Skip to content
ai101.tools
navigateopenescclose
Claude+372Whisper+228LangChain+168Codex+223NotebookLM+276DALL-E 3+192DeepL+249n8n+208Topaz Video AI+153LlamaIndex+161
Backend API Security logo
Skill

Backend API Security

Two backend agents that write secure API code rather than audit it after the fact.

0
SaveVisit website ↗

Install

Claude Code: /plugin marketplace add wshobson/agents → /plugin install backend-api-security@claude-code-workflows
Triggers on

Kimlik doğrulama, yetkilendirme ya da girdi doğrulama kodu yazarken ve API'yi saldırıya karşı sertleştirirken

Needs tools
ReadEditGrep
Author
wshobson
License
MIT

The plugin ships a backend architect and a backend security coder, and the second one carries an unusual instruction: its own description tells the model when not to use it. Posture audits, compliance work and threat modeling are routed to a different agent, because this one exists to write the code. That routing note matters, since security prompts otherwise collapse into generic advice that fits every project and fixes none. Coverage is the backend attack surface in detail: allowlist input validation, SQL, NoSQL, LDAP and command injection prevention, HttpOnly and SameSite cookie scoping, HSTS and CSP headers, credential-aware CORS, double-submit CSRF tokens, session fixation and secret rotation.

Comments(0)

Sign in to comment

No comments yet — be the first.

Similar skills

Report this comment

Why are you reporting this?