Skip to content
Back to skills

Owasp Web Security

ASecurity

Harden web applications against the OWASP Top 10: injection, XSS, auth flaws, CSRF, SSRF, and insecure dependencies. Use for any web app security review.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentspythonrustgobashsqldjangoawsgitapisecurity

Works with

  • cursor
  • api

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 2 files and shows the line behind each finding

Scanned September 29, 2026

npx -y skills add ssrjkk/claude-skills --skill owasp-web-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Owasp Web Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Owasp Web Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ssrjkk-owasp-web-security/badge)](https://www.skillsdirectory.com/skills/ssrjkk-owasp-web-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: owasp-web-security
description: "Harden web applications against the OWASP Top 10: injection, XSS, auth flaws, CSRF, SSRF, and insecure dependencies. Use for any web app security review."
category: security
tags: [owasp, security, web, injection, xss, csrf, ssrf, pentest]
models: [sonnet, opus, gpt-5, gemini-2.5, glm-4.6]
version: 1.0.0
created: 2026-09-20
updated: 2026-09-28
author: ssrjkk
---
# OWASP Web Security

> Hardening web applications against the OWASP Top 10.

## Quick Start
```bash
# Scan dependencies for known vulnerabilities
pip-audit --format full
npm audit
# then review the OWASP Top 10 checklist against your app
```

## When to Use
- Before launching or major releases
- When handling auth, payments, or PII
- After dependency or framework upgrades
- Regular security hardening of existing apps

## Best Practices

### Injection
- Parameterize all SQL/query construction
- Escape output for the context (HTML, JS, URL)
- Validate and whitelist inputs server-side
- Use ORM/query builders; never string-concatenate queries

### Authentication & Authorization
- Use a proven auth library (not homegrown)
- Hash passwords with bcrypt/argon2
- Enforce MFA for sensitive actions
- Check authorization on every endpoint, not just the UI

### XSS & CSRF
- Auto-escape template output; sanitize rich content
- Set CSP headers; use strict `Trusted Types` where possible
- CSRF tokens on all state-changing requests
- Set `SameSite=Lax/Strict` on cookies

### Data & Dependencies
- Encrypt data in transit (TLS) and at rest
- Keep dependencies updated; scan regularly
- Restrict SSRF: block private ranges, pin redirects
- Limit file uploads: type, size, and execution

## Dependencies
```bash
pip install bandit pip-audit
npm install -g npm-audit-resolver
# scanners: semgrep, gitleaks, trivy
```

## Examples
```python
# SQL injection safe pattern
cursor.execute("SELECT * FROM users WHERE email = %s", (email,))
```
```python
# Escape output in templates (Django auto-escapes)
# context = {"user_input": user_input}
# Template: {{ user_input }}   # auto-escaped
```
```python
# CSRF protection (Django middleware default)
from django.views.decorators.csrf import csrf_exempt
# never use @csrf_exempt on state-changing views
```
```python
# SSRF guard
import ipaddress, socket

def safe_fetch(url: str) -> str:
    host = urlparse(url).hostname
    ip = ipaddress.ip_address(socket.gethostbyname(host))
    if not ip.is_private:          # block local/private ranges
        return requests.get(url).text
    raise ValueError("Blocked private address")
```

## Step-by-Step
1. Run dependency scanners (pip-audit/npm audit/trivy).
2. Review authN/authZ: password storage, sessions, roles.
3. Check all inputs: validation, escaping, parameterization.
4. Audit CSRF, XSS, and CSP headers.
5. Review file uploads, SSRF vectors, and redirect handling.
6. Check secrets: gitleaks scan and env-based config.
7. Harden headers: CSP, HSTS, X-Content-Type-Options.
8. Re-scan after fixes; document residual risks.

## Validation
1. No injection points found in code scan
2. Passwords stored with a strong hash
3. Authorization enforced server-side on all endpoints
4. CSP and security headers present
5. Dependency scan reports no critical vulnerabilities

## Troubleshooting
- Broken auth flows: test with the same browser/network rules users hit.
- False positives: verify scanners' claims in a safe environment.
- Legacy code risk: prioritize by exposed attack surface.

Files in this skill

  • SKILL.md3.4 KB
  • SKILL.ru.md5.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…