skills/ HoangNguyen0403/agent-skills-standard

common-owasp

OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). Use when performing any security review, PR review, or codebase audit touching web, mobile, or API code.

0
Installs
—
Rating
—
Success rate
5
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

5 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 0191f5afcb040c23… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

OWASP Top 10 Security Checklist

Priority: P0 (CRITICAL)

Always-Apply Rules

Apply these on every code write, not during dedicated security reviews:

  • No IDOR: Filter every resource query by owner_id or tenantId alongside any user-supplied ID. findById(params.id) without owner filter immediate P0.
  • No wildcard CORS: Restrict to explicit allowlisted origins — never Access-Control-Allow-Origin: * on authenticated routes.
  • No full entity return: Always project to DTO — never serialize raw ORM output to API response.
  • No plaintext secrets in mobile: Never store tokens in SharedPreferences/UserDefaults — use Keychain/Keystore.

Context-Specific Checklist

Activate when: writing security-sensitive features, reviewing PRs, or doing codebase audits.

Mark each item: ✅ not affected | ⚠️ needs review | 🔴 confirmed finding.

P0 finding caps Security score at 40/100.

Apply framework-specific security skills alongside this checklist. See references/owasp-web.md, references/owasp-api.md, and references/owasp-mobile.md for full detection signals.

OWASP Web Application Top 10 (2021)

IDRiskKey Detection Signal
A01Broken Access ControlfindById(params.id) without owner filter. Route without @authorize.
A02Cryptographic FailuresWeak hash (MD5/SHA1) for passwords. HTTP URL hardcoded. No TLS.
A03InjectionString concat in DB queries. Unsanitized input to templates. XSS.
A04Insecure DesignNo rate limiting on auth. Missing input validation at entry points.
A05Security MisconfigurationCORS *. Debug mode in prod. Missing security headers (CSP, HSTS).
A06Vulnerable ComponentsCVE in dependency audit. Unreviewed new direct dependency.
A07Auth FailuresJWT without expiry. No session invalidation on logout.
A08Data Integrity FailuresUnverified JWT/cookie. Deserialization of untrusted input.
A09Logging & MonitoringNo audit log on: deletion, password change, privilege escalation.
A10SSRFHTTP client with user-controlled URL and no allowlist.

OWASP API Security Top 10 (2023)

IDRiskKey Detection Signal
API1Broken Object Level Auth (BOLA)Resource by user-supplied ID without AND owner_id = currentUser.
API2Broken AuthenticationJWT missing exp. Token not revoked on logout. Bearer in URL.
API3Broken Property Level AuthFull ORM entity returned. No DTO projection. Mass assignment.
API4Unrestricted Resource ConsumptionNo server-enforced limit/pageSize. No throttle on heavy ops.
API5Broken Function Level AuthAdmin route reachable without role guard.
API6Unrestricted Business FlowNo verification on OTP/checkout/password-reset flows.
API8Security MisconfigurationStack trace in response. CORS * on authenticated routes.
API9Improper Inventory ManagementDeprecated/undocumented endpoints still reachable.
API10Unsafe API ConsumptionThird-party response used without schema validation.

OWASP Mobile Top 10 (2024)

IDRiskKey Detection Signal
M1Improper Credential UsageAPI keys in BuildConfig, Info.plist, hardcoded in source.
M2Inadequate Supply ChainUnverified SDKs, pods, or packages without lock files.
M3Insecure Auth/AuthZBiometric-only auth without server validation. Local role checks.
M4Insufficient I/O ValidationWebView loadUrl with user data. Intent data used unvalidated.
M5Insecure CommunicationNo cert pinning. cleartextTrafficPermitted=true. ATS exceptions.
M6Inadequate PrivacyLocation/contacts without justification. PII in analytics.
M7Insufficient Binary ProtectionNo obfuscation. android:debuggable=true. No root detection.
M8Security MisconfigurationExported components. Backup enabled. Debug endpoints.
M9Insecure Data StorageTokens in SharedPreferences/UserDefaults vs Keychain/Keystore.
M10Insufficient CryptographyHardcoded encryption keys. Deprecated algorithms (DES, RC4).

References

Canonical response anchors

  • Additional task-grounded exact anchors: rate limit, IDOR/BOLA, DTO projection

Remediation anchors

  • Remediation anchors: DTO projection, CORS, opaque session, JWT expiry, rate limiting

Files

5
19.4 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from HoangNguyen0403/agent-skills-standard8

android-agp-upgrade

Upgrade an Android project to Android Gradle Plugin (AGP) 9. Use when migrating to AGP 9, updating Gradle build files, migrating to built-in Kotlin, or adopting the new AGP DSL.

Scan passed 0
android-architecture

Apply Clean Architecture layering, modularization, and Unidirectional Data Flow in Android projects. Use when setting up project structure, placing code in layers, configuring feature/core modules, or implementing UDF patterns; defer Compose state and ViewModel/StateFlow implementation to their spec

Scan passed 0
android-background-work

Implement WorkManager and background processing correctly on Android. Use when creating Worker classes, scheduling tasks, choosing between WorkManager and Foreground Services, or setting up Hilt in workers; defer FCM and notification delivery to android-notifications.

Scan passed 0
android-compose

Build high-performance declarative UI with Jetpack Compose. Use when writing Composable functions, optimizing recomposition, hoisting state, or working with LazyColumn and side effects; defer deep-link and navigation routing to android-navigation.

Scan passed 0
android-compose-migration

Migrate an Android XML View to Jetpack Compose following a structured 10-step workflow. Use when converting XML layouts to Compose, setting up Compose in an existing View-based project, or incrementally adopting Compose.

Scan passed 0
android-concurrency

Write correct coroutine scopes, lifecycle collection, and dispatcher injection in Android production code. Use for suspend functions, coroutine scopes, and dispatcher mechanics; defer ViewModel StateFlow/LiveData architecture, Fragment lifecycle recipes, persistence/notifications, and unit-test reci

Scan passed 0
android-deployment

Configure release signing, R8 obfuscation, and App Bundle publishing for Android. Use when setting up signing configs, enabling minification, adding ProGuard keep rules, or preparing for Play Store submission.

Scan passed 0
android-design-system

Enforce Material Design 3 theming and design token usage in Jetpack Compose. Use when implementing M3 components, color schemes, typography, or design tokens.

Scan passed 0

Related security skillsscan passed

security-review

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for

Scan passed 1
security-threat-model

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppS

Scan passed 1
security-bounty-hunter

Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings. Use when hunting reportable, remotely reachable vulnerabilities in a repository.

Scan passed 0
cso

Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)

Scan passed 0
claude-security

Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use

Scan passed 0
auth

Implement JWT/cookie authentication and authorization in tRPC using createContext for user extraction, t.middleware with opts.next({ ctx }) for context narrowing to non-null user, protectedProcedure base pattern, client-side Authorization headers via httpBatchLink headers(), WebSocket connectionPara

Scan passed 0