{"enrichment":{"faq":[{"a":"application-security teaches you to prevent SQL injection by using parameterized queries and prepared statements, which separate SQL code from user input. The skill provides code examples showing how to safely construct database queries, ensuring that user-supplied data is treated as data rather than executable code. This is a foundational defense covered in the OWASP Top 10 vulnerabilities section.","q":"How to prevent SQL injection attacks with application-security?"},{"a":"application-security equips you with essential knowledge of the OWASP Top 10\u2014the most critical web application security risks\u2014and demonstrates how to identify and remediate each vulnerability in your codebase. The skill covers injection attacks, broken authentication, sensitive data exposure, XML external entities, broken access control, security misconfiguration, cross-site scripting (XSS), insecure deserialization, using components with known vulnerabilities, and insufficient logging and monitoring, each with defensive techniques and code examples.","q":"What are the OWASP Top 10 security vulnerabilities that application-security covers?"},{"a":"application-security guides you through configuring security headers and CSP policies for web applications, including CSP nonce implementation for inline scripts. The skill teaches you how to set appropriate directives that control which resources can be loaded, preventing unauthorized script execution and mitigating XSS attacks. You'll learn to configure headers that restrict content sources and protect your application from common web vulnerabilities.","q":"How do I implement content security policy headers with application-security?"},{"a":"application-security covers input validation best practices as a core defense against injection attacks and other vulnerabilities. The skill teaches you to validate user input on both client and server sides, implement allowlisting approaches, sanitize data, and use parameterized queries. These practices are essential for preventing SQL injection, XSS, and other attack vectors that exploit unvalidated or improperly handled user-supplied data.","q":"What input validation best practices does application-security teach?"},{"a":"application-security teaches you to select and use SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) tools for security scanning. The skill covers how to integrate these tools into your development pipeline, interpret their findings, and prioritize remediation efforts. You'll learn which tools are appropriate for different testing scenarios and how to use them to identify vulnerabilities before they reach production.","q":"Which SAST and DAST security testing tools does application-security recommend?"},{"a":"application-security provides a security hardening checklist and comprehensive guidance for auditing your web application's security posture. The skill teaches you to implement secure headers, configure authentication and authorization checks with code examples, apply cryptographic best practices, and conduct systematic reviews of your codebase. You'll learn to identify and fix security vulnerabilities systematically, ensuring your application meets industry security standards.","q":"How can application-security help me audit and harden my application's security posture?"}],"shadow_tags":["vulnerability-prevention","secure-coding","penetration-testing","code-hardening","threat-mitigation","defensive-programming","security-toolchain","compliance-patterns"],"summary_rewrite":"This skill equips you with essential knowledge of the OWASP Top 10\u2014the most critical web application security risks\u2014and demonstrates how to identify and remediate each vulnerability in your codebase. Through hands-on code examples and defensive techniques, you'll learn to build more resilient applications and protect against common attack vectors."},"files":[{"bytes":5432,"path":"skills/application-security/SKILL.md","sha256":"dabf2942141b39d9eecce3b95ba21823fba8bd8edb5dce0d652f3d8f3317cdb4","url":"https://skillfed.io/files/travisjneuman/.claude/application-security/99d73cb5/SKILL.md"}],"id":"travisjneuman/.claude/application-security","links":{"html":"https://skillfed.io/travisjneuman/.claude/application-security","md":"https://skillfed.io/travisjneuman/.claude/application-security.md","repo":"https://github.com/travisjneuman/.claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":20,"language":"JavaScript","last_updated":"2026-07-17","license":"MIT","name":"application-security","publisher":"travisjneuman","stars":85},"relations":{"similar":[{"id":"daffy0208/ai-dev-standards/security-engineer"},{"id":"hoodini/ai-agents-skills/owasp-security"},{"id":"josavicentevw/ai-agent-skills/devsecops"},{"id":"martinholovsky/claude-skills-generator/appsec-expert"},{"id":"AgentSecOps/SecOpsAgentKit/sast-bandit"},{"id":"RightNow-AI/openfang/security-audit"},{"id":"shashankswe2020-ux/whoop-mcp/security-and-hardening"},{"id":"adamos486/skills/production-ready"},{"id":"nahisaho/MUSUBI/security-auditor"},{"id":"Jeffallan/claude-skills/security-reviewer"}]},"slug":{"owner":"travisjneuman","repo":".claude","skill":"application-security"},"version":"99d73cb5"}
