Skip to content
Development
Skill

/ios-security

Secure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.

From plugin
agent-skills-standard
538200 skills1 MCP
Install
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill ios-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/ios-security

Context preview

The summary Claude sees to decide when to auto-load this skill.

Secure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.

SKILL.md

ios-security.SKILL.md
name: ios-security
description: Secure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.
metadata:
  triggers:
    files:
    - '**/*.swift'
    keywords:
    - SecItemAdd
    - kSecClassGenericPassword
    - LAContext
    - LocalAuthentication
    - ios security
    - swift security
    - biometric
    - face id
    - touch id
    - certificate pinning
    - app transport security

iOS Security

**Priority: P0 (CRITICAL)**

Implementation Workflow

1. **Store secrets in secure storage** — Use `SecItemAdd`, `SecItemUpdate`, and `SecItemDelete` with `kSecClassGenericPassword` for tokens/PII. Never use `UserDefaults`. 2. **Add biometric auth** — Use `LocalAuthentication` with `LAContext`. Verify availability with `canEvaluatePolicy` before prompting. 3. **Encrypt files** — Use `Data.WritingOptions.completeFileProtection` when saving to disk. 4. **Keep ATS enabled** — Never disable App Transport Security globally in the iOS Info configuration. 5. **Pin certificates** — Use `ServerTrustManager` or `TrustKit` for production apps to prevent MITM attacks. 6. **Strip sensitive logs** — Ensure PII and tokens removed from logs in Release builds.

See [Secure storage and biometrics implementation examples](references/implementation.md)

Anti-Patterns

  • **No Secrets in `UserDefaults`**: Always use secure storage for tokens and PII
  • **No Unhandled `LAError`**: Check for `userCancel` and `authenticationFailed` in biometric flows
  • **No PII/Token Logging**: Strip sensitive data from all logs in Release builds

References

  • [Secure Storage & Biometrics Implementation](references/implementation.md)

Related Topics

  • common/security-standards
  • architecture

Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:

  • Info.plist,info
  • LocalAuthentication
Read more
Ships withagent-skills-standard

The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.

Get the whole plugin

Other skills on agent-skills-standard.