auto-security
Installation
SKILL.md
Security — What Claude Gets Wrong
These are patterns Claude knows but inconsistently applies. This skill exists to enforce them every time.
Sessions: Hash Tokens Before Storage
Claude often stores raw session tokens in the database. If the DB leaks, every session is compromised.
ALWAYS: Store SHA-256(token) in DB, send raw token in cookie
NEVER: Store raw token in DB
import { createHash, randomBytes } from 'node:crypto';
function generateToken(): string {
return randomBytes(32).toString('base64url');
}