Agent skill

Common Security Standards

by HoangNguyen0403 in HoangNguyen0403/agent-skills-standard

Enforce universal security protocols for safe, resilient software.

MITAuto-check passedBackend & APIs

Install Common Security Standards

skills CLI
$ npx skills add HoangNguyen0403/agent-skills-standard --skill common-security-standards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HoangNguyen0403/agent-skills-standard common-security-standards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/common/common-security-standards .claude/skills/common-security-standards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
common-security-standards
GitHub stars
572
Token cost
~764 tokens
SKILL.md length
296 words
Files
5 (incl. references)
Skills in repo
211
Repo updated
First seen
Licence
MIT

At a glance

Enforce universal security protocols for safe, resilient software.

  • Works in 4 steps: Identify trust boundaries — map every… → Validate and sanitize all external input… → Apply least privilege to users,… → …
  • Implementing authentication
  • SKILL.md covers Priority: P0 (CRITICAL), Always-Apply Rules, Workflow and Context-Specific Rules, plus 3 more sections
  • Calls npm and pip

What it does

Common Security Standards is an agent skill from HoangNguyen0403/agent-skills-standard. Enforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/evals.json`, `references/INJECTION_TESTING.md` and `references/VULNERABILITY_REMEDIATION.md`).

It sits in Backend & APIs, covering Secrets management and Authentication. The repository describes itself as: A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages. The licence is MIT.

When your agent uses it

  • Implementing authentication
  • Input validation
  • Secret management
  • Any security-sensitive feature across any language

Example prompts

  • “/common-security-standards”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify trust boundaries — map every data entry point (API, UI, CSV, webhook).
  2. Validate and sanitize all external input at each boundary.
  3. Apply least privilege to users, services, and containers.
  4. Verify with SAST/DAST scanners in CI before merge.

What it can do on your machine

Read from SKILL.md and the folder at commit b529c2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Common Security Standards loads about 764 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~764
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HoangNguyen0403/agent-skills-standard at commit b529c2d, republished under its MIT licence (© HoangNguyen0403). 296 words, ~764 tokens.

Download SKILL.mdSave it as .claude/skills/common-security-standards/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
common-security-standards
description
Enforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.

Security Standards

Priority: P0 (CRITICAL)

Always-Apply Rules

Apply these on every code write, regardless of context:

  • No hardcoded secrets: Use environment variables or secret managers. Never commit keys, passwords, or tokens to source control.
  • No raw SQL strings: Use parameterized queries or ORMs — WHERE id = ${userId} always wrong.
  • No stacktraces in prod: Return generic error codes; log full detail server-side only.

Workflow

Activate when: implementing auth, encryption, authorization, input handling, or any security-sensitive feature.

  1. Identify trust boundaries — map every data entry point (API, UI, CSV, webhook).
  2. Validate and sanitize all external input at each boundary.
  3. Apply least privilege to users, services, and containers.
  4. Verify with SAST/DAST scanners in CI before merge.

Context-Specific Rules

Data Safeguarding
  • Zero Trust: Never trust external input. Sanitize and validate every data boundary.
  • Least Privilege: Grant minimum necessary permissions to users, services, and containers.
  • Encryption: AES-256 for data-at-rest; TLS 1.3 for data-in-transit.
  • PII Logging: Never log PII (email, phone, names). Mask sensitive fields before logging.

See implementation examples for parameterized queries and secret management.

Secure Coding
  • Injection Prevention: Use parameterized queries or ORMs to stop SQL, Command, and XSS injections.
  • Dependency Management: Regularly scan (npm audit, pip audit) and update third-party libraries to patch CVEs.
  • Secure Auth: Implement Multi-Factor Authentication (MFA) and secure session management.
  • Error Privacy: Never leak stack traces or internal implementation details to end-user.
Continuous Security
  • Shift Left: Integrate security scanners (SAST/DAST) early in CI/CD pipeline.
  • Data Minimization: Collect and store only minimum data required for business logic.
  • Audit Logging: Maintain logs for sensitive operations (Auth, Deletion, Admin changes).

Anti-Patterns

  • No default passwords: Force rotation on first use with strong entropy requirements.

