Best for
- Use when implementing auth flows, security layers, input sanitization, vulnerability prevention, prompt injection defense, or data redaction.
yonatangross/orchestkit/src/skills/security-patterns/SKILL.md
Security patterns for authentication, defense-in-depth, input validation, OWASP Top 10, LLM safety, and PII masking. Use when implementing auth flows, security layers, input sanitization, vulnerability prevention, prompt injection defense, or data redaction.
Decision brief
Comprehensive security patterns for building hardened applications. Each category has individual rule files in rules/ loaded on-demand.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Declared | Source record | Install path and trigger |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/yonatangross/orchestkit --skill "src/skills/security-patterns"Inspect the Agent Skill "security-patterns" from https://github.com/yonatangross/orchestkit/blob/1ff988bd66daf223028ed44767b591fecc8510c2/src/skills/security-patterns/SKILL.md at commit 1ff988bd66daf223028ed44767b591fecc8510c2. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
Review the “Quick Start” section in the pinned source before continuing.
Total: 6 rule files across 4 categories. Topics marked "upstream" or "refs" keep only the ork delta here: floors and key decisions in this file, scars and house decisions in references/ork-delta.md, and first-party sources in Upstream coverage.
from argon2 import PasswordHasher ph = PasswordHasher() passwordhash = ph.hash(password) ph.verify(passwordhash, password) python
import jwt from datetime import datetime, timedelta, timezone payload = { 'sub': userid, 'type': 'access', 'exp': datetime.now(timezone.utc) + timedelta(minutes=15), } token = jwt.encode(payload, SECRETKEY, algorithm='HS256') typescript // Zod v4 schema validation import { z } f…
import re from langfuse import Langfuse
Permission review
The documentation asks the agent to read local files, directories, or repositories.
**CC 2.1.163 — home-path deny rules now cover `$HOME` Bash refs**: before this fix a `Read(~/.ssh/**)`-style deny rule blocked the Read tool but NOT a Bash command that reached the same file via `$HOME/.ssh/...` — a silent secrets-read bypaEvidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 91/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 224 | Source | Repository attention, not individual Skill quality |
| Compatibility | 1 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Comprehensive security patterns for building hardened applications. Each category has individual rule files in rules/ loaded on-demand.
| Category | Rules | Impact | When to Use |
|---|---|---|---|
| Authentication | upstream | CRITICAL | JWT tokens, OAuth 2.1/PKCE, RBAC/permissions |
| Defense-in-Depth | 1 | CRITICAL | Multi-layer security, zero-trust architecture |
| Input Validation | 2 | HIGH | Schema validation (Zod/Pydantic), output encoding, file uploads |
| OWASP Top 10 | 1 | CRITICAL | Injection prevention, broken authentication fixes |
| LLM Safety | refs | HIGH | Prompt injection defense, output guardrails, content filtering |
| PII Masking | refs | HIGH | PII detection/redaction with Presidio, Langfuse, LLM Guard |
| Scanning | upstream | HIGH | Dependency audit, SAST (Semgrep/Bandit), secret detection |
| Advanced Guardrails | 2 | CRITICAL | NeMo/Guardrails AI validators, red-teaming, OWASP LLM |
Total: 6 rule files across 4 categories. Topics marked "upstream" or "refs" keep only
the ork delta here: floors and key decisions in this file, scars and house decisions in
references/ork-delta.md, and first-party sources in
Upstream coverage.
# Argon2id password hashing
from argon2 import PasswordHasher
ph = PasswordHasher()
password_hash = ph.hash(password)
ph.verify(password_hash, password)
# JWT access token (15-min expiry)
import jwt
from datetime import datetime, timedelta, timezone
payload = {
'sub': user_id, 'type': 'access',
'exp': datetime.now(timezone.utc) + timedelta(minutes=15),
}
token = jwt.encode(payload, SECRET_KEY, algorithm='HS256')
// Zod v4 schema validation
import { z } from 'zod';
const UserSchema = z.object({
email: z.email(),
name: z.string().min(2).max(100),
role: z.enum(['user', 'admin']).default('user'),
});
const result = UserSchema.safeParse(req.body);
# PII masking with Langfuse
import re
from langfuse import Langfuse
def mask_pii(data, **kwargs):
if isinstance(data, str):
data = re.sub(r'\b[\w.-]+@[\w.-]+\.\w+\b', '[REDACTED_EMAIL]', data)
data = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[REDACTED_SSN]', data)
return data
langfuse = Langfuse(mask=mask_pii)
Secure authentication with OAuth 2.1, Passkeys/WebAuthn, JWT tokens, and role-based access control.
