Skip to content

Security Way

Source: hooks/ways/softwaredev/code/security/security.md

Frontmatter
Field Value
description security overview, secure coding defaults, security review checklist
vocabulary security vulnerability protect defense secure harden owasp
refire 0.2
scope agent, subagent

Defaults

  • Parameterized queries for all database access
  • Escape output for its context (HTML, URL, SQL)
  • Validate at system boundaries (user input, external APIs)
  • Principle of least privilege for permissions

When Reviewing Existing Code

Flag these as security issues: - Hardcoded secrets or credentials - SQL string concatenation - Unsanitized user input in templates or commands - Missing authentication/authorization on endpoints - Sensitive data in logs

See Also

  • code/security/auth(softwaredev) — authentication requirements
  • code/security/injection(softwaredev) — injection prevention
  • code/security/secrets(softwaredev) — credential management
  • code/security/guards(softwaredev) — restrictive rules, fallback posture, never widen a control to clear a symptom
  • code/security/pentest(softwaredev) — authorized offensive testing, scope gate first
  • code/supplychain(softwaredev) — dependency security