Skip to content
Back to skills

Common Security Standards

ASecurity

Assumption: your application receives PII through APIs, processes it in an application service, and must later decrypt it for authorized use. Implement this flow: 1. Validate and sanitize PII at every trust boundary: API, UI, CSV, and webhook. 2. Encrypt PII in the application before persistence using authenticated AES-256 encryption, preferably AES-256-GCM. 3. Store encryption keys only in a secret manager or environment-backed key-management system—never hardcode or commit them. 4. Use TLS ...

  • 549 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
developmentrustgosqlapidatabase

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill common-security-standards --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Common Security Standards?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Common Security Standards
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-common-security-standards-ade0837a/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-common-security-standards-ade0837a)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Assumption: your application receives PII through APIs, processes it in an application service, and must later decrypt it for authorized use.

Implement this flow:

1. Validate and sanitize PII at every trust boundary: API, UI, CSV, and webhook.
2. Encrypt PII in the application before persistence using authenticated AES-256 encryption, preferably AES-256-GCM.
3. Store encryption keys only in a secret manager or environment-backed key-management system—never hardcode or commit them.
4. Use TLS 1.3 for data in transit.
5. Store only the minimum PII required, and never log raw emails, phone numbers, or names.
6. Persist through an ORM or parameterized queries; never construct raw SQL such as `WHERE id = ${userId}`.
7. Enforce least privilege for application and database accounts. Restrict decryption to services and roles that require it.
8. Return generic error codes to clients; log detailed errors server-side without PII.
9. Add audit logging for sensitive operations such as viewing, decrypting, updating, and deleting PII.
10. Run SAST/DAST and dependency checks such as `npm audit` or `pip audit` in CI.

Example pseudocode:

```ts
const encrypted = aes256GcmEncrypt(
  Buffer.from(user.email, "utf8"),
  keyFromSecretManager(),
);

await db.users.create({
  data: {
    emailCiphertext: encrypted.ciphertext,
    emailIv: encrypted.iv,
    emailAuthTag: encrypted.authTag,
    keyVersion: encrypted.keyVersion,
  },
});
```

Use a versioned key-encryption scheme so keys can be rotated without losing access to existing records. If a PII field must be searchable, store a separately protected deterministic lookup value, such as a keyed HMAC, rather than weakening the encryption.

For passwords, do not use reversible encryption; use Argon2id. If this feature includes authentication, also require MFA, secure session management, rate limiting, and `HttpOnly Secure` cookies.

Files in this skill

  • eval-1.baseline.md1.6 KB
  • eval-1.with-skill.md3.4 KB
  • eval-2.baseline.md854 B
  • eval-2.with-skill.md1.9 KB
  • eval-3.baseline.md477 B
  • eval-3.with-skill.md850 B
  • trigger-1.md127 B
  • trigger-2.md204 B
  • trigger-3.md104 B
  • trigger-4.md188 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…