Skip to content
Back to skills

Ios Security

ASecurity

Secure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.

  • 17 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 4, 2026
securityrustgoswiftsecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add gabrielmoreira/agent-skills-mirror --skill ios-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ios Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ios Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gabrielmoreira-ios-security/badge)](https://www.skillsdirectory.com/skills/gabrielmoreira-ios-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ios-security
description: Secure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.
metadata:
  triggers:
    files:
    - '**/*.swift'
    keywords:
    - SecItemAdd
    - kSecClassGenericPassword
    - LAContext
    - LocalAuthentication
    - ios security
    - swift security
    - biometric
    - face id
    - touch id
    - certificate pinning
    - app transport security
---
# iOS Security

## **Priority: P0 (CRITICAL)**

## Implementation Workflow

1. **Store secrets in secure storage** — Use `SecItemAdd`, `SecItemUpdate`, and `SecItemDelete` with `kSecClassGenericPassword` for tokens/PII. Never use `UserDefaults`.
2. **Add biometric auth** — Use `LocalAuthentication` with `LAContext`. Verify availability with `canEvaluatePolicy` before prompting.
3. **Encrypt files** — Use `Data.WritingOptions.completeFileProtection` when saving to disk.
4. **Keep ATS enabled** — Never disable App Transport Security globally in the iOS Info configuration.
5. **Pin certificates** — Use `ServerTrustManager` or `TrustKit` for production apps to prevent MITM attacks.
6. **Strip sensitive logs** — Ensure PII and tokens removed from logs in Release builds.

See [Secure storage and biometrics implementation examples](references/implementation.md)

## Anti-Patterns

- **No Secrets in `UserDefaults`**: Always use secure storage for tokens and PII
- **No Unhandled `LAError`**: Check for `userCancel` and `authenticationFailed` in biometric flows
- **No PII/Token Logging**: Strip sensitive data from all logs in Release builds

## References

- [Secure Storage & Biometrics Implementation](references/implementation.md)

## Related Topics

- common/security-standards
- architecture

## Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- iOS app configuration
- LocalAuthentication

Files in this skill

  • SKILL.md2 KB
  • evals/evals.json1.8 KB
  • references/implementation.md2.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…