Skip to content
Back to skills

Common Security Standards

ASecurity

Universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, or any security-sensitive feature. (triggers: **/*.ts, **/*.tsx, **/*.go, **/*.dart, **/*.java, **/*.kt, **/*.swift, **/*.py, security, encrypt, authenticate, authorize)

  • 43 stars
  • 0 votes
  • 0 copies
  • 5 views
  • Added May 30, 2026
developmentrustgojavaswiftsqltestinggitapici/cdsecurity

Works with

  • api

Security analysis

A100/100

Scanned May 30, 2026

npx -y skills add ComeOnOliver/skillshub --skill common-security-standards --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Common Security Standards?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Common Security Standards
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/comeonoliver-common-security-standards/badge)](https://www.skillsdirectory.com/skills/comeonoliver-common-security-standards)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: common-security-standards
description: 'Universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, or any security-sensitive feature. (triggers: **/*.ts, **/*.tsx, **/*.go, **/*.dart, **/*.java, **/*.kt, **/*.swift, **/*.py, security, encrypt, authenticate, authorize)'
---

# Security Standards

## **Priority: P0 (CRITICAL)**

## πŸ›‘ Data Safeguarding

- **Zero Trust**: Never trust external input. Sanitize and validate every data boundary (API, UI, CSV).
- **Least Privilege**: Grant minimum necessary permissions to users, services, and containers.
- **No Hardcoded Secrets**: Use environment variables or secret managers. Never commit keys or passwords.
- **Encryption**: Use modern, collision-resistant algorithms (AES-256 for data-at-rest; TLS 1.3 for data-in-transit).
- **PII Logging**: Never log PII (email, phone, names). Mask sensitive fields before logging.

## 🧱 Secure Coding Practices

- **Injection Prevention**: Use parameterized queries or ORMs to stop SQL, Command, and XSS injections.
- **Dependency Management**: Regularly scan (`audit`) and update third-party libraries to patch CVEs.
- **Secure Auth**: Implement Multi-Factor Authentication (MFA) and secure session management.
- **Error Privacy**: Never leak stack traces or internal implementation details to the end-user.

## πŸ” Continuous Security

- **Shift Left**: Integrate security scanners (SAST/DAST) early in the CI/CD pipeline.
- **Data Minimization**: Collect and store only the absolute minimum data required for the business logic.
- **Logging**: Maintain audit logs for sensitive operations (Auth, Deletion, Admin changes).

## Anti-Patterns

- **No secrets in Git**: Use secret managers or env vars; rotate immediately if exposed.
- **No raw SQL strings**: Use parameterized queries or ORMs β€” always.
- **No stacktraces in prod**: Return generic error codes; log full detail server-side.
- **No default passwords**: Force rotation on first use with strong entropy requirements.

## πŸ“š References

- [Injection Testing Protocols (SQLi/HTMLi)](references/INJECTION_TESTING.md)
- [Vulnerability Remediation & Secure Patterns](references/VULNERABILITY_REMEDIATION.md)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…