Skip to content
Back to skills

Quarkus Security

ASecurity

Use when quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. Only for Quarkus — not for other stacks. Triggers on \"quarkus-security\", \"quarkus security\", \"security\".

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentsgojavasqldjangospringsecurity

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add majinmagros/magros.ai-skills --skill quarkus-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Quarkus Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Quarkus Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/majinmagros-quarkus-security/badge)](https://www.skillsdirectory.com/skills/majinmagros-quarkus-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: quarkus-security
description: "Use when quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. Only for Quarkus — not for other stacks. Triggers on \"quarkus-security\", \"quarkus security\", \"security\"."
metadata:
  origin: ECC
---

# Quarkus Security Review

Best practices for securing Quarkus applications with authentication, authorization, and input validation.

## When to Activate

- Adding authentication (JWT, OIDC, Basic Auth)
- Implementing authorization with @RolesAllowed or SecurityIdentity
- Validating user input (Bean Validation, custom validators)
- Configuring CORS or security headers
- Managing secrets (Vault, environment variables, config sources)
- Adding rate limiting or brute-force protection
- Scanning dependencies for CVEs
- Working with MicroProfile JWT or SmallRye JWT

## When NOT to Use

- Other stacks (use `springboot-security`, `django-security`, `security-review`, etc.)
- Quarkus patterns in general (use `quarkus-patterns`)
- Quarkus verification loop (use `quarkus-verification`)

## Contents

| Topic | Reference |
|---|---|
| JWT/OIDC, filters, RBAC | `references/auth.md` |
| Bean Validation, SQLi | `references/validation-sqli.md` |
| CORS, Vault, rate limiting, headers, audit | `references/config-ratelimit.md` |
| Dependency scanning, best practices | `references/deps-best.md` |

## Example

```java
@ApplicationScoped
public class PasswordService {

  public String hash(String plainPassword) {
    return BcryptUtil.bcryptHash(plainPassword);
  }

  public boolean verify(String plainPassword, String hashedPassword) {
    return BcryptUtil.matches(plainPassword, hashedPassword);
  }
}

// In service
@ApplicationScoped
public class UserService {
  @Inject
  PasswordService passwordService;

  @Transactional
  public User register(CreateUserDto dto) {
    String hashedPassword = passwordService.hash(dto.password());
    User user = new User();
    user.email = dto.email();
    user.password = hashedPassword;
    user.persist();

Files in this skill

  • SKILL.md2 KB
  • references/auth.md3.1 KB
  • references/config-ratelimit.md4 KB
  • references/deps-best.md847 B
  • references/validation-sqli.md2.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…