub stars: 31
- Iac SecurityInfrastructure-as-Code security for Terraform, CloudFormation, Ansible, Pulumi and similar configuration. USE WHEN: securing Terraform, CloudFormation, Ansible, Pulumi, or other IaC configurations DO NOT USE FOR: general IaC patterns, cloud architecture design, cost optimizationVotes: 0GitHub stars: 31
- Java SecurityJava and Spring Boot security patterns. Covers Spring Security, dependency auditing, secure coding practices, and OWASP for Java ecosystem. USE WHEN: user works with "Java", "Spring Boot", "Spring Security", asks about "Java vulnerabilities", "Maven security", "Gradle security", "Java injection", "Java authentication" DO NOT USE FOR: general OWASP concepts - use `owasp` or `owasp-top-10` instead, Node.js/Python security - use language-specific skillsVotes: 0GitHub stars: 31
- Kotlin SecurityKotlin application security for backend and Android: vulnerability review and secure implementation patterns. USE WHEN: securing Kotlin applications (backend/Android), reviewing code for vulnerabilities, or implementing security best practices DO NOT USE FOR: code quality issues (use `kotlin-quality`), general Kotlin patterns, UI/UX concernsVotes: 0GitHub stars: 31
- Libsodiumlibsodium — modern, easy-to-use, audited crypto library. Provides authenticated encryption (XSalsa20-Poly1305, XChaCha20-Poly1305, AES-GCM), public-key cryptography (X25519, Ed25519), key derivation (Argon2id, HKDF, BLAKE2b), password hashing, and authenticated streams (secretstream). Wraps NaCl with better defaults. Bindings for Rust (sodiumoxide, libsodium-sys-stable, dryoc), Python (PyNaCl), JS (libsodium-wrappers), Java/Android (lazysodium-android), Swift (Sodium / Clibsodium). USE WHEN:...Votes: 0GitHub stars: 31
- License ComplianceOpen source license compliance and SPDX standards. Covers license types, compatibility, auditing with license-checker, and SBOM generation. USE WHEN: user mentions "license", "SPDX", "GPL", "MIT", "Apache", asks about "license compatibility", "license-checker", "copyleft", "proprietary compliance", "OSI approved" DO NOT USE FOR: dependency vulnerabilities - use `supply-chain`, security scanning - use `owasp-top-10`, secrets - use `secrets-management`Votes: 0GitHub stars: 31
- Owasp Top 10OWASP Top 10:2025 security vulnerabilities. Covers access control, injection, supply chain, cryptographic failures, and more. Use for security reviews. USE WHEN: user mentions "OWASP 2025", "Top 10", "security review", "vulnerability assessment", asks about "broken access control", "injection", "supply chain", "cryptographic failures", "exception handling" DO NOT USE FOR: general OWASP (2021) - use `owasp` instead, secrets - use `secrets-management`, dependencies - use `supply-chain`Votes: 0GitHub stars: 31
- OwaspOWASP security guidelines and Top 10 vulnerabilities USE WHEN: user mentions "OWASP", "security audit", "vulnerability scan", asks about "injection", "XSS", "CSRF", "access control", "authentication security" DO NOT USE FOR: OWASP Top 10:2025 specific - use `owasp-top-10` insteadVotes: 0GitHub stars: 31
- Php SecurityPHP application security: vulnerability review and secure implementation patterns. USE WHEN: securing PHP applications, reviewing code for vulnerabilities, or implementing security best practices DO NOT USE FOR: code quality issues (use `php-quality`), general PHP development patternsVotes: 0GitHub stars: 31
- Python SecurityPython security patterns for Django, FastAPI, and Flask. Covers Bandit, Safety, secure coding practices, and OWASP for Python ecosystem. USE WHEN: user works with "Python", "Django", "FastAPI", "Flask", asks about "Python vulnerabilities", "pip security", "Bandit", "Python injection", "Python authentication" DO NOT USE FOR: general OWASP concepts - use `owasp` or `owasp-top-10` instead, Node.js/Java security - use language-specific skillsVotes: 0GitHub stars: 31
- Rate LimitingRate limiting and throttling. Token bucket, sliding window, fixed window algorithms. Express rate limit, Spring rate limiting, Redis-based distributed rate limiting, and API quota management. USE WHEN: user mentions "rate limit", "throttle", "API quota", "too many requests", "429", "express-rate-limit", "sliding window", "token bucket" DO NOT USE FOR: circuit breaker patterns - use `resilience-patterns`; DDoS protection - use infrastructure/WAF solutionsVotes: 0GitHub stars: 31
- Rust SecurityRust security patterns for web applications. Covers memory safety guarantees, dependency auditing, secure coding practices, and OWASP for Rust ecosystem. USE WHEN: user works with "Rust", "Actix", "Axum", "Rocket", "Warp", asks about "Rust vulnerabilities", "cargo audit", "Rust injection", "Rust authentication" DO NOT USE FOR: general OWASP concepts - use `owasp` or `owasp-top-10` instead, other language security - use language-specific skillsVotes: 0GitHub stars: 31
- Secrets ManagementSecrets and credentials management. Covers environment variables, secret stores, rotation policies, and detection of leaked secrets. USE WHEN: user mentions "secrets", "credentials", "API keys", "environment variables", ".env", asks about "secret leaks", "vault", "secret rotation", "gitleaks", "secret detection" DO NOT USE FOR: OWASP vulnerabilities - use `owasp-top-10`, supply chain - use `supply-chain`, general security - use `owasp`Votes: 0GitHub stars: 31