Security Way¶
Source: hooks/ways/softwaredev/code/security/security.md
Frontmatter
| Field | Value |
|---|---|
description |
security overview, secure coding defaults, security review checklist |
vocabulary |
security vulnerability protect defense secure harden owasp |
refire |
0.2 |
scope |
agent, subagent |
Defaults¶
- Parameterized queries for all database access
- Escape output for its context (HTML, URL, SQL)
- Validate at system boundaries (user input, external APIs)
- Principle of least privilege for permissions
When Reviewing Existing Code¶
Flag these as security issues: - Hardcoded secrets or credentials - SQL string concatenation - Unsanitized user input in templates or commands - Missing authentication/authorization on endpoints - Sensitive data in logs
See Also¶
- code/security/auth(softwaredev) — authentication requirements
- code/security/injection(softwaredev) — injection prevention
- code/security/secrets(softwaredev) — credential management
- code/security/guards(softwaredev) — restrictive rules, fallback posture, never widen a control to clear a symptom
- code/security/pentest(softwaredev) — authorized offensive testing, scope gate first
- code/supplychain(softwaredev) — dependency security