Token导航 LogoToken导航TokenDH.com
开发执行命令github未标认证来源可访问许可证需确认审计通过

secure-coding安全编码

Agent Skill

secure-coding 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

764

周安装

17

GitHub Stars

61

下载量

140
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:secure-coding(安全编码)
来源仓库:https://github.com/melodic-software/claude-code-plugins
仓库路径:skills/secure-coding
安装命令:
npx skills add https://github.com/melodic-software/claude-code-plugins --skill secure-coding
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/melodic-software/claude-code-plugins --skill secure-coding

简介

用于处理 GitHub 仓库、Issue 和 Pull Request 协作信息。

  • 适合围绕代码变更、仓库状态和协作事项进行整理。
  • 建议结合原始 README 了解具体操作流程。
  • 安装前需确认权限范围、维护状态及是否会触发网络请求。
  • secure-coding 属于开发类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Secure Coding

Comprehensive guidance for writing secure code, covering OWASP Top 10 2025, CWE Top 25, and language-specific security patterns.

When to Use This Skill

Use this skill when:

  • Reviewing code for security vulnerabilities
  • Implementing input validation or output encoding
  • Learning about common security weaknesses (OWASP, CWE)
  • Fixing identified security issues
  • Writing security-sensitive code (authentication, authorization, data handling)
  • Conducting security code reviews

OWASP Top 10 2025 Quick Reference

RankVulnerabilityKey Mitigation
A01Broken Access ControlServer-side access checks, deny by default, CORS restrictions
A02Security MisconfigurationHardened configs, remove defaults, disable unnecessary features
A03Software Supply Chain FailuresSCA, SBOM, verify dependencies, integrity checks
A04Cryptographic FailuresStrong encryption (AES-256), TLS 1.2+, no deprecated algorithms
A05InjectionParameterized queries, input validation, context-aware encoding
A06Insecure DesignThreat modeling, secure design patterns, defense in depth
A07Authentication FailuresMFA, strong passwords, secure session management
A08Data Integrity FailuresDigital signatures, integrity verification, secure CI/CD
A09Logging & Alerting FailuresCentralized logging, anomaly detection, audit trails
A10Mishandling ExceptionsFail securely, generic error messages, complete exception handling

For detailed mitigations: See OWASP Top 10 2025 Reference

Core Secure Coding Principles

1. Input Validation

Never trust user input. Validate all inputs on the server side.

using System.Text.RegularExpressions;

// Good: Server-side validation with allowlist
public static partial class InputValidation
{
    [GeneratedRegex(@"^[a-zA-Z0-9_]{3,20}$")]
    private static partial Regex UsernamePattern();

    /// <summary>
    /// Validate username against allowlist pattern.
    /// </summary>
    public static bool ValidateUsername(string username) =>
        !string.IsNullOrEmpty(username) && UsernamePattern().IsMatch(username);
}

// Bad: No validation
public string ProcessUsername(string username) => username;  // Dangerous!

Validation strategies:

  • Allowlist validation: Define what IS allowed (preferred)
  • Blocklist validation: Define what is NOT allowed (less secure)
  • Type checking: Ensure correct data types
  • Range checking: Verify values within expected bounds
  • Length limits: Prevent buffer overflows and DoS

2. Output Encoding

Encode output based on context to prevent injection attacks.

ContextEncoding MethodExample
HTML bodyHTML entity encoding<script>
HTML attributesAttribute encoding' for '
JavaScriptJavaScript encoding\x3Cscript\x3E
URL parametersURL encoding%3Cscript%3E
CSSCSS encoding\3C script\3E
SQLParameterized queriesUse prepared statements

3. Parameterized Queries (Injection Prevention)

Always use parameterized queries for database operations.

// Good: Parameterized query with SqlCommand
using var cmd = new SqlCommand(
    "SELECT * FROM Users WHERE Username = @username AND Status = @status",
    connection);
cmd.Parameters.AddWithValue("@username", username);
cmd.Parameters.AddWithValue("@status", status);

// Good: Parameterized query with Dapper
var users = await connection.QueryAsync<User>(
    "SELECT * FROM Users WHERE Username = @Username AND Status = @Status",
    new { Username = username, Status = status });

// Bad: String interpolation (SQL Injection vulnerable)
var query = $"SELECT * FROM Users WHERE Username = '{username}'";  // VULNERABLE

4. Authentication Security

  • Use strong password hashing: Argon2id, bcrypt, scrypt (see cryptography skill)
  • Implement MFA: Time-based OTP, hardware keys, passkeys
  • Secure session management: HttpOnly cookies, secure flag, short expiration
  • Account lockout: Prevent brute force attacks
  • Credential storage: Never store plaintext passwords

5. Authorization Security

  • Deny by default: Require explicit permission grants
  • Server-side checks: Never rely on client-side authorization
  • Verify object ownership: Check user can access requested resource
  • Use indirect references: Map internal IDs to user-specific references
  • Implement RBAC/ABAC: Use structured access control models

6. Error Handling

// Good: Generic error message to user, detailed logging
public async Task<IActionResult> ProcessData([FromBody] DataRequest request)
{
    try
    {
        await _dataService.ProcessSensitiveDataAsync(request.Data);
        return Ok();
    }
    catch (DbException ex)
    {
        _logger.LogError(ex, "Database error processing request for user {UserId}", User.GetUserId());
        return StatusCode(500, new { error = "An error occurred" });
    }
}

