重要前提
安装AI Skills的关键前提是:必须科学上网,且开启TUN模式,这一点至关重要,直接决定安装能否顺利完成,在此郑重提醒三遍:科学上网,科学上网,科学上网。查看完整安装教程 →
secure-coding-practices by nickcrew/claude-ctx-plugin
npx skills add https://github.com/nickcrew/claude-ctx-plugin --skill secure-coding-practices通过防御性编程技术和主动威胁缓解策略,实现安全优先开发模式的全面指导。
应用多层安全控制——切勿依赖单一的保护机制。
发生错误时,默认进入安全状态(拒绝访问、拒绝输入、记录事件)。
授予最低必要权限——用户、服务和数据库应仅拥有必需的访问权限。
验证所有输入,编码所有输出,验证所有来源,认证所有请求。
| 任务 | 加载参考 |
|---|---|
| 输入验证与净化 | skills/secure-coding-practices/references/input-validation.md |
| 输出编码与 XSS 防护 | skills/secure-coding-practices/references/output-encoding.md |
广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
| 身份验证与会话 | skills/secure-coding-practices/references/authentication.md |
| 密码学与密钥管理 | skills/secure-coding-practices/references/cryptography.md |
| 依赖项与供应链 | skills/secure-coding-practices/references/dependencies.md |
| 错误处理与日志记录 | skills/secure-coding-practices/references/error-handling.md |
| 安全默认值与配置 | skills/secure-coding-practices/references/secure-defaults.md |
输入验证:
输出编码:
身份验证与授权:
密码学:
依赖项:
错误处理与日志记录:
在代码审查中注意以下模式:
OWASP 资源:
标准与指南:
工具:
每周安装数
58
代码仓库
GitHub 星标数
13
首次出现
2026年1月24日
安全审计
安装于
opencode52
gemini-cli49
codex48
cursor46
github-copilot46
amp43
Comprehensive guidance for implementing security-first development patterns with defensive programming techniques and proactive threat mitigation strategies.
Apply multiple layers of security controls - never rely on a single protection mechanism.
When errors occur, default to the secure state (deny access, reject input, log event).
Grant minimum necessary permissions - users, services, and databases should have only required access.
Validate all input, encode all output, verify all sources, authenticate all requests.
| Task | Load reference |
|---|---|
| Input validation & sanitization | skills/secure-coding-practices/references/input-validation.md |
| Output encoding & XSS prevention | skills/secure-coding-practices/references/output-encoding.md |
| Authentication & sessions | skills/secure-coding-practices/references/authentication.md |
| Cryptography & key management | skills/secure-coding-practices/references/cryptography.md |
| Dependencies & supply chain | skills/secure-coding-practices/references/dependencies.md |
| Error handling & logging | skills/secure-coding-practices/references/error-handling.md |
| Secure defaults & configuration | skills/secure-coding-practices/references/secure-defaults.md |
Input Validation:
Output Encoding:
Authentication & Authorization:
Cryptography:
Dependencies:
Error Handling & Logging:
Watch for these patterns in code reviews:
OWASP Resources:
Standards & Guidelines:
Tools:
Weekly Installs
58
Repository
GitHub Stars
13
First Seen
Jan 24, 2026
Security Audits
Gen Agent Trust HubPassSocketPassSnykPass
Installed on
opencode52
gemini-cli49
codex48
cursor46
github-copilot46
amp43
Azure RBAC 权限管理工具:查找最小角色、创建自定义角色与自动化分配
154,300 周安装