security-checklist
Security best practices for Micronaut/Kotlin backend including authentication, authorization, input validation, and OWASP prevention. Use when implementing auth, validating inputs, or reviewing security.
How do I install this agent skill?
npx skills add https://github.com/c0x12c/ai-toolkit --skill security-checklistIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill is a security auditing tool for Micronaut/Kotlin backends. It provides instructions and code references to detect and fix common vulnerabilities such as SQL injection, XSS, and broken authentication. No malicious behaviors or security risks were identified.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Security Checklist
Run a security audit against Micronaut/Kotlin backend code.
When to Use
- Adding authentication or authorization to endpoints
- Validating user inputs on new or changed endpoints
- Reviewing code for security issues before merge
- Checking for common vulnerabilities (SQL injection, XSS, IDOR)
- Setting up secrets management
Process
See audit-reference.md for code examples, vulnerability table, and SAFE/DANGEROUS patterns.
- Check Authentication — every controller has @Secured, current user comes from security context
- Check Authorization — verify user has access to the resource before returning it
- Check Input Validation — @Valid on controller params, Jakarta annotations on request DTOs
- Check SQL Injection Prevention — use Exposed ORM (auto-parameterized), never raw SQL with string concat
- Check Common Vulnerabilities — SQL injection, XSS, CSRF, auth bypass, IDOR, mass assignment, data exposure, rate limiting
- Check Secrets Management — no hardcoded secrets, use env vars, never log tokens/passwords/PII, never commit .env
- Check Response Sanitization — response DTOs control what's exposed, never return raw entities
Interaction Style
- Always checks all categories, doesn't skip any section
- Flags the most dangerous issues first
- Shows code examples for every fix, not just descriptions
- Tells you what's wrong AND how to fix it
Rules
- Every endpoint must have a @Secured annotation
- Admin endpoints use OAuthSecurityRule.ADMIN
- Users can only access their own resources (or admin can access all)
- Input validated with @Valid and Jakarta annotations
- No raw SQL queries with string concatenation
- Sensitive fields excluded from response DTOs
- Tokens/passwords never logged
- Error messages don't leak internal details
- Rate limiting on auth endpoints
Output
Produces a checklist report with pass/fail for each category:
- All endpoints have @Secured annotation
- Admin endpoints use OAuthSecurityRule.ADMIN
- User can only access their own resources (or admin can access all)
- Input validated with @Valid and Jakarta annotations
- No raw SQL queries with string concatenation
- Sensitive fields excluded from response DTOs
- Tokens/passwords never logged
- Error messages don't leak internal details
- Rate limiting on auth endpoints
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/c0x12c/ai-toolkit/security-checklist">View security-checklist on skillZs</a>