bitrix-security
Bitrix security patterns — CSRF, XSS and link sanitizing, open redirects, SQL injection in ORM/ExpressionField, SSRF and local-file reads, uploads, rights checks, JWT, encrypted fields. Use when handling user input or auditing code.
How do I install this agent skill?
npx skills add https://github.com/bxmaximum/bitrix-framework-skills --skill bitrix-securityIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides security guidelines and coding patterns for the Bitrix framework, covering CSRF, XSS, SQL injection, SSRF, and JWT management. No malicious patterns or vulnerabilities were detected.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Security
Baseline: main 23.0+ · Verified: main 26.800.0
General defaults (no superglobals, keep default prefilters, escape output) live in bitrix-framework.
| Task | Read |
|---|---|
| CSRF, escaping, HTML sanitizing, link and redirect targets, raw-HTML sinks | rules/csrf-xss.md |
SQL injection (raw, ORM, ExpressionField), SSRF, local files, uploads, stored settings | rules/sql-ssrf.md |
Rights checks, #[ActionAccess], REST scopes, JWT/JWK, encryption, 2FA | rules/jwt-crypto-access.md |
Invariants
- Untrusted: request data, and also DB-stored settings, imports, REST payloads. The type and owner of an entity come from its DB record, never from the request.
- Whitelist whatever becomes SQL structure (field names, operators, functions,
orderkeys), whatever its source. - Escape for the output context: HTML
htmlspecialcharsbx(), JSJson::encode(), URLs through a scheme allow-list. - User input never goes unchecked into
CFile::MakeFileArray(),file_get_contents(),unserialize(), redirect targets. Authentication/Csrffilters don't authorize: check rights on the object in every action.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/bxmaximum/bitrix-framework-skills/bitrix-security">View bitrix-security on skillZs</a>