API Security Engineer
FerroxLabs/wayland
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…
A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…
$ npx skills add NoobyGains/godmode --skill security-protocol -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install NoobyGains/godmode security-protocol --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/NoobyGains/godmode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-protocol .claude/skills/security-protocol && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-protocol" agent skill from https://github.com/NoobyGains/godmode/tree/master/skills/security-protocol into .claude/skills/security-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-protocol", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/NoobyGains/godmode/tree/master/skills/security-protocolType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add NoobyGains/godmode --skill security-protocol -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install NoobyGains/godmode security-protocol --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NoobyGains/godmode.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-protocol .agents/skills/security-protocol && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-protocol" agent skill from https://github.com/NoobyGains/godmode/tree/master/skills/security-protocol into .agents/skills/security-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-protocol", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add NoobyGains/godmode --skill security-protocol -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install NoobyGains/godmode security-protocol --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NoobyGains/godmode.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-protocol .cursor/skills/security-protocol && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-protocol" agent skill from https://github.com/NoobyGains/godmode/tree/master/skills/security-protocol into .cursor/skills/security-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-protocol", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/NoobyGains/godmode.git --path skills/security-protocol--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add NoobyGains/godmode --skill security-protocol -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install NoobyGains/godmode security-protocol --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NoobyGains/godmode.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-protocol .gemini/skills/security-protocol && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-protocol" agent skill from https://github.com/NoobyGains/godmode/tree/master/skills/security-protocol into .gemini/skills/security-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-protocol", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install NoobyGains/godmode security-protocolInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add NoobyGains/godmode --skill security-protocol -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/NoobyGains/godmode.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-protocol .github/skills/security-protocol && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-protocol" agent skill from https://github.com/NoobyGains/godmode/tree/master/skills/security-protocol into .github/skills/security-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-protocol", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add NoobyGains/godmode --skill security-protocol -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install NoobyGains/godmode security-protocol --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NoobyGains/godmode.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-protocol .opencode/skills/security-protocol && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-protocol" agent skill from https://github.com/NoobyGains/godmode/tree/master/skills/security-protocol into .opencode/skills/security-protocol/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-protocol", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-protocolA skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…
Security Protocol is an agent skill from NoobyGains/godmode. Use when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data, exposes API endpoints, or manages secrets - any code that crosses a trust boundary
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authorization and RBAC, REST APIs and Authentication. The repository describes itself as: The AI development framework that thinks before it builds. 36 composable skills for Claude Code, Cursor, Codex, and OpenCode. The licence is MIT.
Read from SKILL.md and the folder at commit 441103a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmpipcargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Protocol loads about 2.4k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 867 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Commit .env files to version control- Add .env to .gitignore BEFORE the first commitAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from NoobyGains/godmode at commit 441103a, republished under its MIT licence (© NoobyGains). 867 words, ~2,387 tokens.
.claude/skills/security-protocol/SKILL.md (or your agent's skills folder).Security is not a phase you bolt on. Every line of code is a security decision.
Core principle: Never trust data from outside your trust boundary. Validate at every boundary crossing.
No exceptions. No workarounds. No shortcuts.
NO EXTERNAL DATA REACHES A SYSTEM CALL, QUERY, OR OUTPUT WITHOUT VALIDATION AND SANITIZATIONWhen data crosses a trust boundary, it must be validated before consumption. This is absolute.
Mandatory when writing code that:
This is not discretionary. Security awareness is woven into development, not applied afterward.
BEFORE shipping ANY code that handles external data:
1. IDENTIFY: Where does data enter the system? (Trust boundary)
2. VALIDATE: Is input validated at the boundary?
3. SANITIZE: Is output encoded for its target context?
4. AUTHORIZE: Is access control verified before the action?
5. PROTECT: Are secrets, tokens, and keys managed safely?
Omit any step = vulnerability shippedEvery endpoint must verify: Can THIS user perform THIS action on THIS resource?