Implementation tutorials for JWT, OAuth 2.1/PKCE/DPoP, Passkeys/WebAuthn, RBAC, and MFA
are upstream-covered (see Upstream coverage). The
ork delta, including the argon2-cffi-over-passlib scar, lives in references/ork-delta.md.
Key Decisions: Argon2id > bcrypt | Access tokens 15 min | PKCE required | Passkeys > TOTP > SMS
Multi-layer security architecture with no single point of failure.
| Rule | Description |
|---|---|
defense-layers.md | 8-layer security architecture (edge to observability) |
Zero-trust and tenant-isolation implementation recipes (tenant-scoped repositories,
RLS, tenant-keyed caches) are upstream-covered; the immutable RequestContext pattern
survives in references/request-context-pattern.md and sanitized audit logging in
references/audit-logging.md.
Key Decisions: Immutable dataclass context | Query-level tenant filtering | No IDs in LLM prompts
sandbox.network.deniedDomains (CC 2.1.113+)Network-layer blocklist enforced before Bash/WebFetch egress — pair with the hook-layer DENY_PATTERNS for defense in depth. Settings example:
"sandbox": {
"network": {
"deniedDomains": ["*.evil.com", "pastebin.com", "transfer.sh"]
}
}
Wildcards supported (*.example.com, evil.com/*/malicious/*). Plugins ship a baseline list in src/settings/ork.settings.json; project settings can extend it. Use for: prompt-injection exfil sinks, known-bad registries, paste services that bypass audit.
sandbox.credentials (CC 2.1.187+)Blocks sandboxed Bash from reading credential files and secret env vars, defense-in-depth beside sandbox.filesystem.denyRead. Merged across scopes (any scope can add, none can remove); older CC ignores the key. mode is deny or, since CC 2.1.221, mask. Settings example:
"sandbox": {
"credentials": {
"files": [{ "path": "~/.aws/credentials", "mode": "deny" }],
"envVars": [{ "name": "GITHUB_TOKEN", "mode": "deny" }]
}
}
ork ships no sandbox.credentials baseline: CC reads only the permissions key from a plugin's settings file, so the block that used to live in src/settings/ork.settings.json was retired in #3357 as inert. Set it in your user or managed settings (deny ~/.aws/credentials, ~/.ssh, ~/.gnupg, ~/.netrc, ~/.npmrc plus the token env vars that can hijack git-push auth). Pair with CLAUDE_CODE_SUBPROCESS_ENV_SCRUB to scrub all subprocess credentials regardless of sandboxing.
Masking instead of denial. Since CC 2.1.221, a credential file entry can take mode: "mask" on Linux and WSL: the sandboxed command reads a sentinel copy (the whole file, or only the spans an extract regex captures) and the sandbox proxy substitutes the real value on egress. On macOS file masking falls back to deny, so on a Mac it buys nothing over mode: deny. The richer options arrived in CC 2.1.224: beyond mode: deny, credentials can be masked so the command still runs against a redacted value: extract plus onExtractNoMatch pulls a secret out of a structured env value, decode: "jwt" with maskClaims masks named JWT claims, and awsPairs/sigv4 re-signs AWS SigV4 requests after masking. Two constraints decide whether these are usable at all:
sandbox.network.tlsTerminate, so they only apply to traffic CC terminates.--settings. A value shipped by a plugin or set in project .claude/settings.json is ignored, so ork cannot ship these as a baseline the way it ships the deny list. Document them for operators; do not add them to src/settings/ork.settings.json expecting them to take effect.Never write a deny path with a trailing slash. Through CC 2.1.223, a sandbox.filesystem deny entry ending in / (for example denyRead: "~/.aws/") was silently bypassable on Linux and macOS: the rule parsed, reported clean, and protected nothing. Fixed in 2.1.224, but the shape is still worth avoiding because it reads as protection either way. ork's shipped values (~/.aws/credentials, ~/.ssh/*, ~/.gnupg/*) were never affected.
