security-best-practices

Analyze Python, JavaScript/TypeScript, and Go codebases for security best-practice gaps and generate remediation guidance.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/rodrigotoledo/trading-exchange --skill security-best-practices-rodrigotoledo
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-best-practices
Source: https://github.com/rodrigotoledo/trading-exchange/tree/main/packages/skills-catalog/skills/%28security%29/security-best-practices
Command: npx skills add https://github.com/rodrigotoledo/trading-exchange --skill security-best-practices-rodrigotoledo

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps teams identify gaps in security practices across languages and frameworks, and provides actionable guidance to harden code, configurations, and workflows.

Core Features & Use Cases

  • Review language/framework security best practices for Python, JavaScript/TypeScript, and Go projects.
  • Generate prioritized remediation plans for insecure patterns in code, dependencies, and deployment.
  • Produce reusable guidance suitable for security reviews, threat modeling, and secure-by-default coding tasks.

Quick Start

Analyze a project to surface critical security gaps and return a prioritized remediation plan.

Frequently Asked Questions about security-best-practices

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review my codebase for security best practices and generate a remediation plan?

Security best practices review analyzes Python, JavaScript/TypeScript, and Go projects to identify insecure patterns, code gaps, and configuration vulnerabilities. It outputs structured findings with severity levels, locations, recommended fixes, and risk notes to produce a prioritized remediation plan.

What is threat modeling and secure-by-default code review for backend services?

Threat modeling and secure-by-default code review systematically surface security improvements across backend services, frontend apps, and deployment pipelines. This process identifies gaps in security coverage and generates actionable guidance to harden code, dependencies, and workflows.

Can I use this security auditing approach for Go and JavaScript projects?

Yes, security auditing applies across Python, JavaScript/TypeScript, and Go projects, including backend services, frontend apps, and deployment pipelines. It reviews language and framework security best practices to surface critical gaps and return prioritized remediation guidance.

What's the best way to audit deployment and configuration pipelines for vulnerabilities?

Auditing deployment and configuration pipelines for vulnerabilities involves analyzing the codebase to identify insecure patterns and gaps in security best-practices coverage. The process generates prioritized remediation plans with structured findings, severity ratings, and recommended fixes for hardening workflows.

Do I need any dependencies or external tools to perform a security best practices audit?

No external dependencies or tools are required to perform a security best practices audit. The skill loads guidance from its internal references directory and analyzes the codebase directly to output structured findings with severity, location, recommended fixes, and risk notes.