Agent skill

Critical Interval Security Checker

by ArabelaTso in ArabelaTso/Skills-4-SE

Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations.

Apache-2.0Auto-check passedBackend & APIs

Install Critical Interval Security Checker

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill critical-interval-security-checker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE critical-interval-security-checker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/critical-interval-security-checker .claude/skills/critical-interval-security-checker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
critical-interval-security-checker
GitHub stars
253
Token cost
~1.8k tokens
SKILL.md length
420 words
Files
4 (incl. scripts, references)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations.

  • Works in 7 steps: Identify Security-Critical Operations → Check for Common Vulnerabilities → Use Automated Checker → …
  • Reviewing code for proper timeout enforcement
  • SKILL.md covers Workflow, Quick Reference, Helper Script and Best Practices
  • Runs Python scripts from its folder; calls python; needs SECRET_KEY

What it does

Critical Interval Security Checker is an agent skill from ArabelaTso/Skills-4-SE. Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations. Use this skill when reviewing code for proper timeout enforcement, token expiration, session management, rate limiting, password reset validity, or any time-sensitive security mechanism. Detects missing expiration checks, excessive timeout values, lack of rate limiting, client-side only validation, hardcoded timeouts, and timing attack vulnerabilities…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/time_intervals.md`, `references/vulnerability_patterns.md` and `scripts/check_intervals.py`).

It sits in Backend & APIs, covering Authentication, Rate limiting and Security operations. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Reviewing code for proper timeout enforcement
  • Token expiration
  • Session management
  • Password reset validity

Example prompts

  • “Use the critical-interval-security-checker skill to analyz code to identify security-critical time intervals and timing vulnerabilities in…”
  • “/critical-interval-security-checker”

Requirements

  • Python 3
  • A credential in SECRET_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Identify Security-Critical Operations
  2. Check for Common Vulnerabilities
  3. Use Automated Checker
  4. Manual Code Review
  5. Verify Against Standards
  6. Document Findings
  7. Propose Fixes

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Critical Interval Security Checker loads about 1.8k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 184 tokens; SKILL.md has 420 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~184
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 420 words, ~1,816 tokens.

Download SKILL.mdSave it as .claude/skills/critical-interval-security-checker/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
critical-interval-security-checker
description
Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations. Use this skill when reviewing code for proper timeout enforcement, token expiration, session management, rate limiting, password reset validity, or any time-sensitive security mechanism. Detects missing expiration checks, excessive timeout values, lack of rate limiting, client-side only validation, hardcoded timeouts, and timing attack vulnerabilities. Triggers when users ask to check security timeouts, verify token expiration handling, audit session timeout implementation, review rate limiting, or analyze time-based security controls.

Critical Interval Security Checker

Analyze code to identify security-critical time intervals and timing vulnerabilities that could compromise security.

Workflow

1. Identify Security-Critical Operations

Look for code that handles:

  • Authentication: Login, logout, token generation
  • Session management: Session creation, validation, expiration
  • Password operations: Reset tokens, change requests
  • Rate limiting: Login attempts, API calls, password resets
  • Token operations: JWT, OAuth tokens, API keys
  • MFA: OTP codes, push notifications, backup codes
2. Check for Common Vulnerabilities

See vulnerability_patterns.md for detailed patterns.

Critical checks:

  • Missing expiration validation
  • Excessive timeout values
  • No rate limiting on sensitive endpoints
  • Client-side only expiration checks
  • Race conditions in expiration logic
  • Hardcoded timeout values
  • Inconsistent timeout enforcement
  • Timezone handling issues
  • Timing attack vulnerabilities
3. Use Automated Checker

Run the automated checker script:

bash
# Check single file
python scripts/check_intervals.py path/to/file.py

# Check entire directory
python scripts/check_intervals.py src/

# Specify language
python scripts/check_intervals.py src/ --language python

The script detects:

  • 🔴 Critical: JWT decode without verification, timing attacks
  • 🟠 High: Missing expiration checks, no rate limiting
  • 🟡 Medium: Excessive timeouts, inconsistent enforcement
  • 🔵 Low: Hardcoded timeouts, magic numbers
4. Manual Code Review

