Skip to content
Back to skills

Security First Development

ASecurity

OWASP-aware security practices — input validation, secrets management, auth patterns, injection prevention, CORS, rate limiting, and CSP headers.

  • 7 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added May 27, 2026
developmentjavascripttypescriptpythongojavashellsqlreactgitapi

Works with

  • api

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned May 27, 2026

npx -y skills add Vimalk0703/shipworthy --skill security-first-development --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security First Development?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security First Development
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/vimalk0703-security-first-development/badge)](https://www.skillsdirectory.com/skills/vimalk0703-security-first-development)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-first-development
description: OWASP-aware security practices — input validation, secrets management, auth patterns, injection prevention, CORS, rate limiting, and CSP headers.
invoke_when: Use when writing auth logic, API endpoints, database queries, file operations, user input handling, or any code that touches external data.
---

# Security-First Development

## Core Rule

**Every piece of external data is hostile until validated.**

## OWASP Practical Checklist

### Injection Prevention
- **SQL**: Parameterized queries ONLY. Never concatenate strings into queries.
- **NoSQL**: Use query builders, never raw object construction from user input.
- **Command**: Never pass user input to shell commands. Use argument arrays.
- **XSS**: Escape all output. Use framework defaults (React auto-escapes JSX).

### Authentication
- Use established libraries (NextAuth, Passport) — never roll your own
- Passwords: bcrypt/argon2. Never MD5/SHA for passwords.
- Sessions: HTTP-only, secure, SameSite cookies
- Rate limit login attempts

### Authorization
- Check permissions on EVERY request, not just the UI
- Default deny — explicitly grant, never explicitly deny
- Verify resource ownership (user A can't access user B's data)

### Secrets Management
- **NEVER** hardcode secrets in source code
- Use environment variables with validation at startup
- `.env` files MUST be in `.gitignore`
- Different secrets per environment

### Input Validation
- Validate at the boundary (API handler, form submission)
- **ALWAYS install and use a schema validation library** — never write manual if/else validation:
  - TypeScript/JavaScript: `npm install zod` — use `z.object()` schemas for every request body
  - Python: Pydantic models for every endpoint
  - Go: validator package or custom validation
- Whitelist valid input, don't blacklist bad input
- Validate BEFORE processing: parse the request body with the schema, reject if invalid, then proceed with the typed result

### CORS
- Never use `*` in production
- Explicitly list allowed origins

### Rate Limiting
- All public endpoints must have rate limits
- Return 429 with Retry-After header

### Content Security Policy
- Set CSP headers to prevent XSS
- Restrict script sources, style sources, frame ancestors

### Dependencies
- Run `npm audit` / `pip audit` before committing
- No packages with known critical vulnerabilities

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…