Skip to content
Back to skills

Security Best Practices

ASecurity

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

  • 4 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added June 4, 2026
developmentjavascripttypescriptpythongojavatestingdebuggingfrontendbackendsecurity

Security analysis

A100/100

Pro scans all 12 files and shows the line behind each finding

Scanned June 4, 2026

npx -y skills add lidge-jun/cli-jaw-skills --skill security-best-practices --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Best Practices?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Best Practices
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lidge-jun-security-best-practices/badge)](https://www.skillsdirectory.com/skills/lidge-jun-security-best-practices)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "security-best-practices"
description: "Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks."
---

# Security Best Practices

## Workflow

1. **Identify languages and frameworks** in scope — inspect the repo if unclear. Cover both frontend and backend for web apps.
2. **Load matching references** from `references/`. Filename format: `<language>-<framework>-<stack>-security.md`. Also check `<language>-general-<stack>-security.md`. For unspecified web frontends, check `javascript-general-web-frontend-security.md`.
3. **If no references match**, apply well-known security practices for the detected stack. When generating a report, note that concrete guidance is unavailable.

## Modes

1. **Secure-by-default coding** — apply guidance to all new code going forward
2. **Passive detection** — flag critical vulnerabilities encountered while working; focus on highest-impact issues
3. **Security report** — produce a prioritized report (see Report Format below), then offer to fix findings

## Overrides

Project docs or prompt files may override specific practices. Respect these overrides — suggest documenting the rationale so future work stays consistent.

## Report Format

Write to `security_best_practices_report.md` (or user-specified path).

- Executive summary at top
- Sections grouped by severity (critical → low)
- Each finding has a numeric ID, file path with line numbers, and (for critical) a one-sentence impact statement
- After writing, summarize findings to the user and note the file location

## Fixes

- Fix one finding at a time with clear comments explaining the security rationale
- Consider regression risk — insecure code is often depended on elsewhere. A careful, project-aware fix is better than a quick one
- Follow the project's commit and testing workflows; use clear commit messages referencing the finding
- Ask the user before applying fixes from a report; notify and ask for critical passive findings

## General Security Advice

- **Public resource IDs**: use UUID4 or random hex instead of auto-incrementing integers — prevents enumeration and ID guessing
- **TLS/HSTS**: avoid flagging missing TLS in dev environments. Set `Secure` cookies only when the app runs over TLS (provide an env flag to toggle). Avoid recommending HSTS — misconfiguration causes lasting outages and user lockout

Files in this skill

  • SKILL.md2.6 KB
  • agents/openai.yaml237 B
  • references/golang-general-backend-security.md37.8 KB
  • references/javascript-express-web-server-security.md48.2 KB
  • references/javascript-general-web-frontend-security.md37.7 KB
  • references/javascript-jquery-web-frontend-security.md32.8 KB
  • references/javascript-typescript-nextjs-web-server-security.md42.4 KB
  • references/javascript-typescript-react-web-frontend-security.md40.7 KB
  • references/javascript-typescript-vue-web-frontend-security.md30.7 KB
  • references/python-django-web-server-security.md37.8 KB
  • references/python-fastapi-web-server-security.md43.9 KB
  • references/python-flask-web-server-security.md31 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…