# VULNERABLE: Checks authentication but not authorization
GET /api/accounts/456/profile # User 123 views user 456's private data
# SECURE: Verify resource ownership
if resource.owner_id != authenticated_user.id:
return 403 Forbidden| Verification | Method |
|---|---|
| Authentication | Is the user who they claim to be? |
| Authorization | Is this user permitted to perform this action? |
| Resource ownership | Does this user own this specific resource? |
| Role enforcement | Server-side role check; never trust client-provided role claims |
Default posture: deny. If no explicit rule grants access, access is denied.
| Required Practice | Prohibited Practice |
|---|---|
| bcrypt/scrypt/argon2 for password hashing | MD5, SHA1, SHA256 for passwords |
| TLS everywhere (HTTPS) | HTTP for anything sensitive |
| Cryptographically secure RNG for tokens | Math.random() for security tokens |
| Encrypt sensitive data at rest | Store sensitive data in plaintext |
| Use established cryptographic libraries | Implement custom cryptography |
Never concatenate external input into queries, commands, or templates.
| Injection Vector | Prevention |
|---|---|
| SQL injection | Parameterized queries / prepared statements. Always. |
| NoSQL injection | Type-check inputs; use ODM query builders |
| Command injection | Avoid shell execution. If unavoidable: allowlist arguments, never interpolate |
| LDAP injection | Escape special characters; use parameterized queries |
| Template injection | Use auto-escaping template engines |
-- VULNERABLE: String concatenation
SELECT * FROM users WHERE email = '" + userInput + "'
-- SECURE: Parameterized query
SELECT * FROM users WHERE email = $1This is non-negotiable. There is no scenario where string concatenation in queries is acceptable.
| Checkpoint | Action |
|---|---|
| Default credentials | Replace all defaults before deployment |
| Debug features | Disable debug mode, admin consoles, and verbose errors in production |
| Error verbosity | Never expose stack traces, SQL errors, or internal paths to users |
| Directory listing | Disable on all web servers |
| Security headers | Set them (see Security Headers section) |
| CORS policy | Restrict to specific origins; never * for credentialed requests |
BEFORE adding any dependency:
1. Is it actively maintained? (Last commit within 6 months)
2. Are known vulnerabilities published? (npm audit, snyk, dependabot)
3. Is it widely adopted? (Download counts and stars are signals, not guarantees)
4. Is it actually necessary? (Do not add a dependency for a single utility function)Execute npm audit / pip audit / cargo audit regularly. Remediate critical and high findings immediately.
| Requirement | Implementation |
|---|---|
| Password storage | bcrypt/scrypt/argon2 with unique salts |
| Session tokens | Cryptographically random, httpOnly, secure, sameSite flags |
| Brute-force protection | Lock account after 5-10 consecutive failures |
| Multi-factor authentication | Support TOTP minimum for sensitive applications |
| Password policy | Minimum 8 characters; cross-reference against breach databases |
| Session lifecycle | Expire sessions; invalidate on password change |
eval(), no pickle.loads() on user input)| Log | Never Log |
|---|---|
| Authentication attempts (success and failure) | Passwords or authentication tokens |
| Authorization denials | Complete credit card numbers |
| Input validation failures | Personally identifiable information without purpose |
| System errors | Encryption keys or secrets |
Set these on every HTTP response:
Content-Security-Policy: default-src 'self'; script-src 'self'
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Strict-Transport-Security: max-age=31536000; includeSubDomains
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()Begin restrictive and relax only when a specific requirement demands it.
