Agent skill

Security Patterns

by CloudAI-X in CloudAI-X/claude-workflow-v2

Implements authentication, authorization, encryption, secrets management, and security hardening patterns.

MITAuto-check: notesBackend & APIs

Install Security Patterns

skills CLI
$ npx skills add CloudAI-X/claude-workflow-v2 --skill security-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CloudAI-X/claude-workflow-v2 security-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CloudAI-X/claude-workflow-v2.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-patterns .claude/skills/security-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-patterns
GitHub stars
1.4k
Token cost
~3.6k tokens
SKILL.md length
87 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Implements authentication, authorization, encryption, secrets management, and security hardening patterns.

  • Designing auth flows
  • SKILL.md covers Security Implementation Workflow, Authentication Patterns, Authorization Models and Password Handling, plus 7 more sections
  • Needs JWT_SECRET and API_KEY
  • Managing secrets

What it does

Security Patterns is an agent skill from CloudAI-X/claude-workflow-v2. Implements authentication, authorization, encryption, secrets management, and security hardening patterns. Use when designing auth flows, managing secrets, configuring CORS, implementing rate limiting, or when asked about JWT, OAuth, password hashing, API keys, RBAC, or security best practices.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication, Authorization and RBAC and Secrets management. The repository describes itself as: Universal Claude Code workflow plugin with agents, skills, hooks, and commands. The licence is MIT.

When your agent uses it

  • Designing auth flows
  • Managing secrets
  • Configuring CORS
  • Implementing rate limiting

Example prompts

  • “Use the security-patterns skill to implement authentication, authorization, encryption, secrets management, and security hardening patterns”
  • “/security-patterns”

Requirements

  • Python 3
  • A credential in JWT_SECRET
  • A credential in JWT_REFRESH_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 3b5a89e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET
    • API_KEY
    • JWT_REFRESH_SECRET
    • SESSION_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Patterns loads about 3.6k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 87 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:259
    RRECT: Environment variables loaded from .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CloudAI-X/claude-workflow-v2 at commit 3b5a89e, republished under its MIT licence (© CloudAI-X). 87 words, ~3,555 tokens.

Download SKILL.mdSave it as .claude/skills/security-patterns/SKILL.md (or your agent's skills folder).
name
security-patterns
description
Implements authentication, authorization, encryption, secrets management, and security hardening patterns. Use when designing auth flows, managing secrets, configuring CORS, implementing rate limiting, or when asked about JWT, OAuth, password hashing, API keys, RBAC, or security best practices.

Security Patterns

When to Load
  • Trigger: Auth flows, encryption, secrets management, CORS configuration, input validation, rate limiting
  • Skip: No security surface involved in the current task

Security Implementation Workflow

Copy this checklist and track progress:

Security Implementation Progress:
- [ ] Step 1: Choose authentication strategy
- [ ] Step 2: Implement authorization model
- [ ] Step 3: Set up password hashing
- [ ] Step 4: Configure secrets management
- [ ] Step 5: Enable encryption (transit + rest)
- [ ] Step 6: Configure CORS
- [ ] Step 7: Add rate limiting
- [ ] Step 8: Validate against anti-patterns checklist

Authentication Patterns

JWT (JSON Web Tokens)
typescript
import jwt from "jsonwebtoken";

function generateTokens(user: User) {
  const accessToken = jwt.sign(
    { sub: user.id, role: user.role },
    process.env.JWT_SECRET!,
    { expiresIn: "15m", algorithm: "HS256" },
  );
  const refreshToken = jwt.sign(
    { sub: user.id, tokenVersion: user.tokenVersion },
    process.env.JWT_REFRESH_SECRET!,
    { expiresIn: "7d" },
  );
  return { accessToken, refreshToken };
}

