security-lite
giuseppenesca87-png/claude-code-house-rules/skills/security-lite/SKILL.md
Use automatically when the user works on auth, payments, API keys, environment variables, Supabase RLS, permissions, user data, uploads, public endpoints, webhooks, admin panels, dependencies, production config, or asks whether something is secure enough.
Skill0 starsChanged 15 days ago
- Reads credentials
--- name: security-lite description: Use automatically when the user works on auth, payments, API keys, environment variables, Supabase RLS, permissions, user data, uploads, public endpoints, webhooks, admin panels, dependencies, production config, or asks whether something is secure enough. --- # Security Lite Use for pragmatic security review. Do not over-engineer, but do not ignore obvious risks. ## Check - API keys exposed client-side - Secrets committed to repo - `.env` handling - Auth bypass - Missing authorization checks - Admin-only routes - Supabase RLS/policies - File uploads - Webhooks - Rate limits - CORS - Input validation - SQL injection risks - XSS risks - Dependency vulnerabilities - Logging sensitive data - Production debug flags - Public storage buckets - Overbroad tokens or OAuth scopes ## Rules - Stop before destructive security changes. - Prefer least privilege. - Do not store secrets in repository files. - Flag urgent issues clearly. - Give practical fixes first. - Separate theoretical risks from real exploitable risks. ## Output format 1. Security verdict 2. Critical issues 3. High-value fixes 4. Medium/low issues 5. What is probably fine 6. Exact files/areas to inspect 7. Verification steps
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

