Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation

Apache-2.0Auto-check: notesSecurity

Install Security

skills CLI
$ npx skills add static-web-server/static-web-server --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install static-web-server/static-web-server security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/static-web-server/static-web-server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
2.4k
Token cost
~1.5k tokens
SKILL.md length
698 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation

  • Tasks that involve Secure coding
  • SKILL.md covers General Principles, Path Traversal Prevention, TLS & HTTPS and HTTP Security Headers, plus 6 more sections
  • Calls cargo

What it does

Security is an agent skill from static-web-server/static-web-server. Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secure coding. It works with Linux. The repository describes itself as: A cross-platform, high-performance and asynchronous web server for static files-serving. ⚡. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secure coding

Example prompts

  • “/security”

What it can do on your machine

Read from SKILL.md and the folder at commit 32ec4aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 1.5k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 698 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:98
    - **`.env` files are gitignored**: Never commit `.env` files or configs with embedded secrets

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from static-web-server/static-web-server at commit 32ec4aa, republished under its Apache-2.0 licence (© static-web-server). 698 words, ~1,513 tokens.

Download SKILL.mdSave it as .claude/skills/security/SKILL.md (or your agent's skills folder).
name
security
description
Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation

Security Best Practices

Load this skill when implementing authentication, hardening the file-serving pipeline, configuring TLS, reviewing CORS policies, or auditing path handling.

When to load: touching src/static_files/security.rs, src/security_headers.rs, src/cors.rs, src/basic_auth.rs, src/tls.rs, or any code that handles user-supplied paths, headers, or credentials.

General Principles

  • Least privilege: Run SWS on a non-privileged port (8787 by default). Use systemd socket activation or a reverse proxy for port 80/443. Never run as root
  • Defense in depth: Path traversal is prevented at multiple layers (see below). No single layer is sufficient
  • Fail closed: If a security check errors, deny access. Traversal and hidden-file violations return 404 (not 403) to avoid leaking information about the filesystem layout. Symlink policy violations return 403
  • Don't roll your own crypto: Use tokio-rustls (backed by ring or aws-lc-rs for FIPS) for TLS. Never implement ciphers or hashing

Path Traversal Prevention

SWS's multi-layer defense against directory traversal:

Layer 1: Path Sanitization

sanitize_path() in src/fs/path.rs processes each path component:

  • Strips .. (ParentDir), root prefixes, and Windows drive prefixes
  • Normalizes // and ./ (CurDir)
  • Percent-decodes the URI path before processing
Layer 2: Containment Check

resolve_and_contain() and enforce_containment() in src/static_files/security.rs:

  • Canonicalizes the resolved file path (resolves all symlinks to real paths)
  • Verifies the canonical path starts with the canonical base directory
  • Returns StatusCode::NOT_FOUND (404) if the path escapes the base — fail closed, no info leak

When --follow-symlinks is disabled (default), enforce_symlink_policy() in src/static_files/security.rs walks every path component and checks for symlinks using symlink_metadata(). Returns StatusCode::FORBIDDEN (403) if any component is a symlink.

Layer 4: Hidden File Blocking

When --include-hidden is disabled (default), any path component starting with . is rejected with StatusCode::NOT_FOUND (404). This is a pure string check (zero syscalls) and runs before the more expensive symlink walk.

TLS & HTTPS

  • Enable TLS in production: Use --tls --tls-cert cert.pem --tls-key key.pem
  • TLS 1.2+ only: Configured via tokio-rustls. Default cipher suites are secure
  • HTTP/2 requires TLS: --http2 depends on --tls being enabled
  • HTTPS redirect: Use --https-redirect to redirect HTTP→HTTPS. Configure --https-redirect-host and --https-redirect-from-port
  • Security headers auto-enable with TLS: When --tls is active, security headers default to true

HTTP Security Headers

SWS sends these headers when --security-headers is enabled (default with TLS):

HeaderValuePurpose
Strict-Transport-Securitymax-age=63072000; includeSubDomains; preloadEnforce HTTPS for 2 years
X-Frame-OptionsDENYPrevent clickjacking
X-Content-Type-OptionsnosniffPrevent MIME-type sniffing
Content-Security-Policyframe-ancestors 'self'Restrict embedding
Referrer-Policystrict-origin-when-cross-originControl referrer information

HSTS is only sent when TLS is active. Other headers are safe on plain HTTP.

Show full SKILL.md (295 more words)Show less

CORS

  • Restrictive by default: CORS is disabled unless --cors-allow-origins is set
  • Avoid wildcard with credentials: Access-Control-Allow-Origin: * is supported but incompatible with credentials
  • Explicit origin list preferred: --cors-allow-origins="https://example.com,https://app.example.com"
  • Limit allowed methods: SWS only allows GET, HEAD, OPTIONS. Other methods return 405
  • Custom allowed/exposed headers: --cors-allow-headers and --cors-expose-headers

Basic Authentication

  • Use --basic-auth: Format is BCrypt-hashed password. Generate with htpasswd -B or SWS's built-in tooling
  • Credentials in every request: HTTP Basic Auth sends credentials base64-encoded (not encrypted). Always use with TLS
  • No brute-force protection built in: Put SWS behind a reverse proxy (nginx, Caddy) for rate limiting if needed

