Skip to content
Back to skills

Input Validation

ASecurity

Add validation and sanitization at trust boundaries where untrusted data enters

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
ai-agentsrustgoshellsqlapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill input-validation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Input Validation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Input Validation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-input-validation/badge)](https://www.skillsdirectory.com/skills/black141312-input-validation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: input-validation
description: Add validation and sanitization at trust boundaries where untrusted data enters
category: security
---

# Input Validation

Use this when adding or hardening checks on data crossing a trust boundary — request bodies, query params, headers, file uploads, env, or upstream API responses.

1. Identify each trust boundary and the exact shape expected (type, range, length, format, allowed values) for every field.
2. Validate at the boundary with a schema/validator (zod, pydantic, JSON Schema, Joi) — parse into typed values, reject anything that does not conform.
3. Prefer allowlists over denylists: enumerate what is permitted (enum, regex anchored with `^...$`, numeric bounds) rather than blocking known-bad.
4. Enforce size and depth limits (max length, max array size, max upload bytes, max JSON nesting) to blunt resource-exhaustion.
5. Apply context-correct encoding/escaping at the sink (SQL params, HTML escape, shell arg arrays) — validation does not replace output encoding.
6. Fail closed with a clear, non-leaky error; log the rejection for monitoring without echoing raw payloads.

## Rules
- Validate on the server even if the client already validates — the client is untrusted.
- Normalize before validating (Unicode, path, case) so checks cannot be bypassed by alternate encodings.
- Validate is not the same as sanitize: reject bad input where you can; only transform when you must.
- Keep validation declarative and centralized so it is auditable, not scattered ad-hoc checks.
- Anchor regexes and set timeouts/limits to avoid ReDoS on attacker-controlled strings.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…