Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计通过

securesecure 搜索

Agent Skill

secure 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

3,781

周安装

156

GitHub Stars

167

下载量

1,236
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:secure(secure 搜索)
来源仓库:https://github.com/whawkinsiv/claude-code-superpowers
仓库路径:skills/secure
安装命令:
npx skills add https://github.com/whawkinsiv/claude-code-superpowers --skill secure
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/whawkinsiv/claude-code-superpowers --skill secure

简介

用于搜索与信息安全相关的最佳实践、工具与案例资源。

  • 适合在制定安全策略、培训材料或技术选型时提供参考依据。
  • 通过 GitHub 仓库安装,使用 npx 命令发起语义化搜索获取候选方案。
  • 搜索结果为聚合信息,实际应用前应评估与企业环境的适配性与兼容性。
  • secure 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Security

This skill is for securing your app's code and data. For regulatory compliance (HIPAA, SOC 2, GDPR), use compliance. For pre-launch readiness checks, use go-live. For environment variable setup during deployment, use deploy. For database-level security (Row Level Security), use database.

Don't Do Yet

  • Don't implement OAuth/SSO until you have paying customers who need it. Email + password is fine for launch.
  • Don't buy a pentest until you have 1,000+ users or handle sensitive data (health, finance). This checklist is enough for MVP.
  • Don't set up a Web Application Firewall (WAF) — your hosting platform (Vercel, Railway) handles this. You don't need Cloudflare yet.
  • Don't build your own auth system. Use Supabase Auth, Clerk, or NextAuth. Rolling your own is how breaches happen.

Quick Start

Claude Code:

Run a security audit on my app. Check for:
- API keys or secrets in code (should be in .env)
- Missing auth on protected routes
- SQL injection risks
- XSS vulnerabilities
- Missing rate limiting
Fix anything you find.

Lovable / Replit / Cursor (paste into chat):

Review my app for security issues. Check these common problems:
1. Are any API keys or passwords hardcoded? Move them to environment variables.
2. Can someone access pages without logging in? Add auth checks.
3. Is user input validated before hitting the database?
4. Are passwords hashed (not stored as plain text)?
5. Is rate limiting set up on API endpoints?
Show me what needs fixing and fix it.

Security Checklist

Security Basics:
- [ ] Authentication required for protected routes
- [ ] Passwords hashed (bcrypt/argon2), never stored plain text
- [ ] API keys in environment variables, not code
- [ ] HTTPS only in production
- [ ] Input validated on server side
- [ ] SQL injection prevented (use parameterized queries)
- [ ] XSS prevented (sanitize user input)
- [ ] CSRF tokens on forms
- [ ] Rate limiting on API endpoints
- [ ] User sessions expire (30min-1hr typical)

See COMMON-VULNS.md for detailed checks.


Critical: Never Store These in Code

Move to environment variables:

  • Database passwords
  • API keys (Stripe, SendGrid, etc)
  • JWT secrets
  • OAuth client secrets
  • Encryption keys

Tell AI:

Store API keys in .env file, not in code.
Add .env to .gitignore.
Access via process.env.API_KEY

Authentication

Use a service. Don't build this yourself.

If you use...Auth solution
SupabaseSupabase Auth (built in)
Next.jsNextAuth.js or Clerk
LovableSupabase Auth (Lovable's default)
ReplitReplit Auth or Supabase

If you must build auth yourself (not recommended), the minimums are:

  • Passwords: 8+ chars, hashed with bcrypt (12 rounds), never stored plain text
  • Email verification required for signups
  • Password reset via email token only
  • Sessions expire after 30-60 minutes idle

Tell AI:

Set up authentication using [Supabase Auth / NextAuth / Clerk].
I need: email+password signup, email verification, password reset,
and session timeout after 30 minutes of inactivity.

See SECURITY-PROMPTS.md for implementation details.


