Home / security-basics
Security Basics
Six lightweight security skills for everyday development: secrets hygiene scan, npm audit and pip-audit reader, HTTP security header check, JWT inspector, CORS review and auth flow review. Agent and MCP security lives in the agent-security-skills marketplace.
Install
In Claude Code, add the marketplace and install the plugin:
/plugin marketplace add basitalisandhu/claude-skills
/plugin install security-basics@claude-skills
Or copy the skill files into ~/.claude/skills/ from a clone:
git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --only security-basics
Skills
| Skill | What it does | Scripts |
|---|---|---|
| auth-flow-review | Review an application's authentication and session design against a checklist covering password handling, login and logout, session cookies and tokens, OAuth and OIDC flows (authorization code with PKCE, state, redirect URI validation), multi-factor, password reset, account enumeration, rate limiting, remember-me and device trust, and logging; then produce findings with severity and the corrected flow. | no |
| cors-review | Review a web application's Cross-Origin Resource Sharing configuration (allowed origins, credentials, methods, headers, preflight caching, exposed headers) against a checklist of the mistakes that create cross-site data leaks or break legitimate clients, and produce the correct configuration for the framework or gateway in use. | no |
| dependency-audit-reader | Read the JSON output of npm audit, yarn audit, pip-audit or cargo audit with a bundled script that ranks vulnerable packages by severity, separates fixable from unfixable and direct from transitive, and names the packages to upgrade first; then plan the upgrades, the overrides and the accepted risks with expiry dates. | yes |
| http-security-headers | Check the security headers of a captured HTTP response (saved from curl or the browser) with a bundled script that grades HSTS, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy, cookie flags, CORS with credentials, information disclosure and caching, then produce the header set for the web server or framework. | yes |
| jwt-inspector | Decode a JSON Web Token without verifying it with a bundled script that prints the header and claims with times explained, and flags unsafe settings (alg none, empty signature, missing or long expiry, jku or x5u headers, suspicious kid, symmetric algorithms, sensitive claims in the payload), then review how the application issues and verifies tokens. | yes |
| secrets-hygiene | Scan a repository, a directory or the files staged for commit for leaked credentials (cloud and SaaS API keys, private keys, tokens, connection strings with passwords, high-entropy assignments) with a bundled script that redacts what it finds, check that .env files are ignored, maintain a baseline of accepted findings, and walk the rotation and history cleanup when something real is found. | yes |
Plugin README
Six lightweight security skills for everyday development: a secrets scan, an audit report reader, an HTTP security header check, a JWT inspector, a CORS review and an auth flow review. Agent and MCP security lives in the agent-security-skills marketplace.
Install
/plugin marketplace add basitalisandhu/claude-dev-skills
/plugin install security-basics@claude-dev-skills
Skills then appear as /security-basics:<skill>. Scripts need Python 3.11 or newer on PATH as python3; they use the standard library only and make no network calls.
Skills
| Skill | Triggers on | Produces |
|---|---|---|
secrets-hygiene | check for secrets, pre-commit, after a leak | secrets_scan.py redacted findings, baseline, rotation steps |
dependency-audit-reader | npm audit or pip-audit fails CI | audit_reader.py ranked packages, upgrade and override plan |
http-security-headers | are our headers secure, scanner finding | headers_check.py grade and the server configuration |
jwt-inspector | what is in this token, is our JWT setup safe | jwt_inspect.py decoded claims (unverified) and findings |
cors-review | CORS error, allow the frontend, permissive policy | checklist findings and the allowlist configuration |
auth-flow-review | design login, review auth, account takeover | per-flow findings with severity and corrected flows |
Tests for every script live in the repository's tests/ directory; run python3 -m pytest -q at the repository root.