aif-security-checklist
Security audit checklist based on OWASP Top 10 and best practices. Covers authentication, injection, XSS, CSRF, secrets management, and more. Use when reviewing security, before deploy, asking "is this secure", "security check", "vulnerability".
Pinned to revision ca482af4e862, so it is the text this page describes rather than whatever the author pushed since.
Pre-approved tools experimental
Experimental field. Support varies between clients, so this list is what the author declared, not what your client will enforce.
- Read
- Glob
- Grep
- Write
- Edit
- Bash(npm audit)
- Bash(grep *)
Files
- skills/aif-security-checklist/SKILL.md
- skills/aif-security-checklist/references/AUTH-PATTERNS.md
- skills/aif-security-checklist/references/PROMPT-INJECTION.md
- skills/aif-security-checklist/references/RACE-CONDITIONS.md
- skills/aif-security-checklist/scripts/audit.sh
Every link opens the file at its source, pinned to the revision this page describes.