// WRONG: localStorage (XSS vulnerable) | CORRECT: httpOnly cookie for refresh, memory for access
res.cookie("refreshToken", refreshToken, {
  httpOnly: true,
  secure: true,
  sameSite: "strict",
  maxAge: 7 * 24 * 60 * 60 * 1000,
  path: "/api/auth/refresh",
});
JWT Verification Middleware
typescript
function authenticate(req: Request, res: Response, next: NextFunction) {
  const header = req.headers.authorization;
  if (!header?.startsWith("Bearer ")) {
    return res.status(401).json({ error: "Missing token" });
  }

  try {
    const token = header.slice(7);
    const payload = jwt.verify(token, process.env.JWT_SECRET!, {
      algorithms: ["HS256"], // pin: never let the token choose its algorithm
    }) as JwtPayload;
    req.user = { id: payload.sub, role: payload.role };
    next();
  } catch (err) {
    if (err instanceof jwt.TokenExpiredError) {
      return res.status(401).json({ error: "Token expired" });
    }
    return res.status(401).json({ error: "Invalid token" });
  }
}
Session-Based Auth
typescript
import session from "express-session";
import { RedisStore } from "connect-redis";

app.use(
  session({
    store: new RedisStore({ client: redisClient }),
    secret: process.env.SESSION_SECRET!,
    resave: false,
    saveUninitialized: false,
    cookie: {
      httpOnly: true,
      secure: process.env.NODE_ENV === "production",
      sameSite: "strict",
      maxAge: 24 * 60 * 60 * 1000, // 24 hours
    },
  }),
);
OAuth 2.0 / OIDC Flow Summary
Authorization Code Flow with PKCE (all clients):
1. Redirect to provider: /authorize?response_type=code&client_id=...&redirect_uri=...&scope=openid email
   &state=RANDOM&nonce=RANDOM&code_challenge=...&code_challenge_method=S256
2. User authenticates, provider redirects back with ?code=AUTHORIZATION_CODE&state=... (reject if state differs)
3. Backend exchanges code for tokens (POST /token with code_verifier, plus client_secret for confidential clients)
4. Backend validates the id_token (signature, iss, aud, exp, nonce), then creates session/JWT

Public clients (SPAs, mobile): same flow without client_secret
NEVER use Implicit Flow (deprecated, tokens exposed in URL)
API Key Authentication
typescript
async function authenticateApiKey(
  req: Request,
  res: Response,
  next: NextFunction,
) {
  const apiKey = req.headers["x-api-key"] as string;
  if (!apiKey) return res.status(401).json({ error: "API key required" });

  // WRONG: Direct comparison (timing attack) | CORRECT: Hash-based lookup
  const hashedKey = crypto.createHash("sha256").update(apiKey).digest("hex");
  const keyRecord = await db.apiKey.findUnique({ where: { hash: hashedKey } });
  if (!keyRecord || keyRecord.revokedAt)
    return res.status(401).json({ error: "Invalid API key" });

  req.apiClient = { id: keyRecord.clientId, scopes: keyRecord.scopes };
  next();
}

Authorization Models

RBAC (Role-Based Access Control)
typescript
const PERMISSIONS = {
  admin: [
    "users:read",
    "users:write",
    "users:delete",
    "posts:read",
    "posts:write",
    "posts:delete",
  ],
  editor: ["posts:read", "posts:write", "posts:delete", "users:read"],
  viewer: ["posts:read", "users:read"],
} as const;

type Role = keyof typeof PERMISSIONS;

function authorize(...requiredPermissions: string[]) {
  return (req: Request, res: Response, next: NextFunction) => {
    const userPermissions = PERMISSIONS[req.user.role as Role] || [];
    const hasPermission = requiredPermissions.every((p) =>
      (userPermissions as readonly string[]).includes(p),
    );
    if (!hasPermission)
      return res.status(403).json({ error: "Insufficient permissions" });
    next();
  };
}

// Usage: app.delete("/api/users/:id", authenticate, authorize("users:delete"), deleteUser);
Resource-Level Authorization
typescript
// WRONG: Only checking role, not ownership -- any editor can edit ANY post
// CORRECT: Check ownership or admin role
app.put(
  "/api/posts/:id",
  authenticate,
  authorize("posts:write"),
  async (req, res) => {
    const post = await db.post.findUnique({ where: { id: req.params.id } });
    if (!post) return res.status(404).json({ error: "Not found" });
    if (post.authorId !== req.user.id && req.user.role !== "admin") {
      return res
        .status(403)
        .json({ error: "Not authorized to edit this post" });
    }
    // WRONG: data: req.body -- mass assignment lets the client overwrite authorId
    const { title, body } = UpdatePostSchema.parse(req.body); // allowlisted fields only
    const updated = await db.post.update({
      where: { id: post.id },
      data: { title, body },
    });
    res.json(updated);
  },
);