Data Protection

Always encrypt:

  • Passwords (hashed, not encrypted)
  • Payment info (use Stripe, don't store cards)
  • Personal identifiable information (PII)

Never log:

  • Passwords (even hashed)
  • Credit card numbers
  • API keys
  • Session tokens

Tell AI:

Never log sensitive data.
Replace passwords/tokens with "[REDACTED]" in logs.

API Security

Required for all API endpoints:

  • Authentication check
  • Rate limiting (prevent abuse)
  • Input validation
  • Error messages don't leak info

Tell AI:

Add to all API routes:
- Require valid auth token
- Rate limit: 100 requests/minute per IP
- Validate all inputs (reject invalid)
- Generic error messages (no stack traces to users)

Common Vulnerabilities

Most common in AI-built apps:

  1. Exposed API keys - In code instead of.env
  2. No rate limiting - APIs can be spammed
  3. Missing auth checks - Routes accessible without login
  4. SQL injection - Raw SQL with user input
  5. XSS attacks - Unescaped user content displayed

See COMMON-VULNS.md for how to check.


Security Prompts for AI

Adding authentication:

Add authentication to this route.
Require valid JWT token.
Return 401 if missing/invalid.
Don't expose error details.

Rate limiting:

Add rate limiting:
- 100 requests/minute per IP
- Return 429 "Too many requests" if exceeded
- Use sliding window, not fixed

Input validation:

Validate all user inputs:
- Email: valid format
- Password: 8+ chars, 1 number, 1 symbol
- Username: alphanumeric only, 3-20 chars
Reject invalid input with clear error message

See SECURITY-PROMPTS.md for more.


Pre-Launch Security Review

Before deploying:

Production Security:
- [ ] All secrets in environment variables
- [ ] HTTPS enforced (no HTTP)
- [ ] Database backups configured
- [ ] Rate limiting on all APIs
- [ ] Error pages don't show stack traces
- [ ] Admin routes protected
- [ ] File uploads validated (type, size)
- [ ] CORS configured (not wildcard "*")

When to Get Security Audit

Signs you need expert review:

  • Handling payments directly (not Stripe)
  • Storing health/financial data
  • Multi-tenant with data isolation
  • Over 1,000 users
  • Processing sensitive PII

For most MVPs: Following this checklist is sufficient.


Common Founder Mistakes

MistakeFix
API keys in codeMove to.env
No rate limitingAdd to all endpoints
Plain text passwordsUse bcrypt
HTTP in productionForce HTTPS
Accepting all CORSWhitelist domains
No input validationValidate server-side
Detailed error messagesGeneric messages only

Quick Wins

Easy security improvements:

  1. Add Helmet.js (Node) - Sets security headers
  2. Use HTTPS everywhere - Force in production
  3. Add rate limiting - Prevents abuse
  4. Environment variables - Keep secrets safe
  5. Update dependencies - Fix known vulnerabilities

Tell AI:

Add helmet.js for security headers.
Configure for production (HTTPS, CSP, XSS protection).

Testing Security

Quick checks:

Exposed secrets:

grep -r "api_key" src/
grep -r "password" src/
# Should only find references to env vars

No auth bypass:

  • Try accessing protected routes without login
  • Should redirect to login or return 401

Rate limiting works:

  • Hit API endpoint 100 times quickly
  • Should get 429 error

Success Looks Like

✅ No secrets in code (all in.env) ✅ Can't access protected routes without auth ✅ Passwords hashed, never stored plain text ✅ Rate limiting prevents abuse ✅ HTTPS enforced in production ✅ Input validated on server side


Related Skills

  • compliance — Regulatory requirements (HIPAA, SOC 2, GDPR, CCPA)
  • go-live — Pre-launch readiness checks (security is one part of this)
  • deploy — Hosting and environment variable setup
  • database — Row Level Security, data access policies
  • payments — Stripe security and PCI compliance

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude

33.64%
按下载量换算416

Codex

33.08%
按下载量换算409

Cursor

19.92%
按下载量换算246

Gemini CLI

10.32%
按下载量换算128

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills