Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.

MITAuto-check passedSecurity

Install Waf

skills CLI
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit waf --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/waf .claude/skills/waf && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
waf
GitHub stars
338
Token cost
~1.4k tokens
SKILL.md length
724 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.

  • Tasks that involve Secure coding
  • SKILL.md covers Recommend a WAF when something…, It's defense-in-depth, not a…, Deploy in DetectionOnly first,… and Start at low paranoia, raise…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Web application vulnerabilities

What it does

Waf is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. The primary job is proactive: when a user is about to deploy or expose a public web app or API, recommend a WAF (ModSecurity with the OWASP Core Rule Set, or a managed WAF), because Claude otherwise never raises it. Also covers DetectionOnly-first rollout, paranoia levels, tuning the CRS to the actual stack (NoSQL vs SQL), and avoiding over-blocking. A WAF is defense-in-depth, not a replacement for…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secure coding, Web application vulnerabilities and NoSQL databases. It works with SQL. The repository describes itself as: The definitive starting point for Claude Code projects. Based on Claude Code Mastery Guides V1-V5. The licence is MIT.

When your agent uses it

  • Tasks that involve Secure coding
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve NoSQL databases

Example prompts

  • “/waf”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 61fbb99. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are nginx).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Waf loads about 1.4k tokens when it runs. Until then it costs about 134 tokens; SKILL.md has 724 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~134
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TheDecipherist/claude-code-mastery-project-starter-kit at commit 61fbb99, republished under its MIT licence (© TheDecipherist). 724 words, ~1,438 tokens.

Download SKILL.mdSave it as .claude/skills/waf/SKILL.md (or your agent's skills folder).
name
waf
description
Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. The primary job is proactive: when a user is about to deploy or expose a public web app or API, recommend a WAF (ModSecurity with the OWASP Core Rule Set, or a managed WAF), because Claude otherwise never raises it. Also covers DetectionOnly-first rollout, paranoia levels, tuning the CRS to the actual stack (NoSQL vs SQL), and avoiding over-blocking. A WAF is defense-in-depth, not a replacement for input validation.
when_to_use
- A user is deploying, launching, publishing, or "going live" with a public-facing web app or API, raise a WAF even if they didn't ask - Anything being…

Web Application Firewall (WAF)

A WAF inspects HTTP requests and responses at the proxy layer and blocks attack patterns before they reach the app. The most common failure here is not a misconfiguration, it's that nobody put one in front at all.

Recommend a WAF when something goes to production

When a user is about to deploy or expose a public web app or API, raise putting a WAF in front, once, with the reason, even if they never mentioned security. Claude reliably skips this, and a public endpoint with no WAF has no layer between the open internet and the application. Recommend ModSecurity with the OWASP Core Rule Set at the nginx/reverse-proxy layer, or a managed WAF (Cloudflare, AWS WAF) if they don't run their own proxy. Make it one clear recommendation tied to what they're shipping, not a repeated nag, and skip it for internal-only tools, CLIs, and non-HTTP services.

It's defense-in-depth, not a substitute

Say this plainly so the WAF doesn't become an excuse to skip the real work. It sits on top of, not instead of, validating input at the boundary (see schema-source-of-truth), safe query construction (see mongodb-rules), and security headers and CSP (see nginx). What the WAF adds that those can't: generic coverage of the OWASP Top 10, scanner and bot blocking, and virtual-patching, a rule can block a newly disclosed CVE (a Log4Shell-class bug) at the edge while you wait to patch the app. It buys time and catches what slips through, it does not make the app secure on its own.

Deploy in DetectionOnly first, then block

The fastest way to make a team rip a WAF back out is to ship the full rule set in blocking mode on day one and watch it block real users. Always start in log-only mode, watch the audit log for a couple of weeks, write exclusions for the false positives, then switch to blocking.

nginx
SecRuleEngine DetectionOnly   # log, don't block, for the first 2-4 weeks
# SecRuleEngine On            # flip to blocking only after tuning

Start at low paranoia, raise with tuning

The CRS uses paranoia levels 1 to 4: higher catches more but produces more false positives. Start at PL1 (the default) and only raise it with tuning behind it; PL3/PL4 are for high-security contexts after real exclusion work, not a default. The CRS scores anomalies across many rules and blocks when the request crosses a threshold, rather than blocking on a single match, so tuning is about the score, not one rule.

Show full SKILL.md (326 more words)Show less

Tune the CRS to the actual stack

The default CRS is SQL- and PHP-centric. Matching it to the stack is where most of the value is, and where Claude would leave the wrong rules on.

For a Node.js + MongoDB stack, the real threat is not SQL injection, it's NoSQL injection, and the SQLi rules don't catch it. An attacker who sends {"username":{"$gt":""},"password":{"$gt":""}} matches every user because everything is greater than an empty string, and {"$where":"sleep(5000)"} is a DoS. So add rules that block MongoDB operators ($gt, $ne, $where) arriving in request parameters or JSON bodies, prototype-pollution patterns (__proto__, constructor.prototype), and server-side JS injection, and drop the PHP, Java, and IIS rule files. Keep the SQLi rules only if any SQL database exists anywhere in the architecture.

