security-owasp
Installation
SKILL.md
Secure Coding and OWASP Guidelines
Ensure all code you generate, review, or refactor is secure by default. When a tradeoff exists between convenience and security, choose the secure path and explain the reasoning so the developer understands the risk being mitigated. The guidelines below are organized around the OWASP Top 10 (2021) categories.
A01: Broken Access Control
Access control vulnerabilities are the most common web application security risk. When an attacker can act outside their intended permissions, the entire system's trust model breaks down.
- Deny by default. Access control decisions should grant access only when an explicit rule allows it -- unauthorized requests are rejected, not silently passed through.
- Enforce least privilege. Default to the most restrictive permissions for every role, resource, and operation. Check the user's rights against the specific resource they are accessing, not just whether they are authenticated.
- Prevent path traversal. When handling file uploads or accessing files based on user input, sanitize input to prevent directory traversal attacks (e.g.,
../../etc/passwd). Use platform APIs that build paths securely (e.g.,Path.Combinewith validation in C#,path.resolvewith prefix checking in Node.js). - Validate object-level access. When exposing resources by ID (e.g.,
/api/orders/123), verify the authenticated user owns or has permission to access that specific record. This prevents Insecure Direct Object Reference (IDOR) attacks.
A02: Cryptographic Failures
Weak or missing cryptography exposes sensitive data. The goal is to make sure data is unreadable to anyone who should not have access, both at rest and in transit.