For each security-critical operation, verify:

Expiration is set:

python
# Good: Expiration set
token_expiry = datetime.utcnow() + timedelta(hours=1)

Expiration is checked:

python
# Good: Expiration validated
if datetime.utcnow() > token_expiry:
    raise TokenExpiredError()

Timeout is reasonable:

python
# Good: 1-hour reset token
RESET_TOKEN_EXPIRY = timedelta(hours=1)

# Bad: 7-day reset token (too long!)
RESET_TOKEN_EXPIRY = timedelta(days=7)

Rate limiting exists:

python
# Good: Rate limited
@limiter.limit("5 per 15 minutes")
def login():
    pass

Server-side enforcement:

python
# Good: Server validates expiration
decoded = jwt.decode(token, SECRET_KEY)  # Checks exp

# Bad: Client-side only
decoded = jwt.decode(token, options={"verify_signature": False})
5. Verify Against Standards

Consult time_intervals.md for recommended values:

Common intervals:

  • JWT access token: 5-15 minutes
  • JWT refresh token: 7-30 days
  • Session timeout: 15-30 minutes (idle), 8-12 hours (absolute)
  • Password reset token: 15-60 minutes
  • Login rate limit: 5 attempts per 15 minutes
  • TOTP code: 30 seconds
  • SMS/Email OTP: 5-10 minutes

Check if intervals match use case:

  • High-security apps need shorter timeouts
  • User-facing apps balance security and UX
  • API tokens can be shorter-lived with refresh tokens
6. Document Findings

For each issue found, document:

Issue: Missing expiration check on password reset token
Location: auth/reset_password.py:45
Severity: High
Current: Token created with expiry but never validated
Recommendation: Add expiration check before using token
Code fix:
  if datetime.utcnow() > token.expires_at:
      raise TokenExpiredError("Reset token expired")
Show full SKILL.md (166 more words)Show less
7. Propose Fixes

Fix missing expiration checks:

python
# Before
def validate_token(token):
    decoded = jwt.decode(token, SECRET_KEY, options={"verify_signature": False})
    return decoded['user_id']

# After
def validate_token(token):
    try:
        decoded = jwt.decode(token, SECRET_KEY)  # Verifies exp automatically
        return decoded['user_id']
    except jwt.ExpiredSignatureError:
        raise AuthenticationError("Token expired")

Fix excessive timeouts:

python
# Before
RESET_TOKEN_EXPIRY = timedelta(days=7)  # Too long!

# After
RESET_TOKEN_EXPIRY = timedelta(hours=1)  # Appropriate

Add rate limiting:

python
# Before
@app.route('/login', methods=['POST'])
def login():
    pass

# After
@app.route('/login', methods=['POST'])
@limiter.limit("5 per 15 minutes")
def login():
    pass

Fix hardcoded timeouts:

python
# Before
expiry = datetime.utcnow() + timedelta(seconds=3600)  # Magic number

# After
SESSION_TIMEOUT = timedelta(hours=1)  # Named constant
expiry = datetime.utcnow() + SESSION_TIMEOUT

Quick Reference

Critical Vulnerabilities

Missing expiration check:

  • Token/session has expiry field but it's never validated
  • High risk: Expired tokens still work

No rate limiting:

  • Authentication endpoints without throttling
  • High risk: Brute force attacks

Client-side only validation:

  • Expiration checked in frontend but not backend
  • Critical risk: Easily bypassed

Excessive timeouts:

  • Reset tokens valid for days
  • Sessions never expire
  • Medium risk: Extended attack window
Detection Patterns

Python:

python
# Look for
jwt.decode(..., verify=False)  # Bad
timedelta(days=7)  # Check context
@limiter.limit  # Good
datetime.now() vs datetime.utcnow()  # Timezone issue

JavaScript:

javascript
// Look for
jwt.decode(...)  // Check if expiration validated
Date.now() < exp  // Client-side check
rateLimit(...)  // Good
setTimeout(..., 86400000)  // Magic number

