Skip to content
Back to skills

Auth Security Input Validation Zod

ASecurity

Parse, don't validate: coerce untrusted input into typed values once at the edge.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsrustbashgitapibackendsecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add aniruddhaadak80/skills --skill auth-security-input-validation-zod --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Auth Security Input Validation Zod?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Auth Security Input Validation Zod
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aniruddhaadak80-auth-security-input-validation-zod/badge)](https://www.skillsdirectory.com/skills/aniruddhaadak80-auth-security-input-validation-zod)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: auth-security-input-validation-zod
description: "Parse, don't validate: coerce untrusted input into typed values once at the edge."
---
# Validate all external input at the boundary

> Parse, don't validate: coerce untrusted input into typed values once at the edge.

**Track:** ⚙️ Backend Engineering · **Domain:** Auth & Security Basics · **Level:** foundation · **~25 min**

**Who this is for:** Backend Engineers, API Developers, Platform Engineers, Full-Stack Developers

## When to Use This Skill

Parse, don't validate: coerce untrusted input into typed values once at the edge.
Use it whenever a matching task appears in conversation — the agent loads these instructions on demand.

## Steps

1. Define schemas per endpoint covering body, query, params, headers
2. Reject unknown fields by default; allowlists beat blocklists
3. Coerce types explicitly; fail closed on ambiguity
4. Return field-level errors machines can render
5. Reuse the same schemas for client-side forms where possible
6. Fuzz one nasty payload corpus against public endpoints in CI

## Common Pitfalls

- Validating in UI but trusting raw req.body server-side
- Mass assignment from spreads straight into ORM updates

## Commands

**Install with skills CLI**
```bash
npx skills add aniruddhaadak80/skills --skill auth-security-input-validation-zod
```

**Install globally**
```bash
npx skills add aniruddhaadak80/skills --skill auth-security-input-validation-zod -g
```

---

Part of [aniruddhaadak80/skills](https://github.com/aniruddhaadak80/skills) · Browse all at https://skills.sh/aniruddhaadak80/skills

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…