hello-security
SkillFiles & storageUse when performing security-sensitive operations involving authentication, passwords, tokens, JWT, OAuth, sessions, cookies, encryption, keys, API keys, permissions, roles, user input validation, file uploads, etc.
Use hello-security in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add hello-security and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the hello-security skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by hellowind777/helloagents in skills/hello-security/SKILL.md and read by ahel’s review.
安全相关代码必须遵循以下规范。
编码前
先识别攻击面和信任边界,再写代码。
认证与密钥
- 密码:bcrypt/argon2 哈希,不可逆存储
- JWT:设置过期时间,使用 RS256 或 HS256,不在 payload 存敏感数据
- 密钥/API key:环境变量或密钥管理服务,不硬编码
- .env 不提交到版本控制(.gitignore)
- API key 使用最小权限原则
输入验证
- 所有外部输入(用户、API、文件)必须验证
- 白名单优于黑名单
- SQL:参数化查询,不拼接字符串
- 文件上传:验证类型、大小、内容,不信任文件扩展名
输出防护
- XSS:输出编码,设置 CSP 头
- CSRF:token 验证
- 敏感数据:HTTPS 传输,加密存储,不记录到日志
- 错误信息:不暴露内部实现细节给用户
权限控制
- 最小权限原则
- 检查资源所有权(不能只检查角色)
- 路径遍历:规范化路径,限制访问范围
交付检查
- 无硬编码密钥/密码
- 所有用户输入已验证
- SQL 使用参数化查询
- 敏感数据不在日志中
- 认证 token 有过期时间
Signals
- GitHub stars
- 704
- Forks
- 97
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
hello-security- Source
- github.com/hellowind777/helloagents
github.com/hellowind777/helloagents
Related picks
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretschecking-owasp-compliance
Skill · jeremylongshore
The pick for Web (OWASP)owasp-security
Skill · davila7
The pick for Web (OWASP)pptx
Skill · anthropics
More in Files & storagedocx
Skill · anthropics
More in Files & storage