安全加固

原名:security-and-hardening

强化代码安全性,防范漏洞。处理用户输入、认证、数据存储或外部集成时使用。适用于任何接受不可信数据、管理用户会话或对接第三方服务的功能。

分类
开发提效
版本
v1.0.0
作者
胡轩(@userdittm6)
下载
2
收藏
0
发布
2026-08-08
更新
2026-08-14
TRACE 评分
4.2 / 5

内容概览

Security-first development practices for web applications. Treat every external input as hostile, every secret as sacred, and every authorization check as mandatory. Security isn't a phase — it's a constraint on every line of code that touches user data, authentication, or external systems. - Building anything that accepts user input - Implementing authentication or authorization - Storing or transmitting sensitive data - Integrating with external APIs or services - Adding file uploads, webhooks, or callbacks - Handling payment or PII data Controls bolted on without a threat model are guesses. Before hardening, spend five minutes thinking like an attacker: 1. Map the trust boundaries. Where does untrusted data cross into your system? HTTP requests, form fields, file uploads, webhooks, third-party APIs, message queues, and LLM output . Every boundary is attack surface. 2. Name the assets.…

查看 SKILL 详情