Validate and sanitize all untrusted input using Zod v4 and Pydantic.
| Rule | Description |
|---|---|
validation-input.md | Schema validation with Zod v4 and Pydantic, type coercion |
validation-output.md | HTML sanitization, output encoding, XSS prevention |
Advanced schema recipes (discriminated unions, file upload validation, URL allowlists)
and the full Zod v4 API are upstream-covered; the Zod v4-not-v3 trap list is in
references/ork-delta.md, and typed schema examples in scripts/validation-schemas.ts.
Key Decisions: Allowlist over blocklist | Server-side always | Validate magic bytes not extensions
Protection against the most critical web application security risks.
| Rule | Description |
|---|---|
supply-chain.md | Lockfile integrity, dependency confusion, provenance, SBOM (A03:2025) |
Injection prevention (SQL/command/SSRF) and broken-auth fixes (JWT algorithm confusion, CSRF, timing attacks) plus vulnerable-vs-secure demos are upstream-covered; see Upstream coverage.
Key Decisions: Parameterized queries only | Hardcode JWT algorithm | SameSite=Strict cookies
Security patterns for LLM integrations including context separation and output validation.
| Reference | Description |
|---|---|
references/context-separation.md | Context separation architecture, forbidden patterns |
references/prompt-audit.md | Prompt auditing, safe prompt builder |
references/output-guardrails.md | Output validation pipeline: schema, grounding, safety, size |
references/pre-llm-filtering.md | Tenant-scoped retrieval, content extraction |
references/post-llm-attribution.md | Deterministic attribution (three-phase pattern) |
Key Decisions: IDs flow around LLM, never through | Attribution is deterministic | Audit every prompt
Sensitive IDs and data flow AROUND the LLM, never through it. The LLM sees only content — mapping back to entities happens deterministically after.
# CORRECT: IDs bypass the LLM
context = {"user_id": user_id, "tenant_id": tenant_id} # kept server-side
llm_input = f"Summarize this document:\n{doc_text}" # no IDs in prompt
llm_output = call_llm(llm_input)
result = {"summary": llm_output, **context} # IDs reattached after
Every LLM response MUST pass a 4-stage guardrail pipeline before reaching the user:
def validate_llm_output(raw_output: str, schema, sources: list[str]) -> str:
# 1. Schema — does it match expected structure?
parsed = schema.parse(raw_output)
# 2. Grounding — are claims supported by source documents?
assert_grounded(parsed, sources)
# 3. Safety — toxicity, PII leakage, prompt leakage
assert_safe(parsed, max_toxicity=0.5)
# 4. Size — prevent token-bomb responses
assert len(parsed.text) < MAX_OUTPUT_CHARS
return parsed.text
PII detection and masking for LLM observability pipelines and logging.
| Reference | Description |
|---|---|
references/presidio-integration.md | Microsoft Presidio setup, custom recognizers |
references/langfuse-mask-callback.md | Langfuse SDK mask implementation |
LLM Guard Anonymize/Deanonymize with Vault and structlog/loguru redaction processors are upstream-covered; see Upstream coverage.
Key Decisions: Presidio for enterprise | Replace with type tokens | Use mask callback at init
Automated security scanning for dependencies, code, and secrets. Tool tutorials
(npm audit, pip-audit, Trivy, Semgrep, Bandit, Gitleaks, TruffleHog, detect-secrets)
are upstream-covered; the runnable house pipeline is scripts/scan-vulnerabilities.sh,
and the enforced-not-advisory repo gates (pre-push security suite, CI gitleaks) are
recorded in references/ork-delta.md.
