Skip to content
Back to skills

Application Security

ASecurity

Secure applications against common vulnerabilities. Use when reviewing code for security, implementing security controls, or hardening applications. Covers OWASP Top 10.

  • 34 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
securityrustgojavasqlspringdatabaseci/cdsecurity

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add nguyenhuuca/assessment --skill application-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Application Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Application Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nguyenhuuca-application-security/badge)](https://www.skillsdirectory.com/skills/nguyenhuuca-application-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: application-security
description: Secure applications against common vulnerabilities. Use when reviewing code for security, implementing security controls, or hardening applications. Covers OWASP Top 10.
allowed-tools: Read, Glob, Grep
---

# Application Security

## OWASP Top 10 (2021)

### 1. Broken Access Control
**Risk**: Users accessing unauthorized resources.

**Prevention**:
- Deny by default
- Implement RBAC/ABAC
- Validate permissions server-side
- Log access failures

### 2. Cryptographic Failures
**Risk**: Sensitive data exposure.

**Prevention**:
- Encrypt data at rest and in transit
- Use strong algorithms (AES-256, RSA-2048+)
- Never store passwords in plaintext
- Use secure key management

### 3. Injection
**Risk**: Malicious input executed as code.

**Prevention**:
```java
// ❌ BAD - SQL injection vulnerability
@GetMapping("/users/{id}")
public User getUser(@PathVariable String id) {
    String query = "SELECT * FROM users WHERE id = " + id;
    return jdbcTemplate.queryForObject(query, User.class);
}

// ✅ GOOD - Use JPA/Spring Data (parameterized by default)
@Repository
public interface UserRepository extends JpaRepository<User, Long> {
    Optional<User> findById(Long id);
}

// ✅ GOOD - JPQL with named parameters
@Query("SELECT u FROM User u WHERE u.email = :email AND u.status = :status")
Optional<User> findByEmailAndStatus(
    @Param("email") String email,
    @Param("status") UserStatus status
);

// ❌ BAD - Command injection
Runtime.getRuntime().exec("ls " + userInput);

// ✅ GOOD - Use ProcessBuilder with separate arguments
ProcessBuilder pb = new ProcessBuilder("ls", userInput);
Process p = pb.start();
```

### 4. Insecure Design
**Risk**: Missing security controls by design.

**Prevention**:
- Threat modeling
- Security requirements
- Defense in depth

### 5. Security Misconfiguration
**Risk**: Default or weak configuration.

**Prevention**:
- Disable unnecessary features
- Remove default credentials
- Keep software updated
- Harden server configuration

### 6. Vulnerable Components
**Risk**: Using libraries with known vulnerabilities.

**Prevention**:
- Regular dependency audits
- Keep dependencies updated
- Monitor CVE databases

### 7. Authentication Failures
**Risk**: Weak or broken authentication.

**Prevention**:
- Multi-factor authentication
- Strong password policies
- Secure session management
- Rate limiting on login

### 8. Software & Data Integrity
**Risk**: Untrusted sources for updates.

**Prevention**:
- Verify code signatures
- Use SRI for CDN resources
- Secure CI/CD pipeline

### 9. Logging & Monitoring Failures
**Risk**: Attacks go undetected.

**Prevention**:
- Log security events
- Monitor for anomalies
- Alert on suspicious activity

### 10. Server-Side Request Forgery
**Risk**: Server makes requests to unintended destinations.

**Prevention**:
- Validate URLs
- Use allowlists
- Block internal IPs

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…