Agent skill

Security Practices

by eser in eser/stack

Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…

Custom licenceAuto-check passedSecurity

Install Security Practices

skills CLI
$ npx skills add eser/stack --skill security-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install eser/stack security-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/eser/stack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-practices .claude/skills/security-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-practices
GitHub stars
128
Token cost
~598 tokens
SKILL.md length
199 words
Files
6 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
Custom licence

At a glance

Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…

  • Handling secrets
  • SKILL.md covers Always and References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Production config

What it does

Security Practices is an agent skill from eser/stack. Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies, crypto, untrusted files and archives, LLM trust. Use when handling secrets, input, auth, sessions, cookies, crypto, uploads, subprocesses, outbound URLs, prompts, production config or a security review.

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `evals/triggers.json`, `references/crypto-and-files.md` and `references/http-and-auth.md`).

It sits in Security, covering Web application vulnerabilities, Security review and Authorization and RBAC. It works with TypeScript. The repository describes itself as: The Portability Solution for Your Code! 🚀 Powered By Deno and JavaScript.

When your agent uses it

  • Handling secrets
  • Production config
  • A security review

Example prompts

  • “/security-practices”

What it can do on your machine

Read from SKILL.md and the folder at commit 64939e6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Practices loads about 598 tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 199 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~598
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 199 words (~598 tokens).

“Security rules that apply to every package and service in the repository.”

— opening of SKILL.md by eser, Custom licence
name
security-practices

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files (references) in .agents/skills/security-practices of eser/stack.

  • SKILL.md
  • evals/triggers.json
  • references/crypto-and-files.md
  • references/http-and-auth.md
  • references/review-checklist.md
  • references/security-rules.md

Open the folder on GitHubat commit 64939e6

Compare with similar skills

Security Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Practices this skilleser/stack128—~598Automated safety check: PassCustom licence
Audit Gitbook IntegrationGitbookIO/integrations131—~1.2kAutomated safety check: PassNone
Security Reviewdeadlock-mod-manager/deadlock-mod-manager473—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Security Reviewlangfuse/langfuse35k—~1.4kAutomated safety check: PassCustom licence
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • Audit Gitbook Integration

    GitbookIO/integrations

    Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk.

    131 GitHub stars~1.2k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    473 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    35k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Security Review

    trycompai/comp

    Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it…

    2k GitHub stars~853 tokensUpdated 5 days ago
    SecurityAuto-check passed

More from eser/stack

All 13 skills in this repo
  • Picks the skills a task needs and maintains the rules in .agents/skills.

    128 GitHub stars~749 tokensUpdated 4 days ago
    Auto-check passed
  • System design in eserstack: double-layered hexagonal architecture, explicit adapter composition, public API and CLI surface, request metadata, testing strategy, ADRs.

    128 GitHub stars~516 tokensUpdated 4 days ago
    Auto-check passed
  • Language-neutral code quality rules for eserstack, TypeScript and Go.

    128 GitHub stars~688 tokensUpdated 4 days ago
    Auto-check passed
  • Enrichment

    eser/stack

    Interviews the user about a plan, decision or idea in rounds, level by level down a decision tree, until both share one understanding; facts are researched by sub-agents, decisions stay with the user.

    128 GitHub stars~642 tokensUpdated 4 days ago
    Auto-check passed
  • Go Practices

    eser/stack

    Go conventions for eserstack's ajan framework, services and FFI bridge.

    128 GitHub stars~851 tokensUpdated 4 days ago
    Auto-check passed
  • TS and JS conventions for eserstack packages: namespace imports, mod.ts entries, cross-runtime APIs, explicit checks, async, tests and laroux React components.

    128 GitHub stars~599 tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Security Practices

What does Security Practices do?

Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…. Security Practices is an agent skill from eser/stack. Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies, crypto, untrusted files and archives, LLM trust.

When should I use Security Practices?

Security Practices fits situations like: handling secrets; production config; A security review.

How do I install Security Practices in Claude Code?

Run `npx skills add eser/stack --skill security-practices -a claude-code`. Or copy the skill folder (.agents/skills/security-practices in eser/stack) into .claude/skills/security-practices in your project. Claude Code loads it when a task matches its description.

How do I install Security Practices in Codex?

Run `npx skills add eser/stack --skill security-practices -a codex`. Or copy the skill folder (.agents/skills/security-practices in eser/stack) into .agents/skills/security-practices in your project. Codex loads it when a task matches its description.

Can I use Security Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add eser/stack --skill security-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-practices, .gemini/skills/security-practices, .github/skills/security-practices and .opencode/skills/security-practices in your project.

What does Security Practices need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Practices is instructions for the agent only.

Does Security Practices access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Practices use?

Security Practices has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Practices use?

About 598 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.6k tokens, read only when the agent opens those files.

What are the alternatives to Security Practices?

Skills that share tags, products or a category with Security Practices: Audit Gitbook Integration (GitbookIO/integrations, 131 stars), Security Review (deadlock-mod-manager/deadlock-mod-manager, 473 stars), Security Review (langfuse/langfuse, 35k stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Practices?

eser (a GitHub user) maintains it in eser/stack, which has 128 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 3, 2026.

Source: eser/stack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.