Back to list
SylphxAI

appsec

by SylphxAI

🚀 AI development platform with MEP architecture - stop writing prompts, start building with 90% less typing

4🍴 3📅 Jan 8, 2026

SKILL.md


name: appsec description: Application security - OWASP, validation, secrets. Use when securing the app.

AppSec Guideline

Tech Stack

  • Rate Limiting: Upstash Redis
  • Framework: Next.js (with Turbopack)
  • Platform: Vercel

Non-Negotiables

  • OWASP Top 10:2025 vulnerabilities must be addressed
  • Security headers present (CSP, HSTS, X-Frame-Options, X-Content-Type-Options)
  • CSRF protection on state-changing requests
  • No plaintext secrets in logs, returns, storage, or telemetry
  • Required configuration must fail-fast at build/startup if missing
  • Secrets must not be hardcoded or committed

Context

Security isn't a feature — it's a foundational property. A single vulnerability can compromise everything else. Think like an attacker: where are the weak points?

MFA and session security live in account-security. This skill focuses on application-level attack surface.

Driving Questions

  • What would an attacker target first?
  • Where is rate limiting missing or insufficient?
  • How are secrets managed and what's the rotation strategy?
  • What happens when a secret is compromised?
  • Where does "security by obscurity" substitute for real controls?

Score

Total Score

75/100

Based on repository quality metrics

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

+10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新

+5
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

+5

Reviews

💬

Reviews coming soon