api
RESTful API design patterns and best practices. Use when creating endpoints, designing APIs, or implementing routes.
Security review skill: comprehensive security checklist and patterns. Use when adding authentication, handling user input, working with secrets, or creating API endpoints.
$ npx -y skills add xiaobei930/cc-best --skill security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Security review skill: comprehensive security checklist and patterns. Use when adding authentication, handling user input, working with secrets, or creating API endpoints.
name: security description: "Security review skill: comprehensive security checklist and patterns. Use when adding authentication, handling user input, working with secrets, or creating API endpoints." allowed-tools: Read, Write, Edit, Bash, Grep, Glob parent: quality
> 关联 Agent: `security-reviewer`(安全审查主力)、`code-reviewer`(代码审查中的安全维度)
本技能确保所有代码遵循安全最佳实践,识别潜在漏洞。
| 类别 | 核心规则 | 检查项 | | ------------ | ----------------------------------- | ------------------------------------------ | | **密钥管理** | 环境变量,不硬编码 | `.env.local` 在 .gitignore,Git 历史无密钥 | | **输入验证** | Schema 验证(zod/pydantic),白名单 | 文件上传限制(大小/类型/扩展名) | | **SQL 注入** | 参数化查询,不拼接 SQL | ORM 正确使用 | | **认证授权** | httpOnly cookies,RBAC | Token 不放 localStorage | | **XSS** | DOMPurify 净化,CSP 头 | 无未验证的动态渲染 | | **CSRF** | CSRF Token,SameSite=Strict | 状态变更操作有保护 | | **速率限制** | 所有 API 有限制 | 昂贵操作更严格 | | **敏感数据** | 日志脱敏,通用错误消息 | 堆栈跟踪不暴露 | | **依赖** | npm audit clean,Lock 已提交 | 启用 Dependabot | | **命令注入** | execFile 非 exec,shell=False | 不拼接用户输入 | | **路径遍历** | os.path.basename 过滤 | 不直接拼接路径 |
| 文件 | 内容 | | -------------------------------------------- | ----------------------------------- | | [owasp-patterns.md](./owasp-patterns.md) | OWASP Top 10 详细防护模式和代码示例 | | [verify-checklist.md](./verify-checklist.md) | 安全测试示例 + 部署前安全检查清单 | | [cloud-security.md](./cloud-security.md) | IAM、密钥管理、CI/CD、网络安全 | | [config-audit.md](./config-audit.md) | 配置审计清单 |
---
> **记住**:安全不是可选项。一个漏洞可能危及整个平台。有疑问时,选择更安全的方案。
Role-Driven Development Workflow for Claude Code Transform Claude into a complete development team. From product requirements to code review — one plugin, full workflow. Quick Start • Features • Workflow • Commands • FAQ
Repo: xiaobei930/cc-best
RESTful API design patterns and best practices. Use when creating endpoints, designing APIs, or implementing routes.
Architecture design skill: ADR records, system design checklists, scalability assessment, architecture patterns. Use for complex system design and architecture…
Backend development patterns for services, error handling, logging, caching. Use when building backend services, APIs, or microservices.
Strategic compaction skill: suggests context compression at logical breakpoints. Use to suggest compaction at logical intervals during development sessions.
Database design, query optimization, migrations, and indexing. Use when designing schemas, writing queries, or managing migrations.
Systematic debugging methods, log analysis, and performance diagnostics. Use when debugging issues, analyzing errors, or troubleshooting incidents.