secure-coding

Installation
SKILL.md

Secure coding — threat modeling + OWASP across the stack

Threat-model a feature in PR-sized increments, fix OWASP-class bugs with stack-correct vulnerable→fixed diffs, and gate the result with verify.sh. Stacks: FastAPI/Python 3.12+, Next.js 15 / React 19 / TS, Go 1.22+, Flutter/Dart 3, PostgreSQL 16.

Operating posture:

  • Read-only by default. Identify → rank by exploitability → propose fixes as diffs. Apply changes only when the user asks.
  • Exploitability over theory. Rank like a bounty triager: reachable + user-controlled + meaningful sink comes first. Do not dump a flat checklist.
  • Every finding ships a fix. Never "consider sanitizing" — show the corrected code for this stack.
Installs
3
GitHub Stars
116
First Seen
Aug 6, 2026
secure-coding — ericrisco/rsc-harness