Apply input validation, output encoding and least privilege by default.
Scanned 9/3/2026
Install to Claude Code
npx -y skills add Andersseen/agentyx --skill secure-coding --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Secure Coding?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/andersseen-secure-coding)More formats (shields.io, HTML) on the badges page.
---
name: secure-coding
description: Apply input validation, output encoding and least privilege by default.
---
# Secure coding
Treat every input crossing a trust boundary as hostile, including input from your own other services.
## Validate at the boundary
Validate structure, type, range and length where untrusted data enters, and reject what does not
conform. Allow-lists beat deny-lists: enumerate what is valid rather than guessing what is dangerous.
## Never build queries or commands by concatenation
Use parameterized queries and argument arrays. String interpolation into SQL, shell commands,
templates or file paths is the root of injection.
## Encode for the destination
Escaping depends on where the value lands: HTML body, attribute, URL, SQL, shell and JSON all differ.
Encode at the point of output, not on the way in.
## Apply least privilege
Give every process, token and database role the narrowest permissions that let it work. Scope
credentials per environment so a leak in one does not compromise the others.
## Fail closed
On error, deny access and log the reason. An exception path that falls through to permitted access is
a vulnerability, not a bug.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.
Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation
SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.
Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST APIs with FastAPI, (2) Implementing JWT/OAuth2 authentication, (3) Setting up SQLAlchemy/async databases, (4) Integrating Redis/Upstash caching, (5) Refactoring AI-generated Python code (deslopification), (6) Designing API patterns, or (7) Optimizing backend performance.
PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.