Password Handling

typescript
import bcrypt from "bcrypt";
// WRONG: plaintext or MD5/SHA256 (too fast, brute-forceable)
// CORRECT: bcrypt with appropriate cost factor
const SALT_ROUNDS = 12; // ~250ms on modern hardware

async function hashPassword(password: string): Promise<string> {
  return bcrypt.hash(password, SALT_ROUNDS);
}
async function verifyPassword(
  password: string,
  hash: string,
): Promise<boolean> {
  return bcrypt.compare(password, hash); // constant-time comparison built-in
}

// Registration
await db.user.create({
  data: { email, password: await hashPassword(req.body.password) },
});

// Login -- WRONG: "Invalid password" (reveals email exists) | CORRECT: generic message
// Always run bcrypt, even for unknown emails, or response time reveals which emails exist
const user = await db.user.findUnique({ where: { email } });
const hash = user?.password ?? DUMMY_HASH; // bcrypt hash of a random string, created at startup
if (!(await verifyPassword(req.body.password, hash)) || !user) {
  return res.status(401).json({ error: "Invalid email or password" });
}
Password Policies
typescript
function validatePassword(password: string): string[] {
  const errors: string[] = [];
  if (password.length < 12) errors.push("Minimum 12 characters");
  if (Buffer.byteLength(password) > 72) errors.push("Maximum 72 bytes"); // bcrypt ignores the rest

  // Check against breached password lists (haveibeenpwned API or local)
  // Do NOT enforce arbitrary complexity rules (uppercase + number + symbol)
  // NIST 800-63B recommends length over complexity
  return errors;
}

Secrets Management

python
# WRONG: Hardcoded values in source code
# API_KEY = "some-value-here"

# CORRECT: Environment variables loaded from .env
from dotenv import load_dotenv
import os

load_dotenv()
api_key = os.getenv("API_KEY")
db_url = os.getenv("DATABASE_URL")

# CORRECT: Secrets manager for production
# AWS: Secrets Manager, Parameter Store
# GCP: Secret Manager
# HashiCorp Vault for self-hosted
Secret Rotation
1. Generate new secret value
2. Deploy code that accepts BOTH old and new values
3. Update all consumers to use the new value
4. Verify old value is no longer in use
5. Revoke old value

Never: Rotate in-place without a transition period

Encryption Patterns

In Transit
typescript
// Redirect HTTP to HTTPS in production
app.use((req, res, next) => {
  if (
    req.headers["x-forwarded-proto"] !== "https" &&
    process.env.NODE_ENV === "production"
  ) {
    return res.redirect(301, `https://${req.hostname}${req.url}`);
  }
  next();
});
// HSTS header
app.use((req, res, next) => {
  res.setHeader(
    "Strict-Transport-Security",
    "max-age=31536000; includeSubDomains",
  );
  next();
});
At Rest
typescript
import crypto from "crypto";
const ALGORITHM = "aes-256-gcm";

function encrypt(
  plaintext: string,
  key: Buffer,
): { ciphertext: string; iv: string; tag: string } {
  const iv = crypto.randomBytes(16);
  const cipher = crypto.createCipheriv(ALGORITHM, key, iv);
  let ciphertext =
    cipher.update(plaintext, "utf8", "hex") + cipher.final("hex");
  return {
    ciphertext,
    iv: iv.toString("hex"),
    tag: cipher.getAuthTag().toString("hex"),
  };
}

function decrypt(
  ciphertext: string,
  key: Buffer,
  iv: string,
  tag: string,
): string {
  const decipher = crypto.createDecipheriv(
    ALGORITHM,
    key,
    Buffer.from(iv, "hex"),
  );
  decipher.setAuthTag(Buffer.from(tag, "hex"));
  return decipher.update(ciphertext, "hex", "utf8") + decipher.final("utf8");
}
// Use for PII, sensitive data. Encryption key in secrets manager, NOT in code.

