Backend API Security
Two backend agents that write secure API code rather than audit it after the fact.
Install
Claude Code: /plugin marketplace add wshobson/agents → /plugin install backend-api-security@claude-code-workflows
Kimlik doğrulama, yetkilendirme ya da girdi doğrulama kodu yazarken ve API'yi saldırıya karşı sertleştirirken
- Author
- wshobson
- License
- MIT
The plugin ships a backend architect and a backend security coder, and the second one carries an unusual instruction: its own description tells the model when not to use it. Posture audits, compliance work and threat modeling are routed to a different agent, because this one exists to write the code. That routing note matters, since security prompts otherwise collapse into generic advice that fits every project and fixes none. Coverage is the backend attack surface in detail: allowlist input validation, SQL, NoSQL, LDAP and command injection prevention, HttpOnly and SameSite cookie scoping, HSTS and CSP headers, credential-aware CORS, double-submit CSRF tokens, session fixation and secret rotation.
Similar skills
Shell Scripting
SkillTwo shell agents that keep bash idioms out of POSIX sh scripts, with ShellCheck and Bats.
Blockchain & Web3
SkillSolidity security, ERC token standards and Hardhat or Foundry testing for smart contract work.
Game Development
SkillUnity DOTS, Godot 4 GDScript and Bukkit or Paper plugin agents in a single bundle.
Comments(0)
Sign in to comment