Smithery Logo
MCPsSkillsDocsPricing
Login
Smithery Logo

Accelerating the Agent Economy

Resources

DocumentationPrivacy PolicySystem Status

Company

PricingAboutBlog

Connect

© 2026 Smithery. All rights reserved.

    Zate

    security-checklist

    Zate/security-checklist
    Security
    4

    About

    SKILL.md

    Install

    Install via Skills CLI

    or add to your agent
    • Claude Code
      Claude Code
    • Codex
      Codex
    • OpenClaw
      OpenClaw
    • Cursor
      Cursor
    • Amp
      Amp
    • GitHub Copilot
      GitHub Copilot
    • Gemini CLI
      Gemini CLI
    • Kilo Code
      Kilo Code
    • Junie
      Junie
    • Replit
      Replit
    • Windsurf
      Windsurf
    • Cline
      Cline
    • Continue
      Continue
    • OpenCode
      OpenCode
    • OpenHands
      OpenHands
    • Roo Code
      Roo Code
    • Augment
      Augment
    • Goose
      Goose
    • Trae
      Trae
    • Zencoder
      Zencoder
    • Antigravity
      Antigravity
    ├─
    ├─
    └─

    About

    This skill should be used for OWASP, security review, authentication, XSS, SQL injection prevention, CSRF, input validation, secure coding, vulnerability scanning

    SKILL.md

    Security Checklist

    Security review checklist based on OWASP Top 10.

    Input Validation

    • Validate all user input
    • Use parameterized queries (no SQL concat)
    • Sanitize HTML output (prevent XSS)
    • Validate file uploads (type, size)

    Authentication

    • Hash passwords (bcrypt, argon2)
    • Use secure session management
    • Implement rate limiting
    • Require strong passwords

    Authorization

    • Check permissions on every request
    • Use principle of least privilege
    • Validate ownership of resources

    Data Protection

    • Use HTTPS everywhere
    • Don't log sensitive data
    • Encrypt sensitive data at rest
    • No secrets in source code

    Headers

    Content-Security-Policy: default-src 'self'
    X-Content-Type-Options: nosniff
    X-Frame-Options: DENY
    Strict-Transport-Security: max-age=31536000
    

    Common Vulnerabilities

    Vuln Prevention
    SQL Injection Parameterized queries
    XSS Output encoding
    CSRF CSRF tokens
    Secrets Environment variables
    Repository
    zate/cc-plugins
    Files