References

Remediation anchors

  • Remediation anchors: Argon2id, parameterized queries or ORM, rate limiting, HttpOnly Secure cookies

© HoangNguyen0403, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/common/common-security-standards of HoangNguyen0403/agent-skills-standard.

  • SKILL.md
  • evals/evals.json
  • references/INJECTION_TESTING.md
  • references/VULNERABILITY_REMEDIATION.md
  • references/implementation.md

Open the folder on GitHubat commit b529c2d

Compare with similar skills

Common Security Standards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Common Security Standards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Common Security Standards this skillHoangNguyen0403/agent-skills-standard572—~764Automated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Debugsbusso/claudeclaw1941 repos~3.3kAutomated safety check: NotesMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
JS Secrets Extractionuphiago/recon-skills1.3k—~2.6kAutomated safety check: PassMIT
Scanning For Hardcoded Secretsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT

Similar skills

  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Debug

    sbusso/claudeclaw

    Debug container agent issues. An agent skill from sbusso/claudeclaw.

    194 GitHub starsUsed in 1 repo~3.3k tokens
    DevOps & CloudAuto-check: notes
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Scanning For Hardcoded Secrets

    jeremylongshore/tons-of-skills-marketplace

    Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic…

    2.8k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from HoangNguyen0403/agent-skills-standard

All 211 skills in this repo
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • draw.io Architecture Diagramming

    HoangNguyen0403/agent-skills-standard

    Draws architecture diagrams as editable draw.io files from a JSON spec, with a fixed house style, one C4 level per diagram and evidence-tagged shapes.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Android Navigation 3 Guide

    HoangNguyen0403/agent-skills-standard

    Implements and migrates to Jetpack Navigation 3 in Compose: NavDisplay, typed route objects, a state-list back stack, deep links, multiple back stacks and dialog scenes.

    572 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    572 GitHub stars~652 tokensUpdated yesterday
    Auto-check passed
  • Angular Tooling

    HoangNguyen0403/agent-skills-standard

    Angular CLI usage, code generation, build configuration, and bundle optimization.

    572 GitHub stars~743 tokensUpdated yesterday
    Auto-check passed
  • Common Code Review

    HoangNguyen0403/agent-skills-standard

    Conduct high-quality, persona-driven code reviews. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Questions about Common Security Standards

What does Common Security Standards do?

Enforce universal security protocols for safe, resilient software. Common Security Standards is an agent skill from HoangNguyen0403/agent-skills-standard. Enforce universal security protocols for safe, resilient software.

When should I use Common Security Standards?

Common Security Standards fits situations like: implementing authentication; input validation; secret management; any security-sensitive feature across any language.

How do I install Common Security Standards in Claude Code?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill common-security-standards -a claude-code`. Or copy the skill folder (skills/common/common-security-standards in HoangNguyen0403/agent-skills-standard) into .claude/skills/common-security-standards in your project. Claude Code loads it when a task matches its description.

How do I install Common Security Standards in Codex?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill common-security-standards -a codex`. Or copy the skill folder (skills/common/common-security-standards in HoangNguyen0403/agent-skills-standard) into .agents/skills/common-security-standards in your project. Codex loads it when a task matches its description.

Can I use Common Security Standards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HoangNguyen0403/agent-skills-standard --skill common-security-standards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/common-security-standards, .gemini/skills/common-security-standards, .github/skills/common-security-standards and .opencode/skills/common-security-standards in your project.

What does Common Security Standards need to run?

Going by SKILL.md and its folder, Common Security Standards needs the command-line tools its instructions call (npm and pip).

Does Common Security Standards access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Common Security Standards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Common Security Standards use?

Common Security Standards is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Common Security Standards use?

About 764 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 674 tokens, read only when the agent opens those files.

What are the alternatives to Common Security Standards?

Skills that share tags, products or a category with Common Security Standards: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Debug (sbusso/claudeclaw, 194 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars) and JS Secrets Extraction (uphiago/recon-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Common Security Standards?

HoangNguyen0403 (a GitHub user) maintains it in HoangNguyen0403/agent-skills-standard, which has 572 GitHub stars. The repository holds 211 skills in this directory. The repository was last updated on October 9, 2026.

Source: HoangNguyen0403/agent-skills-standard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.