Agent skill

Checking Session Security

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Analyze session management implementations to identify security vulnerabilities in web applications.

MITAuto-check passedSecurity

Install Checking Session Security

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-session-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace checking-session-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/checking-session-security .claude/skills/checking-session-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
checking-session-security
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
537 words
Files
8 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Analyze session management implementations to identify security vulnerabilities in web applications.

  • Works in 9 steps: Locate session management code by… → Analyze session ID generation: verify… → Check session fixation protections:… → …
  • You need to audit session handling
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Check for session fixation risks

What it does

Checking Session Security is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit session handling, check for session fixation risks, review session timeout configurations, or validate session ID generation security. Trigger with phrases like "check session security", "audit session management", "review session handling", or "session fixation vulnerability".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `references/critical-findings.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Authentication, Security review and Backend development. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You need to audit session handling
  • Check for session fixation risks
  • Review session timeout configurations
  • Validate session ID generation security

Example prompts

  • “check session security”
  • “audit session management”
  • “review session handling”
  • “/checking-session-security”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(code-scan:*), Bash(security-check:*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Locate session management code by searching for patterns: /auth/, /session/, /middleware/, and framework-specific files (settings.py…
  2. Analyze session ID generation: verify use of a cryptographically secure random generator with at least 128 bits of entropy. Flag…
  3. Check session fixation protections: confirm the session ID is regenerated after authentication (req.session.regenerate() in Express…
  4. Validate cookie security attributes: verify HttpOnly (prevents XSS-based token theft), Secure (HTTPS-only transmission)…
  5. Review session expiration: check idle timeout (recommend 15-30 min for sensitive apps), absolute timeout (recommend 4-8 hours), and…
  6. Audit session invalidation: verify logout handlers destroy server-side session state and clear client cookies. Confirm password reset and…
  7. Inspect session storage: flag in-memory stores in production (no persistence across restarts), unencrypted session data at rest, and…
  8. Identify attack vectors: assess exposure to session fixation, CSRF via session riding, replay attacks from stolen tokens, and session…
  9. Produce the session security report at ${CLAUDE_SKILL_DIR}/security-reports/session-security-YYYYMMDD.md with per-finding severity, CWE…

What it can do on your machine

Read from SKILL.md and the folder at commit 80f86df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(code-scan:*)
    • Bash(security-check:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cwe.mitre.org
    • cheatsheetseries.owasp.org
    • pages.nist.gov
    • intentsolutions.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Checking Session Security loads about 1.5k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 537 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 80f86df, republished under its MIT licence (© jeremylongshore). 537 words, ~1,483 tokens.

Download SKILL.mdSave it as .claude/skills/checking-session-security/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
checking-session-security
description
Analyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit session handling, check for session fixation risks, review session timeout configurations, or validate session ID generation security. Trigger with phrases like "check session security", "audit session management", "review session handling", or "session fixation vulnerability".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(code-scan:*), Bash(security-check:*)
compatibility
Designed for Claude Code
version
1.27.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, audit, checking-session

Checking Session Security

Overview

Audit session management implementations in web applications to identify vulnerabilities including session fixation (CWE-384), insufficient session expiration (CWE-613), and cleartext transmission of session tokens (CWE-319).

Prerequisites

  • Application source code accessible in ${CLAUDE_SKILL_DIR}/
  • Session management code locations identified (auth modules, middleware, session stores)
  • Framework and language identified (Express.js, Django, Spring Boot, Rails, ASP.NET, etc.)
  • Session configuration files available (session.config.*, settings.py, application.yml)
  • Write permissions for reports in ${CLAUDE_SKILL_DIR}/security-reports/

Instructions

  1. Locate session management code by searching for patterns: **/auth/**, **/session/**, **/middleware/**, and framework-specific files (settings.py, application.yml, web.config).
  2. Analyze session ID generation: verify use of a cryptographically secure random generator with at least 128 bits of entropy. Flag predictable patterns such as Date.now(), Math.random(), sequential IDs, or timestamp-based tokens (CWE-330).
  3. Check session fixation protections: confirm the session ID is regenerated after authentication (req.session.regenerate() in Express, request.session.cycle_key() in Django). Flag any login handler that sets authenticated = true without regenerating the session ID.
  4. Validate cookie security attributes: verify HttpOnly (prevents XSS-based token theft), Secure (HTTPS-only transmission), SameSite=Lax|Strict (CSRF mitigation), and __Host-/__Secure- prefix usage. Flag any missing attribute.
  5. Review session expiration: check idle timeout (recommend 15-30 min for sensitive apps), absolute timeout (recommend 4-8 hours), and sliding window configuration. Flag sessions without any expiration.
  6. Audit session invalidation: verify logout handlers destroy server-side session state and clear client cookies. Confirm password reset and privilege escalation flows invalidate existing sessions.
  7. Inspect session storage: flag in-memory stores in production (no persistence across restarts), unencrypted session data at rest, and missing integrity checks on session payloads (e.g., unsigned JWT session tokens).
  8. Identify attack vectors: assess exposure to session fixation, CSRF via session riding, replay attacks from stolen tokens, and session prediction from weak ID generation.
  9. Produce the session security report at ${CLAUDE_SKILL_DIR}/security-reports/session-security-YYYYMMDD.md with per-finding severity, CWE mapping, vulnerable code snippet, and remediated code example.

