security-best-practices

Review Python, JavaScript/TypeScript, and Go code for security best practices.

Updated Feb 14, 2026
One-click install
npx skills add https://github.com/oldwombat/nekrosol --skill security-best-practices-oldwombat
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-best-practices
Source: https://github.com/oldwombat/nekrosol/tree/main/.github/skills/security-best-practices
Command: npx skills add https://github.com/oldwombat/nekrosol --skill security-best-practices-oldwombat

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security best-practices for language/framework reviews are often scattered across sources; this skill consolidates them into a unified, actionable guide that streamlines secure coding and auditing workflows.

Core Features & Use Cases

  • Centralized, language- and framework-specific security guidance for development, reviews, and auto-generated checks.
  • Reference-driven operation: loads canonical guidance from a references directory to inform actions.
  • Suitable for security reviews, vulnerability hunting, and secure-by-default coding assistance across teams and projects.

Quick Start

Prompt the system to load the appropriate language security references and perform an initial security review against the current codebase.

Frequently Asked Questions about security-best-practices

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is secure-by-default coding guidance and how does it work for code reviews?

To perform a security review, prompt the system to load the appropriate language security references from the references directory. The skill then analyzes your Python, JavaScript/TypeScript, or Go codebase against canonical best practices and generates structured security reports.

How do I perform a security best-practice review for my Python or Go backend?

To perform a security review, prompt the system to load the appropriate language security references from the references directory. The skill then analyzes your Python, JavaScript/TypeScript, or Go codebase against canonical best practices and generates structured security reports.

Does this security guidance support both frontend and backend JavaScript projects?

This skill consolidates scattered security best-practices into a unified, actionable guide. Unlike manual checklist reviews, it loads canonical guidance directly from a references directory to inform automated checks, vulnerability hunting, and secure-by-default coding assistance.

What's the best way to consolidate scattered security best practices for threat modeling?

This skill consolidates scattered security best-practices into a unified, actionable guide. Unlike manual checklist reviews, it loads canonical guidance directly from a references directory to inform automated checks, vulnerability hunting, and secure-by-default coding assistance.

Do I need specific dependencies or components to use this security review skill?

This skill relies on YAML-frontmatter rules to yield structured metadata for discovery and automation. If the reference guidance is not loaded properly from the references directory, the security reports and secure-by-default coding assistance will not execute correctly.

Why does my security review fail to load the authoritative guidance references?

This skill relies on YAML-frontmatter rules to yield structured metadata for discovery and automation. If the reference guidance is not loaded properly from the references directory, the security reports and secure-by-default coding assistance will not execute correctly.