common-architecture-di…
Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes. Use when producing a system context,…
OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). Use when performing any security review, PR review, or codebase audit touching web, mobile, or API code.
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill common-owasp --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/common-owaspContext preview
The summary Claude sees to decide when to auto-load this skill.
OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). Use when performing any security review, PR review, or codebase audit touching web, mobile, or API code.
name: common-owasp
description: OWASP Top 10 audit checklists for Web Applications (2021), APIs (2023), and Mobile (2024). Use when performing any security review, PR review, or codebase audit touching web, mobile, or API code.
metadata:
triggers:
keywords:
- security review
- OWASP
- broken access control
- IDOR
- BOLA
- injection
- broken auth
- API review
- authorization
- access control
- mobile securityApply these on **every code write**, not during dedicated security reviews:
Activate when: writing security-sensitive features, reviewing PRs, or doing codebase audits.
Mark each item: ✅ not affected | ⚠️ needs review | 🔴 confirmed finding.
**P0 finding caps Security score at 40/100.**
Apply framework-specific security skills alongside this checklist. See [references/owasp-web.md](references/owasp-web.md), [references/owasp-api.md](references/owasp-api.md), and [references/owasp-mobile.md](references/owasp-mobile.md) for full detection signals.
| ID | Risk | Key Detection Signal | | --- | ---- | -------------------- | | A01 | Broken Access Control | `findById(params.id)` without owner filter. Route without `@authorize`. | | A02 | Cryptographic Failures | Weak hash (MD5/SHA1) for passwords. HTTP URL hardcoded. No TLS. | | A03 | Injection | String concat in DB queries. Unsanitized input to templates. XSS. | | A04 | Insecure Design | No rate limiting on auth. Missing input validation at entry points. | | A05 | Security Misconfiguration | CORS `*`. Debug mode in prod. Missing security headers (CSP, HSTS). | | A06 | Vulnerable Components | CVE in dependency audit. Unreviewed new direct dependency. | | A07 | Auth Failures | JWT without expiry. No session invalidation on logout. | | A08 | Data Integrity Failures | Unverified JWT/cookie. Deserialization of untrusted input. | | A09 | Logging & Monitoring | No audit log on: deletion, password change, privilege escalation. | | A10 | SSRF | HTTP client with user-controlled URL and no allowlist. |
| ID | Risk | Key Detection Signal | | ----- | ---- | -------------------- | | API1 | Broken Object Level Auth (BOLA) | Resource by user-supplied ID without `AND owner_id = currentUser`. | | API2 | Broken Authentication | JWT missing `exp`. Token not revoked on logout. Bearer in URL. | | API3 | Broken Property Level Auth | Full ORM entity returned. No DTO projection. Mass assignment. | | API4 | Unrestricted Resource Consumption | No server-enforced `limit`/`pageSize`. No throttle on heavy ops. | | API5 | Broken Function Level Auth | Admin route reachable without role guard. | | API6 | Unrestricted Business Flow | No verification on OTP/checkout/password-reset flows. | | API8 | Security Misconfiguration | Stack trace in response. CORS `*` on authenticated routes. | | API9 | Improper Inventory Management | Deprecated/undocumented endpoints still reachable. | | API10 | Unsafe API Consumption | Third-party response used without schema validation. |
| ID | Risk | Key Detection Signal | | --- | ---- | -------------------- | | M1 | Improper Credential Usage | API keys in `BuildConfig`, `Info.plist`, hardcoded in source. | | M2 | Inadequate Supply Chain | Unverified SDKs, pods, or packages without lock files. | | M3 | Insecure Auth/AuthZ | Biometric-only auth without server validation. Local role checks. | | M4 | Insufficient I/O Validation | WebView `loadUrl` with user data. Intent data used unvalidated. | | M5 | Insecure Communication | No cert pinning. `cleartextTrafficPermitted=true`. ATS exceptions. | | M6 | Inadequate Privacy | Location/contacts without justification. PII in analytics. | | M7 | Insufficient Binary Protection | No obfuscation. `android:debuggable=true`. No root detection. | | M8 | Security Misconfiguration | Exported components. Backup enabled. Debug endpoints. | | M9 | Insecure Data Storage | Tokens in `SharedPreferences`/`UserDefaults` vs Keychain/Keystore. | | M10 | Insufficient Cryptography | Hardcoded encryption keys. Deprecated algorithms (DES, RC4). |
The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.
Repo: hoangnguyen0403/agent-skills-standard
Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes. Use when producing a system context,…
Enforce SOLID principles, guard-clause style, function size limits, and intention-revealing naming across all languages. Use when refactoring for readability,…
Standardize BRD and BRD-lite discovery for business goals, stakeholder impact, current-to-future state, and measurable value outcomes. Use when creating BRD,…
Conduct high-quality, persona-driven code reviews. Use when reviewing PRs, critiquing code quality, or analyzing changes for team feedback.
Maximize context window efficiency, reduce latency, and prevent lost-in-middle issues through strategic masking and compaction. Use when token budgets are…
Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser…