Skip to content
Back to skills

Dygo Security Engineering

ASecurity

Design, implement, or review security-sensitive dygo behavior across auth, sessions, Permissions, secrets, APIs, database writes, files, Jobs, and Studio. Use when security boundaries are a primary concern.

  • 16 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added August 31, 2026
databasesrustgoapidatabasesecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned August 31, 2026

npx -y skills add hapyco/dygo --skill dygo-security-engineering --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dygo Security Engineering?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dygo Security Engineering
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hapyco-dygo-security-engineering/badge)](https://www.skillsdirectory.com/skills/hapyco-dygo-security-engineering)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dygo-security-engineering
description: Design, implement, or review security-sensitive dygo behavior across auth, sessions, Permissions, secrets, APIs, database writes, files, Jobs, and Studio. Use when security boundaries are a primary concern.
---

# dygo Security Engineering

Protect business data at the server boundary and use secure defaults.

## Review Areas

- identity, session creation, expiry, revocation, and cookie settings;
- Permission checks and Administrator boundaries;
- secret encryption, redaction, environment selection, and key rotation;
- input validation, query construction, routes, and API errors;
- destructive database and CLI operations;
- Job payloads, Logs, files, and audit data;
- Studio exposure of protected metadata and Records.

## Rules

- Default to deny.
- Do not rely on UI hiding for enforcement.
- Keep secrets out of stdout, Logs, errors, fixtures, and committed plaintext.
- Use parameterized queries and canonical identifier validation.
- Make privileged and destructive targets explicit before execution.
- Preserve tenant or actor context when the runtime contract requires it.
- Record useful security events without storing sensitive payloads.
- Do not invent cryptographic protocols. Use the repository's established libraries and formats.
- Treat public SDK and HTTP surfaces as compatibility and trust boundaries.

Use focused adversarial checks for the changed boundary. Report evidence and impact. Do not expand a normal review into a security audit unless the task calls for it.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…