security-rules

security-rules is a skill for Claude Code from rocky2431/ultra-builder-pro. It costs 9 tokens per session (466 once invoked), scanned A, original, MIT.

A set of mandatory code-review rules for finding common security problems, such as unsafe input handling, SQL injection, cross-site scripting, leaked secrets, and weak access checks.

In plain words
What is it for?
Reviewing or writing code that handles user input, databases, HTML output, authentication, sessions, secrets, or browser access rules.
Why use it?
It gives reviews a consistent checklist for rejecting risky patterns before they become vulnerabilities.

Skill for Claude Code

Written for Claude Code: user-invocable in frontmatter. Also seen: positional $N argument.

Good fit Reviewing or writing code that handles user input, databases, HTML output, authentication, sessions, secrets, or browser access rules.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/rocky2431/ultra-builder-pro/security-rules
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add rocky2431/ultra-builder-pro --skill security-rules
Clone the repo
git clone --depth 1 https://github.com/rocky2431/ultra-builder-pro

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-rules

README.md
[![agentmods](https://agentmods.dev/badge/skills/rocky2431/ultra-builder-pro/security-rules.svg)](https://agentmods.dev/skills/rocky2431/ultra-builder-pro/security-rules)
Your own site
<a href="https://agentmods.dev/skills/rocky2431/ultra-builder-pro/security-rules"><img src="https://agentmods.dev/badge/skills/rocky2431/ultra-builder-pro/security-rules.svg" alt="Measured on agentmods" height="20"></a>
Per session 9 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 466 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00009 $0.00466
Opus 5 $0.00005 $0.00233
Sonnet 5 $0.00002 $0.00093
Haiku 4.5 $0.00001 $0.00047

Measured 8d ago against content hash 50d143d11bdc, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

security-rules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/security-rules/SKILL.md · 61 lines

How it starts

The opening of the file, as written. The whole thing — 61 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Rules

These rules are mandatory for all code review and security-related work.

Input Validation

All external input MUST be validated:

  • Syntactic: correct format (email, date, UUID)
  • Semantic: valid in business context (start < end, price > 0)
  • Validate early, reject invalid input immediately

Forbidden Patterns

Pattern Risk Alternative
SQL string concatenation SQL Injection Parameterized queries ($1, ?)
User input → HTML directly XSS textContent, sanitizer library
Hardcoded secrets/keys Credential leak Environment variables, secret manager
Trust client-supplied role Privilege escalation Derive from session/token server-side
Dynamic code evaluation with user input Code injection Use safe parsers (JSON.parse, etc.)
Regex with user input ReDoS Validate/escape regex input

Required Practices

Area Rule
SQL Parameterized queries only
Output Escape/sanitize all user-derived content
Auth Use established auth libraries
Secrets Environment variables or secret manager
Sessions Secure, HttpOnly, SameSite cookies
CORS Explicit allowlist, never wildcard in production
File upload Validate type, size, sanitize filename

Error Handling Security

  • Never expose stack traces to end users
  • Never include sensitive data in error messages
  • Log security events with sufficient context for investigation
  • Use typed errors, not generic messages

Review Checklist

When reviewing code, check for:

  1. SQL injection vectors (string concatenation in queries)
  2. XSS vectors (unescaped user input in HTML/templates)
  3. Hardcoded credentials, API keys, or secrets
  4. Missing authentication/authorization checks
  5. Missing input validation on external boundaries
  6. Insecure direct object references (IDOR)
  7. Missing rate limiting on sensitive endpoints
  8. Sensitive data in logs or error messages
  9. Missing CSRF protection on state-changing operations
  10. Insecure deserialization

Read the full file on GitHub · 61 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 61 lines · 9 tokens per session scan A 50d143d11bdc

Subscribe to this mod's changes

security-rules is a skill published in the GitHub repository rocky2431/ultra-builder-pro (11 stars, last pushed 1mo ago), licensed MIT. It adds 9 tokens to every session and 466 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.