Key Decisions: Pre-commit hooks for shift-left | Block on critical/high | Gitleaks + detect-secrets baseline
Production LLM safety with NeMo Guardrails, Guardrails AI validators, and DeepTeam red-teaming.
| Rule | Description |
|---|---|
guardrails-nemo.md | NeMo Guardrails, Colang 2.0 flows, Guardrails AI validators, layered validation |
guardrails-llm-validation.md | DeepTeam red-teaming (40+ vulnerabilities), OWASP LLM Top 10 compliance |
Key Decisions: NeMo for flows, Guardrails AI for validators | Toxicity 0.5 threshold | Red-team pre-release + quarterly
These topics were removed from this skill as vendor restatement. Consult the first-party
source; only the ork delta (floors, scars, house decisions) lives here, in
references/ork-delta.md.
| Topic | First-party source |
|---|---|
| JWT implementation + password hashing (PyJWT, Argon2id) | https://pyjwt.readthedocs.io/ + https://argon2-cffi.readthedocs.io/ |
| OAuth 2.1, PKCE, DPoP, Passkeys/WebAuthn flows | https://oauth.net/2.1/ + https://www.w3.org/TR/webauthn-3/ + https://github.com/duo-labs/py_webauthn |
| RBAC decorators, MFA/TOTP, rate limiting, auth checklists | OWASP Cheat Sheet Series: https://cheatsheetseries.owasp.org/ (Authentication, Session Management, MFA) |
| Zero-trust tenant isolation (tenant-scoped repos, RLS, tenant-keyed caches) | PostgreSQL RLS: https://www.postgresql.org/docs/current/ddl-rowsecurity.html + OWASP LLM08: https://genai.owasp.org/ |
| Zod v4 API + validation recipes (coercion, unions, file/URL schemas) | https://zod.dev (context7: /colinhacks/zod) + https://docs.pydantic.dev/ |
| OWASP Top 10 vulnerable-vs-secure examples (injection, XSS, CSRF, JWT confusion, timing) | https://owasp.org/Top10/ + https://cheatsheetseries.owasp.org/ |
| LLM prompt-injection defense + output guardrail tutorials | OWASP LLM Top 10: https://genai.owasp.org/llm-top-10/ |
| PII sanitization with LLM Guard (Anonymize/Deanonymize/Vault) | https://protectai.github.io/llm-guard/ |
| Pre-logging redaction with structlog/loguru | https://www.structlog.org/ + https://loguru.readthedocs.io/ |
| Dependency, secret, and SAST scanning tools | https://semgrep.dev/docs/ + https://github.com/gitleaks/gitleaks + https://trufflesecurity.com/trufflehog + https://bandit.readthedocs.io/ |
Plugin settings follow a 3-tier precedence:
| Tier | Source | Overridable? |
|---|---|---|
1. Managed (plugin settings.json) | Plugin author ships defaults | Yes, by user |
2. Project (.claude/settings.json) | Repository config | Yes, by user |
3. User (~/.claude/settings.json) | Personal preferences | Final authority |
Security hooks shipped by OrchestKit are managed defaults — users can disable them but are warned. Enterprise admins can lock settings via managed profiles.
CC 2.1.166 — managed-settings enforcement fix: before 2.1.166 a single invalid entry in managed settings silently disabled enforcement of all remaining valid policies — one typo could void your entire security lockdown. Require 2.1.166+ when relying on managed profiles, and validate the file before deploying it. The same release fixed
allowedMcpServers/deniedMcpServerspredicates not matching when they use${VAR}references.
CC 2.1.160 — write prompts: Claude Code now prompts before writing shell startup files (
.zshenv,.zlogin,.bash_login,~/.config/git/) and — underacceptEdits— build-tool configs that grant code execution (.npmrc,.yarnrc*,bunfig.toml,.bazelrc,.pre-commit-config.yaml,.devcontainer/). Treat these as defense-in-depth defaults: approve deliberately rather than blanket-allowing.
Permission-rule semantics (≥ 2.1.166):
allow/ask/denyrules gained security-relevant behavior —Readdeny now hides files from Glob/Grep, deny tool-names accept globs ("*"= default-deny), explicitWebFetch(domain:…)overrides the preapproved-host auto-allow, relayedSendMessagefrom other sessions carries no authority, and org-managed rules apply for the whole session. Seereferences/cc-permission-model.mdfor the full model + a recommended baselinesettings.json.
