hello-security

SkillFiles & storage

Use when performing security-sensitive operations involving authentication, passwords, tokens, JWT, OAuth, sessions, cookies, encryption, keys, API keys, permissions, roles, user input validation, file uploads, etc.

Use hello-security in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add hello-security and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the hello-security skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

hello-securityStart free

What this skill tells your AI

The instructions your AI receives, as published by hellowind777/helloagents in skills/hello-security/SKILL.md and read by ahel’s review.

安全相关代码必须遵循以下规范。

编码前

先识别攻击面和信任边界,再写代码。

认证与密钥

  • 密码:bcrypt/argon2 哈希,不可逆存储
  • JWT:设置过期时间,使用 RS256 或 HS256,不在 payload 存敏感数据
  • 密钥/API key:环境变量或密钥管理服务,不硬编码
  • .env 不提交到版本控制(.gitignore)
  • API key 使用最小权限原则

输入验证

  • 所有外部输入(用户、API、文件)必须验证
  • 白名单优于黑名单
  • SQL:参数化查询,不拼接字符串
  • 文件上传:验证类型、大小、内容,不信任文件扩展名

输出防护

  • XSS:输出编码,设置 CSP 头
  • CSRF:token 验证
  • 敏感数据:HTTPS 传输,加密存储,不记录到日志
  • 错误信息:不暴露内部实现细节给用户

权限控制

  • 最小权限原则
  • 检查资源所有权(不能只检查角色)
  • 路径遍历:规范化路径,限制访问范围

交付检查

  • 无硬编码密钥/密码
  • 所有用户输入已验证
  • SQL 使用参数化查询
  • 敏感数据不在日志中
  • 认证 token 有过期时间

Signals

GitHub stars
704
Forks
97
Last commit
Sep 2026
Advanced
Item type
skill
Key
hello-security
Source
github.com/hellowind777/helloagents