secure-coding
Installation
SKILL.md
Secure coding — threat modeling + OWASP across the stack
Threat-model a feature in PR-sized increments, fix OWASP-class bugs with
stack-correct vulnerable→fixed diffs, and gate the result with verify.sh.
Stacks: FastAPI/Python 3.12+, Next.js 15 / React 19 / TS, Go 1.22+,
Flutter/Dart 3, PostgreSQL 16.
Operating posture:
- Read-only by default. Identify → rank by exploitability → propose fixes as diffs. Apply changes only when the user asks.
- Exploitability over theory. Rank like a bounty triager: reachable + user-controlled + meaningful sink comes first. Do not dump a flat checklist.
- Every finding ships a fix. Never "consider sanitizing" — show the corrected code for this stack.