# Security

> Application security best practices including OWASP Top 10, authentication, and data protection.

- Skill: `diegosouzapw/security-2` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add diegosouzapw/security-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/diegosouzapw/security-2/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: diegosouzapw (https://skillmd.com/u/diegosouzapw)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/diegosouzapw/security-2

---


# Application Security Best Practices

## Input Validation
- Validate all user input
- Use allowlisting over blocklisting
- Sanitize HTML to prevent XSS
- Use parameterized queries for SQL
- Validate file uploads (type, size)

## Authentication
- Use strong password hashing (bcrypt, argon2)
- Implement MFA where possible
- Use secure session management
- Implement rate limiting on auth endpoints
- Use JWTs properly (short expiry, refresh tokens)

## Authorization
- Implement least privilege
- Check authorization on every request
- Use role-based access control
- Implement row-level security
- Audit access to sensitive data

## Data Protection
- Encrypt sensitive data at rest
- Use TLS for data in transit
- Don't log sensitive data
- Implement proper key management
- Use secure cookie flags

## Common Vulnerabilities (OWASP Top 10)
- Injection: Use prepared statements
- Broken Auth: Secure session handling
- XSS: Sanitize output, use CSP
- CSRF: Use anti-CSRF tokens
- Security Misconfiguration: Review defaults
- Sensitive Data Exposure: Encrypt everything
- Broken Access Control: Check on server
- SSRF: Validate URLs, use allowlists

## Dependencies
- Keep dependencies updated
- Use npm audit/pip audit
- Pin dependency versions
- Use lockfiles
- Monitor for vulnerabilities