CORS Configuration

typescript
import cors from "cors";

// WRONG: Allow everything
app.use(cors()); // origin: *, credentials: false

// WRONG: Wildcard with credentials
app.use(cors({ origin: "*", credentials: true })); // browsers reject this

// CORRECT: Explicit allowed origins
const ALLOWED_ORIGINS = [
  "https://myapp.com",
  "https://admin.myapp.com",
  ...(process.env.NODE_ENV !== "production" ? ["http://localhost:3000"] : []),
];

app.use(
  cors({
    origin: (origin, callback) => {
      if (!origin || ALLOWED_ORIGINS.includes(origin)) {
        callback(null, true);
      } else {
        callback(new Error("Not allowed by CORS"));
      }
    },
    credentials: true,
    methods: ["GET", "POST", "PUT", "PATCH", "DELETE"],
    allowedHeaders: ["Content-Type", "Authorization"],
    maxAge: 86400, // cache preflight for 24 hours
  }),
);

Rate Limiting

typescript
import rateLimit, { ipKeyGenerator } from "express-rate-limit";
import RedisStore from "rate-limit-redis";

// Global rate limit
app.use(
  rateLimit({
    windowMs: 15 * 60 * 1000, // 15 minutes
    limit: 100, // 100 requests per window
    standardHeaders: true, // RateLimit-* headers
    legacyHeaders: false,
    store: new RedisStore({
      sendCommand: (...args) => redisClient.sendCommand(args),
    }),
  }),
);

// Strict limit on auth endpoints
app.use(
  "/api/auth/login",
  rateLimit({
    windowMs: 15 * 60 * 1000,
    limit: 5, // 5 login attempts per 15 min
    message: { error: "Too many login attempts. Try again later." },
  }),
);

// Per-API-key rate limiting for developer APIs
app.use(
  "/api/v1/",
  rateLimit({
    windowMs: 60 * 1000, // 1 minute
    limit: 60, // 60 requests per minute
    keyGenerator: (req) => req.apiClient?.id ?? ipKeyGenerator(req.ip),
  }),
);

Security Headers

typescript
import helmet from "helmet";

app.use(helmet()); // Sets many secure headers at once

// Key headers helmet sets:
// X-Content-Type-Options: nosniff
// X-Frame-Options: SAMEORIGIN
// Strict-Transport-Security: max-age=31536000; includeSubDomains
// Content-Security-Policy: default-src 'self'

// Customize CSP for your app
app.use(
  helmet.contentSecurityPolicy({
    directives: {
      defaultSrc: ["'self'"],
      scriptSrc: ["'self'"],
      styleSrc: ["'self'", "'unsafe-inline'"],
      imgSrc: ["'self'", "data:", "https://cdn.example.com"],
      connectSrc: ["'self'", "https://api.example.com"],
    },
  }),
);

Input Validation

typescript
import { z } from "zod";

// WRONG: Trusting user input directly (SQL injection risk)
app.post("/api/users", (req, res) => {
  db.query(`SELECT * FROM users WHERE email = '${req.body.email}'`);
});

// CORRECT: Validate with schema, use parameterized queries
const CreateUserSchema = z.object({
  email: z.string().email().max(255),
  name: z.string().trim().min(1).max(100),
  age: z.number().int().min(13).max(150).optional(),
});

app.post("/api/users", async (req, res) => {
  const result = CreateUserSchema.safeParse(req.body);
  if (!result.success) {
    return res.status(400).json({ errors: result.error.flatten() });
  }
  // Use parameterized query (ORM or prepared statement)
  await db.user.create({ data: result.data });
});

Common Anti-Patterns Summary

AVOID                              DO INSTEAD
-------------------------------------------------------------------
JWT in localStorage                httpOnly secure cookie (refresh), memory (access)
MD5/SHA for passwords              bcrypt or argon2 with proper cost factor
Hardcoded secrets in code          Environment variables + secrets manager
cors({ origin: '*' })             Explicit allowed origins list
"Invalid password" message         "Invalid email or password" (no enumeration)
No rate limiting on auth           Strict rate limits on login/register
Rolling your own crypto            Use established libraries (jose, bcrypt)
Trusting user input                Validate with zod/joi, parameterized queries
Same API key forever               Rotate keys regularly, support multiple active
No HTTPS redirect                  Force HTTPS + HSTS header
Symmetric JWT for multi-service    Use RS256/ES256 (asymmetric) for distributed
No input length limits             Max length on all string inputs

© CloudAI-X, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-patterns of CloudAI-X/claude-workflow-v2.

