Security Best Practices

👤 ivangdavila 📦 v1.0.0 ⭐ 4.4 ⬇️ 2.6K 下載
💻 開發程式設計 免費

📖 技能介紹


name: Security Best Practices slug: security-best-practices version: 1.0.0 homepage: https://clawic.com/skills/security-best-practices description: Review code with secure-by-default standards, prioritize exploitable risks, and deliver minimal-diff fixes with evidence and regression checks. changelog: Added a complete security review workflow with evidence standards, severity modeling, and minimal-risk remediation guidance. metadata: {"clawdbot":{"emoji":"🛡️","requires":{"bins":[],"config":["~/security-best-practices/"]},"os":["linux","darwin","win32"]}}


Setup

On first use, read setup.md for integration guidelines. If local memory is needed, ask for consent before creating ~/security-best-practices/.

When to Use

Use this skill for secure-by-default implementation, targeted vulnerability reviews, and prioritized security reports with actionable fixes. Activate when the user requests security guidance, hardening, risk triage, or remediation planning.

Architecture

Memory lives in ~/security-best-practices/. See memory-template.md for setup.

~/security-best-practices/
|- memory.md        # Stable context, preferences, and activation boundaries
|- findings-log.md  # Findings registry with severity and status
`- exceptions.md    # Approved security exceptions and review dates

Quick Reference

Load only the minimum file needed for the current request.

Topic File
Setup process setup.md
Memory template memory-template.md
Full review workflow review-playbook.md
Severity model and scoring severity-model.md
Safe remediation patterns remediation-patterns.md
Risk exception log exceptions.md

Core Rules

1. Establish Scope and Evidence First

Before any conclusions, confirm: - System boundary (service, module, endpoint, or workflow) - Stack evidence (language, framework, deployment context) - Threat assumptions (external attacker, internal misuse, privilege level)

No evidence, no finding.

2. Map Risks to a Repeatable Baseline

Evaluate every review against a consistent baseline: - Authn/authz boundaries - Input validation and output encoding - Secrets handling and configuration safety - Dependency and supply chain posture - Logging, error handling, and data exposure controls

Use review-playbook.md to keep scans systematic instead of ad hoc.

3. Produce Findings That Are Verifiable

Each finding must include: - Severity from severity-model.md - File path and line references - Concrete evidence snippet - Impact statement in plain language - Minimal safe fix direction

Avoid speculative findings without repository evidence.

4. Prioritize Exploitability Over Theory

Rank by practical risk, not by checklist volume: - Reachability from untrusted inputs - Privilege required by attacker - Blast radius if exploited - Ease of abuse and repeatability

High confidence, exploitable issues come first.

5. Remediate With Minimal Product Risk

Fix one finding at a time: - Prefer small diffs that preserve existing behavior - Add tests when security fixes alter code paths - Flag expected behavior changes before implementing - Re-run project validation after each fix batch

Use remediation-patterns.md for safe rollouts.

6. Respect Explicit Exceptions and Ownership

If the user accepts a known risk: - Record rationale in exceptions.md - Define expiry or next review date - Keep the exception scoped to the specific context

Never apply broad silent overrides.

Security Review Traps

  • Reporting generic best practices without file evidence -> low-trust output that teams cannot action.
  • Flooding with low-severity noise -> critical vulnerabilities get ignored.
  • Proposing major refactors as "quick fixes" -> teams reject security work due to delivery risk.
  • Ignoring framework defaults and deployment context -> false positives and wrong remediations.
  • Declaring a system "secure" after one pass -> hidden regressions remain untested.

Security & Privacy

Data that leaves your machine: - None by default from this skill itself.

Data that stays local: - Review preferences and finding history in ~/security-best-practices/. - Exception rationale in local memory files only.

This skill does NOT: - Exfiltrate source code to undeclared third-party endpoints. - Mark unresolved risks as fixed. - Perform hidden destructive changes.

Install with clawhub install <slug> if user confirms: - auth - Authentication design and hardening. - authorization - Access control and permission boundaries. - encryption - Key management and cryptographic hygiene. - firewall - Network exposure review and policy controls. - devops - Secure delivery, CI checks, and operational safeguards.

Feedback

  • If useful: clawhub star security-best-practices

    來源於7w4.net。

  • Stay updated: clawhub sync

🤖 AI 評測

這個Skill質量中上,文件結構清晰完整,提供了從風險評估到修復的完整工作流。它的嚴重程度分級和修復策略設計合理,能幫助開發者優先處理關鍵問題。不足之處是缺乏具體的漏洞檢測示例,作為安全審查工具的實際指導性偏弱,部分文件內容有重複。如果你需要系統的安全審查方法論,這個工具值得一試;但如果期望開箱即用的檢測能力,可能會感到失望。

📊 多維度評分

適應性4.3
規範性4.4
有效性4.4
可靠性4.5
可信度4.3

📁 包含檔案 (8 個)

📄 SKILL.md 4.8 KB
📄 _meta.json 142 B
📄 exceptions.md 1.1 KB
📄 memory-template.md 1.6 KB
📄 remediation-patterns.md 1.6 KB
📄 review-playbook.md 1.4 KB
📄 setup.md 1.8 KB
📄 severity-model.md 1.3 KB