Input Validation

  • HTTP method allowlist: Only GET, HEAD, OPTIONS are permitted. Other methods → 405
  • Max URI length: Hyper's default limits apply. Extremely long URIs are rejected by the HTTP parser
  • Request body is ignored: SWS is a static file server. Request bodies are not read or processed
  • File path validation: All user-supplied paths go through sanitization and canonicalization before filesystem access

Dependency Security

  • Audit dependencies regularly: Run cargo audit to check for known vulnerabilities
  • Minimal dependency footprint: SWS has a carefully curated dependency tree. New dependencies must justify their inclusion
  • Pin critical deps: tokio, hyper, tokio-rustls, rustls are the security-critical core

Secrets Management

  • No secrets in source code: TLS private keys, basic auth credentials, and config secrets live in files or environment variables
  • TLS private key file permissions: Set chmod 600 on private key files
  • .env files are gitignored: Never commit .env files or configs with embedded secrets

Checklist

  • Are all user-supplied paths sanitized and contained?
  • Is TLS enabled for production deployments?
  • Are security headers enabled?
  • Is CORS restricted to specific origins (not wildcard with credentials)?
  • Are symlinks disabled if the served directory contains user-writable areas?
  • Are hidden files ignored to prevent accidental exposure?
  • Are dependencies audited (cargo audit)?

© static-web-server, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security of static-web-server/static-web-server.

Open the folder on GitHubat commit 32ec4aa

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skillstatic-web-server/static-web-server2.4k—~1.5kAutomated safety check: NotesApache-2.0
Hadolint Dockerfile Security LintingAgentSecOps/SecOpsAgentKit2201 repos~4.4kAutomated safety check: PassCustom licence
Implementing Sigstore For Software Signingmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0
Implementing File Integrity Monitoring With Aidemukul975/Anthropic-Cybersecurity-Skills34k—~642Automated safety check: NotesApache-2.0
Configuring Firewallsancoleman/ai-design-components526—~3.5kAutomated safety check: NotesMIT
Performing Authenticated Scan With Openvasmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: WarnApache-2.0

Similar skills

  • Hadolint Dockerfile Security Linting

    AgentSecOps/SecOpsAgentKit

    Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

    220 GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check passed
  • Implementing Sigstore For Software Signing

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing File Integrity Monitoring With Aide

    mukul975/Anthropic-Cybersecurity-Skills

    Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and…

    34k GitHub stars~642 tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Configuring Firewalls

    ancoleman/ai-design-components

    Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Performing Authenticated Scan With Openvas

    mukul975/Anthropic-Cybersecurity-Skills

    Configure and execute authenticated (credentialed) vulnerability scans using OpenVAS/Greenbone Vulnerability Management (GVM) with SSH, SMB, or ESXi credentials to detect local vulnerabilities…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: notes

More from static-web-server/static-web-server

All 9 skills in this repo
  • Design

    static-web-server/static-web-server

    Design or review software architecture, API contracts, data models, and module boundaries for the Static Web Server (SWS) project

    2.4k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Issue Tracking

    static-web-server/static-web-server

    Triage, debug, fix, and document issues for the Static Web Server (SWS) project — bug reports, root cause analysis, fix implementation, and regression prevention

    2.4k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Performance

    static-web-server/static-web-server

    Optimize or review performance for the Static Web Server (SWS) project — profiling, bottlenecks, resource usage, compression, and caching

    2.4k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Prose

    static-web-server/static-web-server

    Author or edit any prose for the Static Web Server (SWS) project — documentation, design docs, READMEs, PR descriptions, issue bodies, commit message bodies, or other human-readable text — following…

    2.4k GitHub stars~971 tokensUpdated today
    Auto-check passed
  • Rust Backend

    static-web-server/static-web-server

    Write or review Rust backend code for the Static Web Server (SWS) project — crates, modules, functions, types, error handling, and async code

    2.4k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Static File Serving

    static-web-server/static-web-server

    Serve static files and web assets with optimal headers, MIME types, compression, and caching for the Static Web Server (SWS) project

    2.4k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Security

What does Security do?

Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation. Security is an agent skill from static-web-server/static-web-server.

When should I use Security?

Security fits situations like: tasks that involve Secure coding.

How do I install Security in Claude Code?

Run `npx skills add static-web-server/static-web-server --skill security -a claude-code`. Or copy the skill folder (.agents/skills/security in static-web-server/static-web-server) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add static-web-server/static-web-server --skill security -a codex`. Or copy the skill folder (.agents/skills/security in static-web-server/static-web-server) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add static-web-server/static-web-server --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

Going by SKILL.md and its folder, Security needs the command-line tools its instructions call (cargo).

Does Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security use?

Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: Hadolint Dockerfile Security Linting (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Sigstore For Software Signing (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing File Integrity Monitoring With Aide (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Configuring Firewalls (ancoleman/ai-design-components, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

static-web-server (a GitHub organization) maintains it in static-web-server/static-web-server, which has 2,372 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: static-web-server/static-web-server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.