API Security Checklist
revfactory/harness-100
Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.
Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.
$ npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Jeffallan/claude-skills secure-code-guardian --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secure-code-guardian .claude/skills/secure-code-guardian && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secure-code-guardian" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardian into .claude/skills/secure-code-guardian/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-guardian", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardianType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Jeffallan/claude-skills secure-code-guardian --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/secure-code-guardian .agents/skills/secure-code-guardian && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secure-code-guardian" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardian into .agents/skills/secure-code-guardian/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-guardian", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Jeffallan/claude-skills secure-code-guardian --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/secure-code-guardian .cursor/skills/secure-code-guardian && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secure-code-guardian" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardian into .cursor/skills/secure-code-guardian/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-guardian", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Jeffallan/claude-skills.git --path skills/secure-code-guardian--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Jeffallan/claude-skills secure-code-guardian --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/secure-code-guardian .gemini/skills/secure-code-guardian && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secure-code-guardian" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardian into .gemini/skills/secure-code-guardian/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-guardian", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Jeffallan/claude-skills secure-code-guardianInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/secure-code-guardian .github/skills/secure-code-guardian && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secure-code-guardian" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardian into .github/skills/secure-code-guardian/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-guardian", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Jeffallan/claude-skills secure-code-guardian --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/secure-code-guardian .opencode/skills/secure-code-guardian && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secure-code-guardian" agent skill from https://github.com/Jeffallan/claude-skills/tree/main/skills/secure-code-guardian into .opencode/skills/secure-code-guardian/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-guardian", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secure-code-guardianGuides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.
The loop is threat model, design, implement with defense in depth, validate and document. Validation has explicit checkpoints: test brute-force protection, session fixation resistance, token expiry and error messages that do not reveal whether a user exists; check horizontal and vertical privilege escalation with tokens from different roles; confirm SQL injection and XSS test payloads are rejected or escaped; and use curl -I or a scanner such as Mozilla Observatory to confirm security headers and the CORS allowlist.
The rules call for bcrypt or argon2 password hashing, parameterized queries, input validation and sanitizing, rate limiting on auth endpoints, security headers such as CSP and HSTS, logging of security events, and secrets kept in environment variables or a secret manager. They rule out plaintext passwords, weak algorithms like MD5 and SHA-1, and sensitive data in logs or errors. Reference files cover OWASP prevention, authentication and JWT, Zod input validation, XSS and CSRF, and headers with Helmet.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1be15d8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comsynergetic.solutionsjeffallan.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
JWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secure Code Guardian loads about 1.8k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 154 tokens; SKILL.md has 344 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Jeffallan/claude-skills at commit 1be15d8, republished under its MIT licence (© Jeffallan). 344 words, ~1,799 tokens.
.claude/skills/secure-code-guardian/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.After each implementation step, verify:
' OR 1=1--) are rejected; confirm XSS payloads (<script>alert(1)</script>) are escaped or rejected.curl -I, Mozilla Observatory) that security headers are present and CORS origin allowlist is correct.Load detailed guidance based on context:
| Topic | Reference | Load When |
|---|---|---|
| OWASP | references/owasp-prevention.md | OWASP Top 10 patterns |
| Authentication | references/authentication.md | Password hashing, JWT |
| Input Validation | references/input-validation.md | Zod, SQL injection |
| XSS/CSRF | references/xss-csrf.md | XSS prevention, CSRF |
| Headers | references/security-headers.md | Helmet, rate limiting |
import bcrypt from 'bcrypt';
const SALT_ROUNDS = 12; // minimum 10; 12 balances security and performance
export async function hashPassword(plaintext: string): Promise<string> {
return bcrypt.hash(plaintext, SALT_ROUNDS);
}
export async function verifyPassword(plaintext: string, hash: string): Promise<boolean> {
return bcrypt.compare(plaintext, hash);
}// NEVER: `SELECT * FROM users WHERE email = '${email}'`
// ALWAYS: use positional parameters
import { Pool } from 'pg';
const pool = new Pool();
export async function getUserByEmail(email: string) {
const { rows } = await pool.query(
'SELECT id, email, role FROM users WHERE email = $1',
[email] // value passed separately — never interpolated
);
return rows[0] ?? null;
}import { z } from 'zod';
const LoginSchema = z.object({
email: z.string().email().max(254),
password: z.string().min(8).max(128),
});
export function validateLoginInput(raw: unknown) {
const result = LoginSchema.safeParse(raw);
if (!result.success) {
// Return generic error — never echo raw input back
throw new Error('Invalid credentials format');
}
return result.data;
}import jwt from 'jsonwebtoken';
const JWT_SECRET = process.env.JWT_SECRET!; // never hardcode
export function verifyToken(token: string): jwt.JwtPayload {
// Throws if expired, tampered, or wrong algorithm
const payload = jwt.verify(token, JWT_SECRET, {
algorithms: ['HS256'], // explicitly allowlist algorithm
issuer: 'your-app',
audience: 'your-app',
});
if (typeof payload === 'string') throw new Error('Invalid token payload');
return payload;
}import express from 'express';
import rateLimit from 'express-rate-limit';
import helmet from 'helmet';
const app = express();
app.use(helmet()); // sets CSP, HSTS, X-Frame-Options, etc.