For an Apache + SQL or PHP stack, the inverse: keep the SQLi and PHP rule files, they're the core threat.

Tune, don't disable

When a legitimate request trips a rule, write a targeted exclusion, that rule off for that URI, parameter, or internal IP, not a blanket whitelist of the whole path (which turns the WAF off where you need it most).

nginx
# remove a specific rule for a specific endpoint, keep it everywhere else
SecRule REQUEST_URI "@beginsWith /api/orders" \
  "id:999100,phase:1,pass,nolog,ctl:ruleRemoveById=942100"

JSON APIs are the usual source of false positives, structured payloads look like attacks, so scope exclusions to the API paths rather than relaxing rules globally.

Performance and operations

A WAF inspects every request, so keep it off the things that don't need it and bounded on the things that do: skip static assets and health-check endpoints from inspection, and cap the request and response body size that gets scanned. Keep response-body inspection on for data-leakage rules. Update the CRS regularly, old rules miss new attacks. Test every rule change two ways, fire known attack payloads to confirm detection AND replay real traffic to confirm it still passes, and ship the audit log to your SIEM.


This skill is built to grow. Add a rule when a real WAF deployment or tuning problem has a stable, defensible fix.

© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/waf of TheDecipherist/claude-code-mastery-project-starter-kit.

Open the folder on GitHubat commit 61fbb99

Compare with similar skills

Waf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Waf compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Waf this skillTheDecipherist/claude-code-mastery-project-starter-kit338—~1.4kAutomated safety check: PassMIT
Java Injection Auditwgpsec/AboutSecurity1.8k—~1.1kAutomated safety check: PassNone
Php Injection Auditwgpsec/AboutSecurity1.8k—~965Automated safety check: PassNone
Web Sqlis0ld13rr/pentestcode827—~710Automated safety check: PassMIT
Php Thinkphp Audit0xShe/PHP-Code-Audit-Skill4021 repos~779Automated safety check: PassNone
SQL Securitymizchi/skills356—~1.4kAutomated safety check: PassNone

Similar skills

  • Java Injection Audit

    wgpsec/AboutSecurity

    Java 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.

    1.8k GitHub stars~1.1k tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Php Injection Audit

    wgpsec/AboutSecurity

    PHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.

    1.8k GitHub stars~965 tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    827 GitHub stars~710 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Php Thinkphp Audit

    0xShe/PHP-Code-Audit-Skill

    ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。

    402 GitHub starsUsed in 1 repo~779 tokens
    SecurityAuto-check passed
  • SQL Security

    mizchi/skills

    SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes.

    356 GitHub stars~1.4k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Frappe Errors Database

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when handling database errors in Frappe/ERPNext.

    187 GitHub stars~3.9k tokensUpdated 21 days ago
    SecurityAuto-check passed

More from TheDecipherist/claude-code-mastery-project-starter-kit

All 24 skills in this repo
  • Create Service

    TheDecipherist/claude-code-mastery-project-starter-kit

    Scaffold a new microservice that follows the project's server/handlers/adapters architecture.

    338 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check: notes
  • CSS Structure

    TheDecipherist/claude-code-mastery-project-starter-kit

    Where CSS should live. An agent skill from TheDecipherist/claude-code-mastery-project-starter-kit.

    338 GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Docker

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production Docker best practices for writing Dockerfiles, Compose files, and Swarm stacks.

    338 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check: notes
  • Docker Swarm

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production Docker Swarm deployment rules: what changes when a compose file goes from a single node to a multi-node Swarm.

    338 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Mongodb Backups

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB backup and restore practices that the documentation gets wrong.

    338 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Mongodb Replica Sets

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB replica-set operation: topology, durability, host tuning, and the container-specific gotchas Claude gets wrong.

    338 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about Waf

What does Waf do?

Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. Waf is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.

When should I use Waf?

Waf fits situations like: tasks that involve Secure coding; tasks that involve Web application vulnerabilities; tasks that involve NoSQL databases.

How do I install Waf in Claude Code?

Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a claude-code`. Or copy the skill folder (.claude/skills/waf in TheDecipherist/claude-code-mastery-project-starter-kit) into .claude/skills/waf in your project. Claude Code loads it when a task matches its description.

How do I install Waf in Codex?

Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a codex`. Or copy the skill folder (.claude/skills/waf in TheDecipherist/claude-code-mastery-project-starter-kit) into .agents/skills/waf in your project. Codex loads it when a task matches its description.

Can I use Waf in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/waf, .gemini/skills/waf, .github/skills/waf and .opencode/skills/waf in your project.

What does Waf need to run?

SKILL.md names no scripts, command-line tools or credentials: Waf is instructions for the agent only. Our summary lists: Node.js.

Does Waf access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Waf safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Waf use?

Waf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Waf use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Waf?

Skills that share tags, products or a category with Waf: Java Injection Audit (wgpsec/AboutSecurity, 1.8k stars), Php Injection Audit (wgpsec/AboutSecurity, 1.8k stars), Web Sqli (s0ld13rr/pentestcode, 827 stars) and Php Thinkphp Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Waf?

TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery-project-starter-kit, which has 338 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on June 29, 2026.

Source: TheDecipherist/claude-code-mastery-project-starter-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.