Skip to content
Back to skills

Secure Coding

ASecurity

Apply input validation, output encoding and least privilege by default.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
developmentrustshellsqlapidatabase

Works with

  • api

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add Andersseen/agentyx --skill secure-coding --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Secure Coding?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Secure Coding
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/andersseen-secure-coding/badge)](https://www.skillsdirectory.com/skills/andersseen-secure-coding)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: secure-coding
description: Apply input validation, output encoding and least privilege by default.
---

# Secure coding

Treat every input crossing a trust boundary as hostile, including input from your own other services.

## Validate at the boundary

Validate structure, type, range and length where untrusted data enters, and reject what does not
conform. Allow-lists beat deny-lists: enumerate what is valid rather than guessing what is dangerous.

## Never build queries or commands by concatenation

Use parameterized queries and argument arrays. String interpolation into SQL, shell commands,
templates or file paths is the root of injection.

## Encode for the destination

Escaping depends on where the value lands: HTML body, attribute, URL, SQL, shell and JSON all differ.
Encode at the point of output, not on the way in.

## Apply least privilege

Give every process, token and database role the narrowest permissions that let it work. Scope
credentials per environment so a leak in one does not compromise the others.

## Fail closed

On error, deny access and log the reason. An exception path that falls through to permitted access is
a vulnerability, not a bug.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…