app.use(express.json({ limit: '10kb' })); // limit payload size
const authLimiter = rateLimit({
windowMs: 15 * 60 * 1000, // 15 minutes
max: 10, // 10 attempts per window per IP
standardHeaders: true,
legacyHeaders: false,
});
app.post('/api/login', authLimiter, async (req, res) => {
// 1. Validate input
const { email, password } = validateLoginInput(req.body);
// 2. Authenticate — parameterized query, constant-time compare
const user = await getUserByEmail(email);
if (!user || !(await verifyPassword(password, user.passwordHash))) {
// Generic message — do not reveal whether email exists
return res.status(401).json({ error: 'Invalid credentials' });
}
// 3. Authorize — issue scoped, short-lived token
const token = jwt.sign(
{ sub: user.id, role: user.role },
JWT_SECRET,
{ algorithm: 'HS256', expiresIn: '15m', issuer: 'your-app', audience: 'your-app' }
);
// 4. Secure response — token in httpOnly cookie, not body
res.cookie('token', token, { httpOnly: true, secure: true, sameSite: 'strict' });
return res.json({ message: 'Authenticated' });
});When implementing security features, provide:
OWASP Top 10, bcrypt/argon2, JWT, OAuth 2.0, OIDC, CSP, CORS, rate limiting, input validation, output encoding, encryption (AES, RSA), TLS, security headers
Maintained by @jeffallan, Principal Consultant at Synergetic Solutions
© Jeffallan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/secure-code-guardian of Jeffallan/claude-skills.
Open the folder on GitHubat commit 1be15d8
Secure Code Guardian next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secure Code Guardian this skillJeffallan/claude-skills | 12k | — | ~1.8k | Automated safety check: Pass | MIT | |
| API Security Checklistrevfactory/harness-100 | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Security And Hardeningdzhalaevd/Donatello | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | |
| Hunt APIEncod3d-Sec/TORCH | 329 | — | ~1.9k | Automated safety check: Pass | MIT |
revfactory/harness-100
Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
dzhalaevd/Donatello
Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.
Encod3d-Sec/TORCH
API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.
secondsky/claude-skills
Cloudflare Workers security with authentication, CORS, rate limiting, input validation.
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
Jeffallan/claude-skills
Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.
Jeffallan/claude-skills
Guides LLM fine-tuning with LoRA and QLoRA through Hugging Face PEFT, from dataset validation and training checks to adapter merging, quantization and deployment.
Jeffallan/claude-skills
Designs GraphQL schemas and Apollo Federation graphs, with DataLoader resolvers, subscriptions, query complexity limits and caching.
Jeffallan/claude-skills
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
Jeffallan/claude-skills
Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.
Works with
Categories
Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks. The loop is threat model, design, implement with defense in depth, validate and document. Validation has explicit checkpoints: test brute-force protection, session fixation resistance, token expiry and error messages that do not reveal whether a user exists; check horizontal and vertical privilege escalation with tokens from different roles; confirm SQL injection and XSS test payloads are rejected or escaped; and use curl -I or a scanner such as Mozilla Observatory to confirm security headers and the CORS allowlist.
Secure Code Guardian fits situations like: adding login, sessions or JWT handling to an application; hashing passwords and storing secrets safely; validating and sanitizing user input to block injection; setting CORS, CSP and other security headers.
Run `npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a claude-code`. Or copy the skill folder (skills/secure-code-guardian in Jeffallan/claude-skills) into .claude/skills/secure-code-guardian in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a codex`. Or copy the skill folder (skills/secure-code-guardian in Jeffallan/claude-skills) into .agents/skills/secure-code-guardian in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jeffallan/claude-skills --skill secure-code-guardian -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-code-guardian, .gemini/skills/secure-code-guardian, .github/skills/secure-code-guardian and .opencode/skills/secure-code-guardian in your project.
Going by SKILL.md and its folder, Secure Code Guardian needs the command-line tools its instructions call (curl) and credentials named JWT_SECRET.
SKILL.md names 3 domains. As links in the text: github.com, synergetic.solutions and jeffallan.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Secure Code Guardian is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Secure Code Guardian: API Security Checklist (revfactory/harness-100, 1.3k stars), Security And Hardening (penpot/penpot, 61k stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars) and Security And Hardening (dzhalaevd/Donatello, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Jeffallan (a GitHub user) maintains it in Jeffallan/claude-skills, which has 11,754 GitHub stars. The repository holds 58 skills in this directory. The repository was last updated on October 3, 2026.
Source: Jeffallan/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.