name: Security Best Practices slug: security-best-practices version: 1.0.0 homepage: https://clawic.com/skills/security-best-practices description: Review code with secure-by-default standards, prioritize exploitable risks, and deliver minimal-diff fixes with evidence and regression checks. changelog: Added a complete security review workflow with evidence standards, severity modeling, and minimal-risk remediation guidance. metadata: {"clawdbot":{"emoji":"🛡️","requires":{"bins":[],"config":["~/security-best-practices/"]},"os":["linux","darwin","win32"]}}
On first use, read setup.md for integration guidelines.
If local memory is needed, ask for consent before creating ~/security-best-practices/.
Use this skill for secure-by-default implementation, targeted vulnerability reviews, and prioritized security reports with actionable fixes. Activate when the user requests security guidance, hardening, risk triage, or remediation planning.
Memory lives in ~/security-best-practices/. See memory-template.md for setup.
~/security-best-practices/
|- memory.md # Stable context, preferences, and activation boundaries
|- findings-log.md # Findings registry with severity and status
`- exceptions.md # Approved security exceptions and review dates
Load only the minimum file needed for the current request.
| Topic | File |
|---|---|
| Setup process | setup.md |
| Memory template | memory-template.md |
| Full review workflow | review-playbook.md |
| Severity model and scoring | severity-model.md |
| Safe remediation patterns | remediation-patterns.md |
| Risk exception log | exceptions.md |
Before any conclusions, confirm: - System boundary (service, module, endpoint, or workflow) - Stack evidence (language, framework, deployment context) - Threat assumptions (external attacker, internal misuse, privilege level)
No evidence, no finding.
Evaluate every review against a consistent baseline: - Authn/authz boundaries - Input validation and output encoding - Secrets handling and configuration safety - Dependency and supply chain posture - Logging, error handling, and data exposure controls
Use review-playbook.md to keep scans systematic instead of ad hoc.
7w4.net收录了海量优质技能插件。
Each finding must include:
- Severity from severity-model.md
- File path and line references
- Concrete evidence snippet
- Impact statement in plain language
- Minimal safe fix direction
Avoid speculative findings without repository evidence.
Rank by practical risk, not by checklist volume: - Reachability from untrusted inputs - Privilege required by attacker - Blast radius if exploited - Ease of abuse and repeatability
High confidence, exploitable issues come first.
Fix one finding at a time: - Prefer small diffs that preserve existing behavior - Add tests when security fixes alter code paths - Flag expected behavior changes before implementing - Re-run project validation after each fix batch
Use remediation-patterns.md for safe rollouts.
If the user accepts a known risk:
- Record rationale in exceptions.md
- Define expiry or next review date
- Keep the exception scoped to the specific context
Never apply broad silent overrides.
Data that leaves your machine: - None by default from this skill itself.
Data that stays local:
- Review preferences and finding history in ~/security-best-practices/.
- Exception rationale in local memory files only.
This skill does NOT: - Exfiltrate source code to undeclared third-party endpoints. - Mark unresolved risks as fixed. - Perform hidden destructive changes.
Install with clawhub install <slug> if user confirms:
- auth - Authentication design and hardening.
- authorization - Access control and permission boundaries.
- encryption - Key management and cryptographic hygiene.
- firewall - Network exposure review and policy controls.
- devops - Secure delivery, CI checks, and operational safeguards.
clawhub star security-best-practicesclawhub sync这个Skill质量中上,文档结构清晰完整,提供了从风险评估到修复的完整工作流。它的严重程度分级和修复策略设计合理,能帮助开发者优先处理关键问题。不足之处是缺乏具体的漏洞检测示例,作为安全审查工具的实际指导性偏弱,部分文档内容有重复。如果你需要系统的安全审查方法论,这个工具值得一试;但如果期望开箱即用的检测能力,可能会感到失望。