Skip to content
Back to skills

Trail Of Bits Security

ASecurity

Security-focused code review based on OWASP Top 10. Flagging vulnerabilities (SQLi, XSS) before code is committed.

  • 8 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentssqlreactapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add mayurrathi/awesome-agent-skills --skill trail-of-bits-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Trail Of Bits Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Trail Of Bits Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mayurrathi-trail-of-bits-security/badge)](https://www.skillsdirectory.com/skills/mayurrathi-trail-of-bits-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Trail Of Bits Security
description: Security-focused code review based on OWASP Top 10. Flagging vulnerabilities (SQLi, XSS) before code is committed.
version: 1.0.0
---

# 2.5.1 Trail Of Bits Security

Act as a strict security auditor. Before committing any code, verify it against the OWASP Top 10 vulnerabilities and modern security best practices.

## 1. Injection Prevention (SQLi, NoSQLi, Command Injection)
- **Parameterized Queries:** Never concatenate user input into database queries. Always use ORMs, parameterized queries, or prepared statements.
- **Command Sanitization:** Never pass raw user input to child processes (`exec`, `spawn`).

## 2. Cross-Site Scripting (XSS) Prevention
- **Output Encoding:** Ensure all user-supplied data rendered in the browser is properly escaped (React handles this by default, but watch out for `dangerouslySetInnerHTML`).
- **Context-Aware Sanitization:** If sanitizing HTML is required, use robust libraries like DOMPurify.

## 3. Broken Authentication & Session Management
- **Secure Cookies:** Always use `HttpOnly`, `Secure`, and `SameSite` attributes on session cookies.
- **Token Storage:** Never store JWTs in `localStorage`. Use secure HttpOnly cookies.

## 4. Insecure Direct Object References (IDOR)
- **Authorization Checks:** Always verify that the currently authenticated user has correct permissions to access or modify the requested resource ID.

## 5. Security Misconfiguration
- **Headers:** Ensure security headers (CSP, HSTS, X-Content-Type-Options) are strictly configured.
- **Secrets:** Never check API keys or secrets into version control. Use `.env` files and secure secret managers.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…