NEVER:
- Embed secrets in source code
- Commit .env files to version control
- Write secrets to log output
- Transmit secrets in URL query parameters
- Store secrets in client-side code
ALWAYS:
- Use environment variables or dedicated secret managers
- Add .env to .gitignore BEFORE the first commit
- Rotate secrets on a defined schedule
- Use distinct secrets per environment
- Audit secret accessFor every input field:
| Rationalization | Truth |
|---|---|
| "Internal tool, no attacker" | Internal tools get compromised. Internal users make mistakes. Insider threats are real. |
| "We will add security later" | Security is not a feature. Retrofitting it costs 10x more than building it in. |
| "The framework handles it" | Frameworks have escape hatches. Know exactly what your framework does and does not protect. |
| "Input validation is excessive" | Every injection attack in history started with unvalidated input. |
| "It is just a prototype" | Prototypes become production systems. Secure from the beginning. |
| "Too complicated, slows development" | Data breaches slow development permanently. |
| "Nobody would do that" | Attackers do exactly that. Assume all input is hostile. |
eval() or exec() on user-provided data* CORS policy with credentialsEvery item on this list is a security vulnerability. Remediate before shipping.
Complementary skills:
Trust boundary crossed -> validate input, sanitize output, verify authorizationNo exceptions. No "we will add it later." Security ships with the code or the code does not ship.
© NoobyGains, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-protocol of NoobyGains/godmode.
Open the folder on GitHubat commit 441103a
Security Protocol next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Protocol this skillNoobyGains/godmode | 107 | — | ~2.4k | Automated safety check: Notes | MIT | |
| API Security EngineerFerroxLabs/wayland | 608 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| API Auditbriiirussell/cybersecurity-skills | 412 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Auth BypassNeoTheCapt/RedteamAgent | 140 | — | ~1.3k | Automated safety check: Pass | None | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Django Securityaffaan-m/ECC | 274k | 5 repos | ~4k | Automated safety check: Notes | MIT |
FerroxLabs/wayland
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
NeoTheCapt/RedteamAgent
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
affaan-m/ECC
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
affaan-m/ECC
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
NoobyGains/godmode
A skill your agent uses when starting any conversation - establishes how to locate and invoke skills, mandating Skill tool usage before ANY response including clarifying questions
NoobyGains/godmode
A skill your agent uses when dispatching subagents, composing prompts for teammates, structuring handoff reports, or managing context boundaries between agents.
NoobyGains/godmode
A skill your agent uses when building ANY feature within an existing project - search the current codebase for existing patterns, conventions, similar implementations, and established approaches…
NoobyGains/godmode
A skill your agent uses when about to declare work done, fixed, or passing, before committing or opening PRs - demands executing verification commands and reading their output before making any…
NoobyGains/godmode
A skill your agent uses when implementing any substantial feature, multi-file modification, or architectural change - produces a plain-language walkthrough of every alteration so the developer can…
NoobyGains/godmode
A skill your agent uses when executing implementation plans with independent tasks in the current session
Categories
A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…. Security Protocol is an agent skill from NoobyGains/godmode.
Security Protocol fits situations like: writing code that processes user input; manages authentication; constructs database queries; handles file operations.
Run `npx skills add NoobyGains/godmode --skill security-protocol -a claude-code`. Or copy the skill folder (skills/security-protocol in NoobyGains/godmode) into .claude/skills/security-protocol in your project. Claude Code loads it when a task matches its description.
Run `npx skills add NoobyGains/godmode --skill security-protocol -a codex`. Or copy the skill folder (skills/security-protocol in NoobyGains/godmode) into .agents/skills/security-protocol in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NoobyGains/godmode --skill security-protocol -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-protocol, .gemini/skills/security-protocol, .github/skills/security-protocol and .opencode/skills/security-protocol in your project.
Going by SKILL.md and its folder, Security Protocol needs the command-line tools its instructions call (npm, pip and cargo).
SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Protocol is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Protocol: API Security Engineer (FerroxLabs/wayland, 608 stars), API Audit (briiirussell/cybersecurity-skills, 412 stars), Auth Bypass (NeoTheCapt/RedteamAgent, 140 stars) and API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
NoobyGains (a GitHub user) maintains it in NoobyGains/godmode, which has 107 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on March 9, 2026.
Source: NoobyGains/godmode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.