Application Security

Writing or reviewing code that handles untrusted input, secrets, outbound requests, rendered content, or third-party dependencies — the OWASP Top 10:2025 lens in two modes, writing secure-by-default code and judging the risk a change introduces. Triggers on "is this safe", "secure by default", "harden", "security", "secret", "privacy", "PII", "XSS", "injection", "SSRF", "safe fetch", "access control", or a dependency review. Covers secrets and environment variables, input validation, output encoding, SSRF, access control and data exposure, and supply-chain risk.

axross 8aaebb5 7 files · 42.5 KB Updated

File contents

axross/skills/tree/main/skills/application-security commit 8aaebb5ca7

Frequently asked questions

npx skillmds@latest add axross/application-security