Security Standards
Priority: P0 (CRITICAL)
Always-Apply Rules
Apply these on every code write, regardless of context:
- No hardcoded secrets: Use environment variables or secret managers. Never commit keys, passwords, or tokens to source control.
- No raw SQL strings: Use parameterized queries or ORMs —
WHERE id = ${userId} always wrong.
- No stacktraces in prod: Return generic error codes; log full detail server-side only.
Workflow
Activate when: implementing auth, encryption, authorization, input handling, or any security-sensitive feature.
- Identify trust boundaries — map every data entry point (API, UI, CSV, webhook).
- Validate and sanitize all external input at each boundary.
- Apply least privilege to users, services, and containers.
- Verify with SAST/DAST scanners in CI before merge.
Context-Specific Rules
Data Safeguarding
- Zero Trust: Never trust external input. Sanitize and validate every data boundary.
- Least Privilege: Grant minimum necessary permissions to users, services, and containers.
- Encryption: AES-256 for data-at-rest; TLS 1.3 for data-in-transit.
- PII Logging: Never log PII (email, phone, names). Mask sensitive fields before logging.
See implementation examples for parameterized queries and secret management.
Secure Coding
- Injection Prevention: Use parameterized queries or ORMs to stop SQL, Command, and XSS injections.
- Dependency Management: Regularly scan (
npm audit, pip audit) and update third-party libraries to patch CVEs.
- Secure Auth: Implement Multi-Factor Authentication (MFA) and secure session management.
- Error Privacy: Never leak stack traces or internal implementation details to end-user.
Continuous Security
- Shift Left: Integrate security scanners (SAST/DAST) early in CI/CD pipeline.
- Data Minimization: Collect and store only minimum data required for business logic.
- Audit Logging: Maintain logs for sensitive operations (Auth, Deletion, Admin changes).
Anti-Patterns
- No default passwords: Force rotation on first use with strong entropy requirements.
References
- Injection Testing Protocols (SQLi/HTMLi)
- Vulnerability Remediation & Secure Patterns
Remediation anchors
- Remediation anchors: Argon2id, parameterized queries or ORM, rate limiting, HttpOnly Secure cookies
1---2name: common-security-standards3description: Enforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.4---5# Security Standards
6
7## **Priority: P0 (CRITICAL)**
8
9## Always-Apply Rules
10
11Apply these on **every code write**, regardless of context:
12
13- **No hardcoded secrets**: Use environment variables or secret managers. Never commit keys, passwords, or tokens to source control.
14- **No raw SQL strings**: Use parameterized queries or ORMs — `WHERE id = ${userId}` always wrong.
15- **No stacktraces in prod**: Return generic error codes; log full detail server-side only.
16
17## Workflow
18
19Activate when: implementing auth, encryption, authorization, input handling, or any security-sensitive feature.
20
211. **Identify trust boundaries** — map every data entry point (API, UI, CSV, webhook).
222. **Validate and sanitize** all external input at each boundary.
233. **Apply least privilege** to users, services, and containers.
244. **Verify** with SAST/DAST scanners in CI before merge.
25
26## Context-Specific Rules
27
28### Data Safeguarding
29
30- **Zero Trust**: Never trust external input. Sanitize and validate every data boundary.
31- **Least Privilege**: Grant minimum necessary permissions to users, services, and containers.
32- **Encryption**: AES-256 for data-at-rest; TLS 1.3 for data-in-transit.
33- **PII Logging**: Never log PII (email, phone, names). Mask sensitive fields before logging.
34
35See [implementation examples](references/implementation.md) for parameterized queries and secret management.
36
37### Secure Coding
38
39- **Injection Prevention**: Use parameterized queries or ORMs to stop SQL, Command, and XSS injections.
40- **Dependency Management**: Regularly scan (`npm audit`, `pip audit`) and update third-party libraries to patch CVEs.
41- **Secure Auth**: Implement Multi-Factor Authentication (MFA) and secure session management.
42- **Error Privacy**: Never leak stack traces or internal implementation details to end-user.
43
44### Continuous Security
45
46- **Shift Left**: Integrate security scanners (SAST/DAST) early in CI/CD pipeline.
47- **Data Minimization**: Collect and store only minimum data required for business logic.
48- **Audit Logging**: Maintain logs for sensitive operations (Auth, Deletion, Admin changes).
49
50## Anti-Patterns
51
52- **No default passwords**: Force rotation on first use with strong entropy requirements.
53
54## References
55
56- [Injection Testing Protocols (SQLi/HTMLi)](references/INJECTION_TESTING.md)
57- [Vulnerability Remediation & Secure Patterns](references/VULNERABILITY_REMEDIATION.md)
58
59## Remediation anchors
60
61- Remediation anchors: Argon2id, parameterized queries or ORM, rate limiting, HttpOnly Secure cookies