Skip to content
Back to skills

Ios Security

ASecurity

For iOS security best practices, focus on a few non-negotiables: - Store tokens, credentials, and PII in the Keychain using `SecItemAdd`, `SecItemUpdate`, and `SecItemDelete` with `kSecClassGenericPassword`. Do not store secrets in `UserDefaults`. - Use biometrics through `LocalAuthentication` and `LAContext`. Check `canEvaluatePolicy` before prompting, and handle cases like `userCancel` and `authenticationFailed`. - Protect files written to disk with `Data.WritingOptions.completeFileProtecti...

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmentrustgosecurity

Security analysis

A100/100

Pro scans all 12 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill ios-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ios Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ios Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-ios-security-agent-skills-standard/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-ios-security-agent-skills-standard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
For iOS security best practices, focus on a few non-negotiables:

- Store tokens, credentials, and PII in the Keychain using `SecItemAdd`, `SecItemUpdate`, and `SecItemDelete` with `kSecClassGenericPassword`. Do not store secrets in `UserDefaults`.
- Use biometrics through `LocalAuthentication` and `LAContext`. Check `canEvaluatePolicy` before prompting, and handle cases like `userCancel` and `authenticationFailed`.
- Protect files written to disk with `Data.WritingOptions.completeFileProtection`.
- Keep App Transport Security enabled. Do not disable ATS globally in your app configuration.
- Use certificate pinning in production, such as with `ServerTrustManager` or `TrustKit`, to reduce MITM risk.
- Remove sensitive values like tokens, credentials, and PII from logs, especially in Release builds.

The main anti-patterns to avoid are storing secrets in `UserDefaults`, ignoring biometric error handling, and logging sensitive data.

Files in this skill

  • eval-1.baseline.md1.3 KB
  • eval-1.with-skill.md945 B
  • eval-2.baseline.md1.5 KB
  • eval-2.with-skill.md1.2 KB
  • eval-3.baseline.md1.2 KB
  • eval-3.with-skill.md2.7 KB
  • trigger-1.md200 B
  • trigger-2.md182 B
  • trigger-3.md125 B
  • trigger-4.md159 B
  • trigger-5.md165 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…