Claude Code Plugins

Community-maintained marketplace

Feedback
0
0

Apply security awareness during code review and implementation. Catches common vulnerabilities without requiring full security audit.

Install Skill

1Download skill
2Enable skills in Claude

Open claude.ai/settings/capabilities and find the "Skills" section

3Upload to Claude

Click "Upload skill" and select the downloaded ZIP file

Note: Please verify skill by going through its instructions before using it.

SKILL.md

name security-lens
description Apply security awareness during code review and implementation. Catches common vulnerabilities without requiring full security audit.
allowed-tools Read, Grep, Glob

Security Awareness Lens

When reviewing or writing code, check for:

Input Handling

  • User input validated before use
  • SQL uses parameterized queries (never string concat)
  • HTML output escaped to prevent XSS
  • File paths validated (no path traversal)

Authentication/Authorization

  • Auth checks at controller level, not just UI
  • Sensitive operations re-verify permissions
  • Session tokens are httpOnly, secure, sameSite

Data Exposure

  • Logs don't contain secrets, tokens, PII
  • Error messages don't leak internal details
  • API responses don't include unnecessary fields

Secrets

  • No hardcoded credentials
  • Secrets from environment/vault, not config files
  • .gitignore covers .env, credentials

See @owasp-quick-ref.md for detailed vulnerability patterns.