See ${CLAUDE_SKILL_DIR}/references/implementation.md for the detailed implementation guide. See ${CLAUDE_SKILL_DIR}/references/critical-findings.md for example vulnerability patterns with before/after code.

Show full SKILL.md (215 more words)Show less

Output

  • Session Security Report: ${CLAUDE_SKILL_DIR}/security-reports/session-security-YYYYMMDD.md with findings by severity
  • Cookie Attribute Matrix: per-cookie compliance table (HttpOnly, Secure, SameSite, prefix)
  • Vulnerable Code Listings: each finding with file path, line number, vulnerable snippet, and fix
  • Framework-Specific Remediation: configuration changes tailored to the detected framework

Error Handling

ErrorCauseSolution
No session handling code found in ${CLAUDE_SKILL_DIR}/Unusual file structure or frameworkSearch for framework-specific patterns; request explicit file paths
Unknown session frameworkCustom or uncommon session libraryApply fundamental session security principles; note limited framework-specific guidance
Cannot analyze minified/compiled codeProduction bundles instead of sourceRequest unminified source code; document limitation
Non-standard session implementationCustom session management bypassing frameworkApply extra scrutiny; custom implementations are higher risk (CWE-384, CWE-613)
Session config in environment variables, not codeExternalized configurationRequest .env.example or deployment config documentation

Examples

  • "Audit session cookie flags and rotation logic for fixation and CSRF risks in the Express.js application."
  • "Review logout and password reset flows to confirm sessions are invalidated correctly and old tokens cannot be replayed."
  • "Check session ID generation entropy and storage backend security for the Django application."

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/checking-session-security of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • references/critical-findings.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • scripts/README.md

Open the folder on GitHubat commit 80f86df

Compare with similar skills

Checking Session Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Checking Session Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Checking Session Security this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMIT
Senior Backendalirezarezvani/claude-skills28k1 repos~3.8kAutomated safety check: PassMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Security Review ChecklistZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Senior Backend

    alirezarezvani/claude-skills

    Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.

    28k GitHub starsUsed in 1 repo~3.8k tokens
    Backend & APIsAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Kuri Agent

    justrach/kuri

    Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

    365 GitHub stars~1.3k tokensUpdated 2 mo ago
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated yesterday
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Checking Session Security

What does Checking Session Security do?

Analyze session management implementations to identify security vulnerabilities in web applications. Checking Session Security is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze session management implementations to identify security vulnerabilities in web applications.

When should I use Checking Session Security?

Checking Session Security fits situations like: you need to audit session handling; check for session fixation risks; review session timeout configurations; validate session ID generation security.

How do I install Checking Session Security in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-session-security -a claude-code`. Or copy the skill folder (skills/.curated/checking-session-security in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/checking-session-security in your project. Claude Code loads it when a task matches its description.

How do I install Checking Session Security in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-session-security -a codex`. Or copy the skill folder (skills/.curated/checking-session-security in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/checking-session-security in your project. Codex loads it when a task matches its description.

Can I use Checking Session Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-session-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-session-security, .gemini/skills/checking-session-security, .github/skills/checking-session-security and .opencode/skills/checking-session-security in your project.

What does Checking Session Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Checking Session Security is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(code-scan:*), Bash(security-check:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Checking Session Security access the network?

SKILL.md names 4 domains. As links in the text: cwe.mitre.org, cheatsheetseries.owasp.org, pages.nist.gov and intentsolutions.io. This is read from the text; nothing was executed.

Is Checking Session Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Checking Session Security use?

Checking Session Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Checking Session Security use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Checking Session Security?

Skills that share tags, products or a category with Checking Session Security: Senior Backend (alirezarezvani/claude-skills, 28k stars), Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars), Security Review (jewbetcha/opentrace, 116 stars) and Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Checking Session Security?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,825 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 9, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.