Skip to content
Back to skills

Security Audit

ASecurity

Security best practices including CSP, XSS prevention, input validation, and secrets management. Use when reviewing security or hardening applications.

  • 33 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added February 10, 2026
developmentjavascriptpythonrustgojavabashsqlnodedockergit

Works with

  • cursor
  • cli
  • api

Security analysis

A92/100
  • mediumUses curl or wget to download content
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned February 12, 2026

npx -y skills add lovedragonball/power-ranger-toolkit --skill security-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Audit
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/lovedragonball-security-audit/badge)](https://www.skillsdirectory.com/skills/lovedragonball-security-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-audit
description: Security best practices including CSP, XSS prevention, input validation, and secrets management. Use when reviewing security or hardening applications.
---

# πŸ”’ Security Audit Skill

## Security Checklist

### Input Validation
- [ ] All user inputs validated
- [ ] Server-side validation (not just client)
- [ ] Whitelist allowed values
- [ ] Sanitize before storage/display

### Authentication
- [ ] Passwords hashed (bcrypt/argon2)
- [ ] Session tokens secure (httpOnly, secure)
- [ ] Rate limiting on login
- [ ] 2FA available

### Secrets
- [ ] No hardcoded API keys
- [ ] Secrets in env variables
- [ ] .env in .gitignore
- [ ] Secrets rotated regularly

---

## XSS Prevention

### ❌ Vulnerable
```javascript
element.innerHTML = userInput;
document.write(userInput);
```

### βœ… Safe
```javascript
// Use textContent
element.textContent = userInput;

// Sanitize HTML
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userInput);

// Trusted Types (Chrome)
const policy = trustedTypes.createPolicy('safe', {
  createHTML: (input) => DOMPurify.sanitize(input)
});
element.innerHTML = policy.createHTML(userInput);
```

---

## Content Security Policy

### Manifest V3
```json
{
  "content_security_policy": {
    "extension_pages": "script-src 'self'; object-src 'self'"
  }
}
```

### HTTP Header
```
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'
```

---

## SQL Injection Prevention

### ❌ Vulnerable
```javascript
const query = `SELECT * FROM users WHERE id = '${userId}'`;
```

### βœ… Safe (Parameterized)
```javascript
// Node.js with pg
const result = await db.query(
  'SELECT * FROM users WHERE id = $1',
  [userId]
);

// Python with psycopg2
cursor.execute('SELECT * FROM users WHERE id = %s', (user_id,))
```

---

## Secrets Management

### Environment Variables
```bash
# .env (never commit!)
API_KEY=sk-xxxx
DATABASE_URL=postgres://...

# .env.example (commit this)
API_KEY=your-api-key-here
DATABASE_URL=your-database-url
```

### Load in Code
```javascript
// Node.js
require('dotenv').config();
const apiKey = process.env.API_KEY;

// Never log secrets
console.log('API Key:', apiKey); // ❌ BAD
```

---

## Chrome Extension Security

### Message Validation
```javascript
chrome.runtime.onMessage.addListener((message, sender, sendResponse) => {
  // Verify sender
  if (!sender.tab || !sender.tab.url.includes('trusted-domain.com')) {
    return;
  }
  
  // Validate message structure
  if (typeof message.type !== 'string') {
    return;
  }
  
  // Process...
});
```

### External Connections
```json
{
  "host_permissions": [
    "https://api.tiktok.com/*"  // Specific, not *
  ]
}
```

---

## Common Vulnerabilities

| Vuln | Prevention |
|------|------------|
| XSS | textContent, Trusted Types |
| SQL Injection | Parameterized queries |
| CSRF | CSRF tokens, SameSite cookies |
| Secrets leak | Env vars, .gitignore |
| Open redirect | Validate redirect URLs |

---

## πŸ” Automated Vulnerability Scanning

### NPM Audit
```bash
# Check vulnerabilities
npm audit

# Auto-fix where possible
npm audit fix

# Force fix (may have breaking changes)
npm audit fix --force

# JSON output for CI
npm audit --json > audit-report.json
```

### Snyk
```bash
# Install
npm install -g snyk

# Authenticate
snyk auth

# Test project
snyk test

# Monitor continuously
snyk monitor
```

### OWASP Dependency-Check
```bash
# Docker
docker run --rm -v $(pwd):/src owasp/dependency-check \
  --scan /src --format HTML --out /src/report
```

---

## πŸ“¦ Dependency Audit

### Check Outdated
```bash
# NPM
npm outdated

# Show all deps
npm ls --all

# Check for known issues
npx is-my-node-ok
```

### Security Headers Check
```bash
# Check security headers
curl -I https://example.com | grep -i security
curl -I https://example.com | grep -i x-content-type
curl -I https://example.com | grep -i x-frame-options
```

### Automated CI Check
```yaml
# GitHub Actions
- name: Security Audit
  run: |
    npm audit --audit-level=high
    npx snyk test --severity-threshold=high
```

---

## Audit Checklist

- [ ] Run npm audit
- [ ] Check outdated dependencies
- [ ] Scan with Snyk/OWASP
- [ ] Review security headers
- [ ] Check for hardcoded secrets
- [ ] Validate CSP configuration
- [ ] Test authentication flows
- [ ] Review access controls

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…