mcpbeat

Common Security Standards

hoangnguyen0403/agent-skills-standard-common-common-security-standards

Enforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.

This is a copy. The original lives at hoangnguyen0403/common-security-standards.

2k tokens
context cost
the whole folder, loaded on every use
5
files
instructions only
0
copies elsewhere
how many repositories repackaged it
536
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/HoangNguyen0403/agent-skills-standard --skill common-security-standards

What comes with it

5 237 bytes besides the instruction
evals/evals.json
references/INJECTION_TESTING.md
references/VULNERABILITY_REMEDIATION.md
references/implementation.md

The instruction itself

11 sections, as written by the author

Security Standards

Priority: P0 (CRITICAL)

Always-Apply Rules

Apply these on every code write, regardless of context:

  • No hardcoded secrets: Use environment variables or secret managers. Never commit keys, passwords, or tokens to source control.
  • No raw SQL strings: Use parameterized queries or ORMs — WHERE id = ${userId} always wrong.
  • No stacktraces in prod: Return generic error codes; log full detail server-side only.

Workflow

Activate when: implementing auth, encryption, authorization, input handling, or any security-sensitive feature.

  • Identify trust boundaries — map every data entry point (API, UI, CSV, webhook).
  • Validate and sanitize all external input at each boundary.
  • Apply least privilege to users, services, and containers.
  • Verify with SAST/DAST scanners in CI before merge.

Context-Specific Rules

Data Safeguarding

  • Zero Trust: Never trust external input. Sanitize and validate every data boundary.
  • Least Privilege: Grant minimum necessary permissions to users, services, and containers.
  • Encryption: AES-256 for data-at-rest; TLS 1.3 for data-in-transit.
  • PII Logging: Never log PII (email, phone, names). Mask sensitive fields before logging.

See implementation examples for parameterized queries and secret management.

Secure Coding

  • Injection Prevention: Use parameterized queries or ORMs to stop SQL, Command, and XSS injections.
  • Dependency Management: Regularly scan (npm audit, pip audit) and update third-party libraries to patch CVEs.
  • Secure Auth: Implement Multi-Factor Authentication (MFA) and secure session management.
  • Error Privacy: Never leak stack traces or internal implementation details to end-user.

Continuous Security

  • Shift Left: Integrate security scanners (SAST/DAST) early in CI/CD pipeline.
  • Data Minimization: Collect and store only minimum data required for business logic.
  • Audit Logging: Maintain logs for sensitive operations (Auth, Deletion, Admin changes).

Anti-Patterns

  • No default passwords: Force rotation on first use with strong entropy requirements.

References

  • Injection Testing Protocols (SQLi/HTMLi)
  • Vulnerability Remediation & Secure Patterns

Remediation anchors

  • Remediation anchors: Argon2id, parameterized queries or ORM, rate limiting, HttpOnly Secure cookies

How to use it

Copy the folder

Take hoangnguyen0403/agent-skills-standard-common-common-security-standards from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.