Java:

java
// Look for
Jwts.parser()  // Check if expiration validated
Duration.ofDays(30)  // Check context
@RateLimit  // Good

Helper Script

The check_intervals.py script automates detection:

bash
# Check Python code
python scripts/check_intervals.py src/ --language python

# Check JavaScript code
python scripts/check_intervals.py src/ --language javascript

# Auto-detect language
python scripts/check_intervals.py src/

Output provides:

  • Categorized issues by severity
  • File and line number
  • Issue description
  • Fix recommendation

Best Practices

Always:

  • Set expiration times for all security tokens
  • Validate expiration server-side
  • Use reasonable timeout values
  • Implement rate limiting on auth endpoints
  • Use UTC for all timestamps
  • Use named constants for timeouts
  • Document timeout decisions

Never:

  • Skip expiration validation
  • Use client-side only checks
  • Set excessive timeout values
  • Use magic number timeouts
  • Mix timezone-aware and naive datetimes
  • Use non-constant-time comparisons for secrets

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/critical-interval-security-checker of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/time_intervals.md
  • references/vulnerability_patterns.md
  • scripts/check_intervals.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Critical Interval Security Checker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Critical Interval Security Checker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Critical Interval Security Checker this skillArabelaTso/Skills-4-SE253—~1.8kAutomated safety check: PassApache-2.0
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Auth Architecturemajiayu000/litellm-rs117—~1.9kAutomated safety check: PassMIT
Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills202—~1.5kAutomated safety check: PassMIT
Apikerhodgef/apiker127—~1.4kAutomated safety check: PassMIT
Springboot Securityaffaan-m/ECC276k5 repos~2kAutomated safety check: PassMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Auth Architecture

    majiayu000/litellm-rs

    LiteLLM-RS Authentication Architecture. An agent skill from majiayu000/litellm-rs.

    117 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Apiker

    hodgef/apiker

    Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.

    127 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    276k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • Domain Web

    fjrevoredo/mini-diarium

    A skill your agent uses when building web services. An agent skill from fjrevoredo/mini-diarium.

    308 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Critical Interval Security Checker

What does Critical Interval Security Checker do?

Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations. Critical Interval Security Checker is an agent skill from ArabelaTso/Skills-4-SE. Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations.

When should I use Critical Interval Security Checker?

Critical Interval Security Checker fits situations like: reviewing code for proper timeout enforcement; token expiration; session management; password reset validity.

How do I install Critical Interval Security Checker in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill critical-interval-security-checker -a claude-code`. Or copy the skill folder (skills/critical-interval-security-checker in ArabelaTso/Skills-4-SE) into .claude/skills/critical-interval-security-checker in your project. Claude Code loads it when a task matches its description.

How do I install Critical Interval Security Checker in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill critical-interval-security-checker -a codex`. Or copy the skill folder (skills/critical-interval-security-checker in ArabelaTso/Skills-4-SE) into .agents/skills/critical-interval-security-checker in your project. Codex loads it when a task matches its description.

Can I use Critical Interval Security Checker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill critical-interval-security-checker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/critical-interval-security-checker, .gemini/skills/critical-interval-security-checker, .github/skills/critical-interval-security-checker and .opencode/skills/critical-interval-security-checker in your project.

What does Critical Interval Security Checker need to run?

Going by SKILL.md and its folder, Critical Interval Security Checker needs Python for the scripts in its folder, the command-line tools its instructions call (python) and credentials named SECRET_KEY. Our summary lists: Python 3; A credential in SECRET_KEY.

Does Critical Interval Security Checker access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Critical Interval Security Checker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Critical Interval Security Checker use?

Critical Interval Security Checker is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Critical Interval Security Checker use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.

What are the alternatives to Critical Interval Security Checker?

Skills that share tags, products or a category with Critical Interval Security Checker: API Audit (briiirussell/cybersecurity-skills, 413 stars), Auth Architecture (majiayu000/litellm-rs, 117 stars), Azure APIM Policy Authoring (thomast1906/github-copilot-agent-skills, 202 stars) and Apiker (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Critical Interval Security Checker?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.