Open the folder on GitHubat commit 3b5a89e

Compare with similar skills

Security Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Patterns this skillCloudAI-X/claude-workflow-v21.4k—~3.6kAutomated safety check: NotesMIT
Quarkus Securityaffaan-m/ECC274k1 repos~3.1kAutomated safety check: PassMIT
Discover APIrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
API Security Best Practicesdavila7/claude-code-templates32k7 repos~5.8kAutomated safety check: PassMIT
Quarkus Securityaffaan-m/ECC274k—~3.1kAutomated safety check: PassMIT

Similar skills

  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    274k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • API Security Best Practices

    davila7/claude-code-templates

    Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

    32k GitHub starsUsed in 7 repos~5.8k tokens
    Backend & APIsAuto-check passed
  • Quarkus Security

    affaan-m/ECC

    Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.

    274k GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from CloudAI-X/claude-workflow-v2

All 13 skills in this repo
  • Analyzing Projects

    CloudAI-X/claude-workflow-v2

    Analyzes codebases to understand structure, tech stack, patterns, and conventions.

    1.4k GitHub starsUsed in 2 repos~937 tokens
    Auto-check passed
  • Designing APIs

    CloudAI-X/claude-workflow-v2

    Designs REST and GraphQL APIs including endpoints, error handling, versioning, and documentation.

    1.4k GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed
  • Designing Architecture

    CloudAI-X/claude-workflow-v2

    Designs software architecture and selects appropriate patterns for projects.

    1.4k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Designing Tests

    CloudAI-X/claude-workflow-v2

    Designs and implements testing strategies for any codebase. An agent skill from CloudAI-X/claude-workflow-v2.

    1.4k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Managing Git

    CloudAI-X/claude-workflow-v2

    Manages Git workflows including branching, commits, and pull requests.

    1.4k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Optimizing Performance

    CloudAI-X/claude-workflow-v2

    Analyzes and optimizes application performance across frontend, backend, and database layers.

    1.4k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed

Categories

Questions about Security Patterns

What does Security Patterns do?

Implements authentication, authorization, encryption, secrets management, and security hardening patterns. Security Patterns is an agent skill from CloudAI-X/claude-workflow-v2. Implements authentication, authorization, encryption, secrets management, and security hardening patterns.

When should I use Security Patterns?

Security Patterns fits situations like: designing auth flows; managing secrets; configuring CORS; implementing rate limiting.

How do I install Security Patterns in Claude Code?

Run `npx skills add CloudAI-X/claude-workflow-v2 --skill security-patterns -a claude-code`. Or copy the skill folder (skills/security-patterns in CloudAI-X/claude-workflow-v2) into .claude/skills/security-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Security Patterns in Codex?

Run `npx skills add CloudAI-X/claude-workflow-v2 --skill security-patterns -a codex`. Or copy the skill folder (skills/security-patterns in CloudAI-X/claude-workflow-v2) into .agents/skills/security-patterns in your project. Codex loads it when a task matches its description.

Can I use Security Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CloudAI-X/claude-workflow-v2 --skill security-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-patterns, .gemini/skills/security-patterns, .github/skills/security-patterns and .opencode/skills/security-patterns in your project.

What does Security Patterns need to run?

Going by SKILL.md and its folder, Security Patterns needs credentials named JWT_SECRET, API_KEY, JWT_REFRESH_SECRET and SESSION_SECRET. Our summary lists: Python 3; A credential in JWT_SECRET; A credential in JWT_REFRESH_SECRET.

Does Security Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Patterns safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Patterns use?

Security Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Patterns use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Patterns?

Skills that share tags, products or a category with Security Patterns: Quarkus Security (affaan-m/ECC, 274k stars), Discover API (rand/cc-polymath, 181 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars) and API Security Best Practices (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Patterns?

CloudAI-X (a GitHub user) maintains it in CloudAI-X/claude-workflow-v2, which has 1,418 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: CloudAI-X/claude-workflow-v2 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.