From nickcrew-claude-ctx-plugin
Guides secure coding practices and defensive patterns for authentication, user input handling, sensitive data management, cryptographic operations, and code reviews.
npx claudepluginhub nickcrew/claude-cortexThis skill uses the workspace's default tool permissions.
Comprehensive guidance for implementing security-first development patterns with defensive programming techniques and proactive threat mitigation strategies.
Reviews code for OWASP Top 10 vulnerabilities, input validation, auth flows, security headers, CSRF/XSS prevention, and dependency audits.
Provides OWASP Top 10 guidelines, secure Python/Flask coding patterns, prevention strategies, and remediation for access control and cryptographic vulnerabilities.
Delivers OWASP Top 10 security guidance and secure coding patterns to prevent injections, XSS, CSRF, auth flaws, encryption issues. Supports secure code creation, diagnosis, review via reference files.
Share bugs, ideas, or general feedback.
Comprehensive guidance for implementing security-first development patterns with defensive programming techniques and proactive threat mitigation strategies.
Apply multiple layers of security controls - never rely on a single protection mechanism.
When errors occur, default to the secure state (deny access, reject input, log event).
Grant minimum necessary permissions - users, services, and databases should have only required access.
Validate all input, encode all output, verify all sources, authenticate all requests.
| Task | Load reference |
|---|---|
| Input validation & sanitization | skills/secure-coding-practices/references/input-validation.md |
| Output encoding & XSS prevention | skills/secure-coding-practices/references/output-encoding.md |
| Authentication & sessions | skills/secure-coding-practices/references/authentication.md |
| Cryptography & key management | skills/secure-coding-practices/references/cryptography.md |
| Dependencies & supply chain | skills/secure-coding-practices/references/dependencies.md |
| Error handling & logging | skills/secure-coding-practices/references/error-handling.md |
| Secure defaults & configuration | skills/secure-coding-practices/references/secure-defaults.md |
Input Validation:
Output Encoding:
Authentication & Authorization:
Cryptography:
Dependencies:
Error Handling & Logging:
Watch for these patterns in code reviews:
OWASP Resources:
Standards & Guidelines:
Tools: