Agent skill

Csrf Protection

by secondsky in secondsky/claude-skills

Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes.

MITAuto-check passedSecurity

Install Csrf Protection

skills CLI
$ npx skills add secondsky/claude-skills --skill csrf-protection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills csrf-protection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/csrf-protection/skills/csrf-protection .claude/skills/csrf-protection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
csrf-protection
GitHub stars
227
Token cost
~656 tokens
SKILL.md length
119 words
Files
2 (incl. references)
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes.

  • Securing web forms
  • SKILL.md covers Protection Methods, Token-Based Protection (Express), SameSite Cookies and HTML Form Integration, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Protecting state-changing endpoints

What it does

Csrf Protection is an agent skill from secondsky/claude-skills. Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. Use when securing web forms, protecting state-changing endpoints, or implementing defense-in-depth authentication.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/python-react.md`).

It sits in Security, covering Web application vulnerabilities and Secure coding. It works with React. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • Securing web forms
  • Protecting state-changing endpoints
  • Implementing defense-in-depth authentication

Example prompts

  • “Use the csrf-protection skill to implement CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes”
  • “/csrf-protection”

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript and html).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Csrf Protection loads about 656 tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 119 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~656
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 119 words, ~656 tokens.

Download SKILL.mdSave it as .claude/skills/csrf-protection/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
csrf-protection
description
Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. Use when securing web forms, protecting state-changing endpoints, or implementing defense-in-depth authentication.
license
MIT

CSRF Protection

Defend against Cross-Site Request Forgery attacks using multiple protection layers.

Protection Methods

MethodHow It WorksBrowser Support
Synchronizer TokenHidden form field validated server-sideAll
Double SubmitCookie + header must matchAll
SameSite CookieBrowser blocks cross-origin requestsModern

Token-Based Protection (Express)

javascript
const crypto = require('crypto');

function generateToken() {
  return crypto.randomBytes(32).toString('hex');
}

// Middleware
app.use((req, res, next) => {
  if (!req.session.csrfToken) {
    req.session.csrfToken = generateToken();
  }
  res.locals.csrfToken = req.session.csrfToken;
  next();
});

// Validation
app.post('*', (req, res, next) => {
  const token = req.body._csrf || req.headers['x-csrf-token'];
  // crypto.timingSafeEqual throws RangeError when buffers differ in length,
  // so check length explicitly first (still constant-time on the equal-length path).
  const csrf = req.session.csrfToken || '';
  if (!token || token.length !== csrf.length) {
    return res.status(403).json({ error: 'Invalid CSRF token' });
  }
  if (!crypto.timingSafeEqual(Buffer.from(token), Buffer.from(csrf))) {
    return res.status(403).json({ error: 'Invalid CSRF token' });
  }
  next();
});

SameSite Cookies

javascript
app.use(session({
  cookie: {
    httpOnly: true,
    secure: true,
    sameSite: 'strict', // or 'lax'
    maxAge: 3600000
  }
}));

HTML Form Integration

html
<form method="POST" action="/transfer">
  <input type="hidden" name="_csrf" value="<%= csrfToken %>">
  <button type="submit">Submit</button>
</form>

Best Practices

  • Apply to all state-changing requests (POST, PUT, DELETE)
  • Use SameSite=Strict for sensitive cookies
  • Validate Origin/Referer headers
  • Never use GET for modifications
  • Implement token expiration (1 hour typical)
  • Combine multiple defense layers

Additional Implementations

See references/python-react.md for:

  • Flask-WTF complete CSRF setup
  • React hooks for CSRF token management
  • Double submit cookie pattern

Common Mistakes

  • Assuming authentication prevents CSRF
  • Reusing tokens across sessions
  • Storing tokens in localStorage
  • Missing token expiration

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/csrf-protection/skills/csrf-protection of secondsky/claude-skills.

  • SKILL.md
  • references/python-react.md

Open the folder on GitHubat commit 8837836

Compare with similar skills

Csrf Protection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Csrf Protection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Csrf Protection this skillsecondsky/claude-skills227—~656Automated safety check: PassMIT
Fix Strix Security Findingsusestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Code Review Securitynicepkg/auto-company1921 repos~3.9kAutomated safety check: PassMIT
Security and Hardeningaddyosmani/agent-skills103k1 repos~4.4kAutomated safety check: NotesMIT

Similar skills

  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    67k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Code Review Security

    nicepkg/auto-company

    Security-focused code review checklist and automated scanning patterns.

    192 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check passed
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    103k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Owasp Security Audit

    LIDR-academy/AI4Devs-LTI-extended

    A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

    278 GitHub stars~4.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 9 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 9 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check passed

Works with

Categories

Questions about Csrf Protection

What does Csrf Protection do?

Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes. Csrf Protection is an agent skill from secondsky/claude-skills. Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes.

When should I use Csrf Protection?

Csrf Protection fits situations like: securing web forms; protecting state-changing endpoints; implementing defense-in-depth authentication.

How do I install Csrf Protection in Claude Code?

Run `npx skills add secondsky/claude-skills --skill csrf-protection -a claude-code`. Or copy the skill folder (plugins/csrf-protection/skills/csrf-protection in secondsky/claude-skills) into .claude/skills/csrf-protection in your project. Claude Code loads it when a task matches its description.

How do I install Csrf Protection in Codex?

Run `npx skills add secondsky/claude-skills --skill csrf-protection -a codex`. Or copy the skill folder (plugins/csrf-protection/skills/csrf-protection in secondsky/claude-skills) into .agents/skills/csrf-protection in your project. Codex loads it when a task matches its description.

Can I use Csrf Protection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill csrf-protection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/csrf-protection, .gemini/skills/csrf-protection, .github/skills/csrf-protection and .opencode/skills/csrf-protection in your project.

What does Csrf Protection need to run?

SKILL.md names no scripts, command-line tools or credentials: Csrf Protection is instructions for the agent only.

Does Csrf Protection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Csrf Protection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Csrf Protection use?

Csrf Protection is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Csrf Protection use?

About 656 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Csrf Protection?

Skills that share tags, products or a category with Csrf Protection: Fix Strix Security Findings (usestrix/strix, 67k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Code Review Security (nicepkg/auto-company, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Csrf Protection?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.