Home / security-basics

Security Basics

Six lightweight security skills for everyday development: secrets hygiene scan, npm audit and pip-audit reader, HTTP security header check, JWT inspector, CORS review and auth flow review. Agent and MCP security lives in the agent-security-skills marketplace.

Plugin security-basics, version 0.1.1, 6 skills, MIT licence. Source: claude-dev-skills. Synced .

Install

In Claude Code, add the marketplace and install the plugin:

/plugin marketplace add basitalisandhu/claude-skills
/plugin install security-basics@claude-skills

Or copy the skill files into ~/.claude/skills/ from a clone:

git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --only security-basics

Skills

SkillWhat it doesScripts
auth-flow-reviewReview an application's authentication and session design against a checklist covering password handling, login and logout, session cookies and tokens, OAuth and OIDC flows (authorization code with PKCE, state, redirect URI validation), multi-factor, password reset, account enumeration, rate limiting, remember-me and device trust, and logging; then produce findings with severity and the corrected flow.no
cors-reviewReview a web application's Cross-Origin Resource Sharing configuration (allowed origins, credentials, methods, headers, preflight caching, exposed headers) against a checklist of the mistakes that create cross-site data leaks or break legitimate clients, and produce the correct configuration for the framework or gateway in use.no
dependency-audit-readerRead the JSON output of npm audit, yarn audit, pip-audit or cargo audit with a bundled script that ranks vulnerable packages by severity, separates fixable from unfixable and direct from transitive, and names the packages to upgrade first; then plan the upgrades, the overrides and the accepted risks with expiry dates.yes
http-security-headersCheck the security headers of a captured HTTP response (saved from curl or the browser) with a bundled script that grades HSTS, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy, cookie flags, CORS with credentials, information disclosure and caching, then produce the header set for the web server or framework.yes
jwt-inspectorDecode a JSON Web Token without verifying it with a bundled script that prints the header and claims with times explained, and flags unsafe settings (alg none, empty signature, missing or long expiry, jku or x5u headers, suspicious kid, symmetric algorithms, sensitive claims in the payload), then review how the application issues and verifies tokens.yes
secrets-hygieneScan a repository, a directory or the files staged for commit for leaked credentials (cloud and SaaS API keys, private keys, tokens, connection strings with passwords, high-entropy assignments) with a bundled script that redacts what it finds, check that .env files are ignored, maintain a baseline of accepted findings, and walk the rotation and history cleanup when something real is found.yes

Plugin README

Six lightweight security skills for everyday development: a secrets scan, an audit report reader, an HTTP security header check, a JWT inspector, a CORS review and an auth flow review. Agent and MCP security lives in the agent-security-skills marketplace.

Install

/plugin marketplace add basitalisandhu/claude-dev-skills
/plugin install security-basics@claude-dev-skills

Skills then appear as /security-basics:<skill>. Scripts need Python 3.11 or newer on PATH as python3; they use the standard library only and make no network calls.

Skills

SkillTriggers onProduces
secrets-hygienecheck for secrets, pre-commit, after a leaksecrets_scan.py redacted findings, baseline, rotation steps
dependency-audit-readernpm audit or pip-audit fails CIaudit_reader.py ranked packages, upgrade and override plan
http-security-headersare our headers secure, scanner findingheaders_check.py grade and the server configuration
jwt-inspectorwhat is in this token, is our JWT setup safejwt_inspect.py decoded claims (unverified) and findings
cors-reviewCORS error, allow the frontend, permissive policychecklist findings and the allowlist configuration
auth-flow-reviewdesign login, review auth, account takeoverper-flow findings with severity and corrected flows

Tests for every script live in the repository's tests/ directory; run python3 -m pytest -q at the repository root.