// Bad: Exposing internal details
catch (DbException ex)
{
    return StatusCode(500, new { error = ex.Message });  // VULNERABLE - exposes internals
}

Error handling rules:

  • Return generic error messages to users
  • Log detailed errors server-side
  • Never expose stack traces, database errors, or internal paths
  • Fail securely (deny access on error)

Language-Specific Patterns

JavaScript/TypeScript

// XSS Prevention - use textContent, not innerHTML
element.textContent = userInput;  // Safe
element.innerHTML = userInput;    // VULNERABLE

// Use DOMPurify for HTML that must be rendered
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userInput);

// Avoid eval() and Function()
eval(userInput);           // VULNERABLE
new Function(userInput)(); // VULNERABLE

// Use strict mode
'use strict';

C# /.NET

// Safe process execution - use argument list, avoid shell
using System.Diagnostics;

public static async Task<string> SafeExecuteAsync(string command, params string[] args)
{
    using var process = new Process
    {
        StartInfo = new ProcessStartInfo
        {
            FileName = command,
            RedirectStandardOutput = true,
            RedirectStandardError = true,
            UseShellExecute = false,  // Safe: no shell interpretation
            CreateNoWindow = true
        }
    };

    foreach (var arg in args)
        process.StartInfo.ArgumentList.Add(arg);  // Safe: no shell escaping needed

    process.Start();
    var output = await process.StandardOutput.ReadToEndAsync();
    await process.WaitForExitAsync();
    return output;
}

// Bad: Shell injection vulnerable
Process.Start("cmd", $"/c dir {userInput}");  // VULNERABLE

// Safe file operations - prevent path traversal
public static class SafeFileAccess
{
    /// <summary>
    /// Safely read a file, preventing path traversal attacks.
    /// </summary>
    public static string SafeReadFile(string baseDir, string filename)
    {
        var basePath = Path.GetFullPath(baseDir);
        var filePath = Path.GetFullPath(Path.Combine(baseDir, filename));

        if (!filePath.StartsWith(basePath, StringComparison.OrdinalIgnoreCase))
            throw new UnauthorizedAccessException("Path traversal detected");

        return File.ReadAllText(filePath);
    }
}

// Use parameterized queries with Entity Framework
var users = context.Users
    .Where(u => u.Username == username)  // Safe - parameterized
    .ToList();

// Avoid raw SQL when possible, use parameters if needed
var users = context.Users
    .FromSqlRaw("SELECT * FROM Users WHERE Username = {0}", username)
    .ToList();

// Anti-forgery tokens for CSRF protection
[ValidateAntiForgeryToken]
public IActionResult UpdateProfile(ProfileModel model)
{
    // Process update
}

// Input validation with data annotations
public sealed class UserInput
{
    [Required]
    [StringLength(100, MinimumLength = 3)]
    [RegularExpression(@"^[a-zA-Z0-9_]+$")]
    public required string Username { get; init; }
}

Security Code Review Checklist

Input Handling

  • All inputs validated on server side
  • Allowlist validation used where possible
  • Length limits enforced
  • Type checking performed
  • File uploads validated (type, size, content)

Output Encoding

  • Context-appropriate encoding applied
  • No raw user input in HTML/JS/SQL
  • Content-Type headers set correctly
  • X-Content-Type-Options: nosniff

Authentication

  • Strong password hashing (Argon2id/bcrypt)
  • Session tokens are random and unpredictable
  • Session invalidation on logout
  • Account lockout after failed attempts
  • Credentials transmitted over HTTPS only

Authorization

  • Access control on every request
  • Deny by default policy
  • Object-level authorization checks
  • No direct object references exposed

Data Protection

  • Sensitive data encrypted at rest
  • TLS 1.2+ for data in transit
  • No sensitive data in URLs or logs
  • Proper key management

Error Handling

  • Generic error messages to users
  • Detailed errors logged securely
  • No stack traces exposed
  • Fail securely (deny on error)

Quick Decision Tree

What security concern are you addressing?

  1. SQL/NoSQL injection → Use parameterized queries, ORMs
  2. XSS (Cross-Site Scripting) → Context-aware output encoding, CSP
  3. CSRF → Anti-forgery tokens, SameSite cookies
  4. Authentication → See authentication-patterns skill
  5. Authorization → See authorization-models skill
  6. Cryptography → See cryptography skill
  7. Secrets/Credentials → See secrets-management skill
  8. API Security → See api-security skill

References

Related Skills

SkillRelationship
authentication-patternsAuth implementation details (JWT, OAuth, Passkeys)
authorization-modelsAccess control (RBAC, ABAC)
cryptographyEncryption, hashing, TLS
api-securityAPI-specific security patterns
secrets-managementCredential and secret handling

Version History

  • v1.0.0 (2025-12-26): Initial release with OWASP Top 10 2025, core principles

Last Updated: 2025-12-26

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.62%
按下载量换算51

Claude

25.73%
按下载量换算36

Cursor

19.81%
按下载量换算28

Gemini CLI

8.25%
按下载量换算12

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 npx skills add https://github.com/melodic-software/claude-code-plugins --skill secure-coding 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills