{"enrichment":{"faq":[{"a":"security-practices teaches you to recognize SQL injection as a critical vulnerability and provides practical mitigation strategies. The skill covers input validation and sanitization techniques that prevent attackers from injecting malicious SQL code into your application queries. By learning parameterized queries, prepared statements, and proper input handling through this skill, you can defend your database layer against one of the most common attack vectors threatening modern applications.","q":"How does security-practices help prevent SQL injection attacks?"},{"a":"security-practices covers the full spectrum of OWASP Top 10 vulnerabilities explained through threat identification and mitigation strategies. The skill teaches you to recognize these critical security weaknesses and implement defensive coding practices to protect against them. By understanding each vulnerability category and learning practical prevention techniques, you gain the foundational knowledge needed to build more secure applications and reduce your attack surface.","q":"What OWASP Top 10 vulnerabilities are explained in security-practices?"},{"a":"security-practices provides comprehensive guidance on implementing secure authentication and authorization mechanisms. The skill covers multiple authentication approaches including JWT authentication, OAuth 2.0 setup, and secure password hashing best practices using modern algorithms like Argon2. You'll learn how to protect against broken authentication vulnerabilities and implement role-based access control (RBAC) to ensure only authorized users can access sensitive resources and functionality.","q":"How can security-practices help implement secure authentication?"},{"a":"security-practices equips you with practical XSS protection strategies for web applications. The skill covers input validation, output encoding, and content security policy (CSP) implementation to prevent cross-site scripting attacks. By learning these defensive coding practices, you'll understand how to sanitize user input, implement security headers, and configure your application to block malicious scripts from executing in users' browsers.","q":"What XSS protection techniques does security-practices teach?"},{"a":"security-practices teaches you to configure security headers and manage secrets properly through environment variables. The skill provides guidance on securing sensitive configuration data, API keys, and credentials outside of your codebase. By learning secure secrets management practices, you prevent accidental exposure of sensitive information and reduce the risk of attackers stealing data or gaining unauthorized access to your application infrastructure.","q":"How does security-practices address secrets management and environment variables?"},{"a":"security-practices delivers secure coding practices tailored for Node.js environments, including CSRF token implementation, rate limiting for login attempts, and command injection prevention. The skill teaches you to apply input validation and sanitization across your Node.js applications, implement proper authorization checks, and protect against insecure direct object references. These practical techniques help you build defensive applications that resist common web attacks and exploits.","q":"What secure coding practices for Node.js does security-practices cover?"}],"shadow_tags":["vulnerability-prevention","auth-patterns","code-hardening","attack-mitigation","access-control","data-protection","compliance-standards","secure-coding","threat-defense"],"summary_rewrite":"This skill teaches you to recognize and defend against the OWASP Top 10 security vulnerabilities that threaten modern applications. Through practical guidance on threat identification and mitigation strategies, you'll build the defensive coding practices needed to protect your software from common attacks and exploits."},"files":[{"bytes":11406,"path":"software-engineering/security-practices/SKILL.md","sha256":"3fdb5b7d7b6c98075f611119dffd7b5909cedc527737f1d13b81b3bd9653b387","url":"https://skillfed.io/files/miles990/claude-software-skills/security-practices/92c62842/SKILL.md"}],"id":"miles990/claude-software-skills/security-practices","links":{"html":"https://skillfed.io/miles990/claude-software-skills/security-practices","md":"https://skillfed.io/miles990/claude-software-skills/security-practices.md","repo":"https://github.com/miles990/claude-software-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":5,"language":"TypeScript","last_updated":"2026-01-20","license":"MIT","name":"security-practices","publisher":"miles990","stars":19},"relations":{"similar":[{"id":"personamanagmentlayer/pcl/security-expert"},{"id":"organvm/a-i--skills/security-implementation-guide"},{"id":"hoodini/ai-agents-skills/owasp-security"},{"id":"travisjneuman/.claude/application-security"},{"id":"nahisaho/MUSUBI/security-auditor"},{"id":"patricio0312rev/skills/auth-security-reviewer"},{"id":"daffy0208/ai-dev-standards/security-engineer"},{"id":"manutej/luxor-claude-marketplace/express-microservices-architecture"},{"id":"manutej/luxor-claude-marketplace/expressjs-development"},{"id":"Bbeierle12/Skill-MCP-Claude/form-security"}]},"slug":{"owner":"miles990","repo":"claude-software-skills","skill":"security-practices"},"version":"92c62842"}
