moai-ref-owasp-checklist

Reference OWASP Top 10 controls, authentication patterns, and HTTP security headers.

Updated Apr 26, 2026
One-click install
npx skills add https://github.com/gkswls5006-web/last-todo --skill moai-ref-owasp-checklist-gkswls5006-web
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: moai-ref-owasp-checklist
Source: https://github.com/gkswls5006-web/last-todo/tree/main/.claude/skills/moai-ref-owasp-checklist
Command: npx skills add https://github.com/gkswls5006-web/last-todo --skill moai-ref-owasp-checklist-gkswls5006-web

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This reference consolidates the OWASP Top 10 controls, authentication patterns, input validation requirements, and HTTP security headers into a single, reusable guide for secure API design and audits.

Core Features & Use Cases

  • Comprehensive checklist aligned with the OWASP Top 10 for API security and backend hardening.
  • Practical defense recommendations and security header guidance for production-ready configurations.
  • Use Case: security reviews, API development, and secure-by-default engineering practices.

Quick Start

Apply the OWASP checklist to your API endpoints to identify and mitigate top risks.

Frequently Asked Questions about moai-ref-owasp-checklist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the OWASP Top 10 checklist for API security and backend hardening?

The OWASP Top 10 checklist is a consolidated reference of security controls, authentication patterns, and HTTP security headers designed to guide secure API design and backend audits.

How do I apply OWASP security checks to my API endpoints?

You can load the OWASP security checklist into context to systematically identify and mitigate top risks across your API endpoints during development and security reviews.

What HTTP security headers and authentication patterns should I use for production-ready APIs?

Production-ready APIs require specific HTTP security headers and robust authentication patterns as defined by the OWASP checklist to ensure secure-by-default engineering practices.

Can I use this OWASP reference for deterministic security guidance during audits?

Yes, this OWASP reference provides deterministic guidance with documented checklists and structured defense recommendations specifically tailored for security reviews and audits.

Does this OWASP security checklist cover input validation requirements for backend services?

Yes, the checklist consolidates input validation requirements alongside OWASP Top 10 controls and authentication patterns to secure backend services against common vulnerabilities.