# Authentication
user.password = request.form['password'] # Plaintext password storage
response_type=token # Implicit OAuth grant (deprecated)
return "Email not found" # Information disclosure
# Input Validation
"SELECT * FROM users WHERE name = '" + name + "'" # SQL injection
if (file.type === 'image/png') {...} # Trusting Content-Type header
# LLM Safety
prompt = f"Analyze for user {user_id}" # ID in prompt
artifact.user_id = llm_output["user_id"] # Trusting LLM-generated IDs
# PII
logger.info(f"User email: {user.email}") # Raw PII in logs
langfuse.trace(input=raw_prompt) # Unmasked observability data
Load on demand with Read("${CLAUDE_PLUGIN_ROOT}/skills/security-patterns/references/<file>"):
| File | Content |
|---|---|
ork-delta.md | Ork-specific scars and house decisions rescued from removed upstream restatement |
cc-permission-model.md | CC allow/ask/deny rule semantics (≥2.1.166): Read-deny hides from Glob/Grep, deny-globs, WebFetch precedence, cross-session auth, org-managed rules |
request-context-pattern.md | Immutable request context for identity flow |
audit-logging.md | Sanitized structured logging, compliance |
context-separation.md | LLM context separation architecture |
output-guardrails.md | Output validation pipeline implementation |
pre-llm-filtering.md | Tenant-scoped retrieval, content extraction |
post-llm-attribution.md | Deterministic attribution pattern |
prompt-audit.md | Prompt audit patterns, safe prompt builder |
presidio-integration.md | Microsoft Presidio setup, custom recognizers |
langfuse-mask-callback.md | Langfuse SDK mask implementation |
api-design-framework - API security patternsork:rag-retrieval - RAG pipeline patterns requiring tenant-scoped retrievalllm-evaluation - Output quality assessment including hallucination detectionKeywords: password, hashing, JWT, token, OAuth, PKCE, passkey, WebAuthn, RBAC, session Solves:
Keywords: defense in depth, security layers, multi-layer, request context, tenant isolation Solves:
Keywords: subprocess, sandbox, PID namespace, env scrub, script caps Solves:
CLAUDE_CODE_SCRIPT_CAPS=100CLAUDE_CODE_SUBPROCESS_ENV_SCRUB=1CC 2.1.128 — SDK host "Always allow" persistence: when a user picks "Always allow" from a Bash permission prompt in an SDK host, the grant now persists via
.claude/settings.local.jsoninstead of evaporating at session end. Audit your SDK consumers'.gitignoreto confirm.claude/settings.local.jsonis excluded — committing it leaks per-developer Bash auth grants. Project-committed.claude/settings.jsonis unchanged; only the user-machine-local file receives the new entries.
CC 2.1.169 — managed MCP enforcement + OTEL cert-path trust: two policy-bypass classes closed. Enterprise
allowedMcpServers/deniedMcpServerspolicies were NOT enforced on reconnect, IDE-typed configs,--mcp-configservers in the first post-install session, or before remote settings loaded — treat any pre-2.1.169 managed-MCP audit as incomplete on those paths. And untrusted project settings could set OTEL client-certificate paths without trust confirmation (a cloned repo could point telemetry at an attacker cert); now gated behind trust. Both fixes are active at ork's floor (2.1.220).
CC 2.1.163 — home-path deny rules now cover
$HOMEBash refs: before this fix aRead(~/.ssh/**)-style deny rule blocked the Read tool but NOT a Bash command that reached the same file via$HOME/.ssh/...— a silent secrets-read bypass. If you gate home-directory secrets (e.g.~/.aws/credentials,~/.ssh/*,~/.gnupg/*) through permission deny rules, pin your CC floor to>= 2.1.163; older builds (< 2.1.163) leave the Bash path open — ork's floor is now2.1.220, which already includes this fix.
Keywords: schema, validate, Zod, Pydantic, sanitize, HTML, XSS, file upload Solves:
Keywords: OWASP, sql injection, broken access control, CSRF, XSS, SSRF Solves:
Keywords: prompt injection, context separation, guardrails, hallucination, LLM output Solves:
Keywords: PII, masking, Presidio, Langfuse, redact, GDPR, privacy Solves:
Frequently asked questions
Comprehensive security patterns for building hardened applications. Each category has individual rule files in rules/ loaded on-demand.
The source record exposes this install command: npx skills add https://github.com/yonatangross/orchestkit --skill "src/skills/security-patterns". Inspect the command and pinned source before running it.
The pinned source record declares support for: claude code.
Static rules flagged read-files in the source; the page lists the matching lines and excerpts.
Alternatives
aaron-he-zhu/aaron-marketing-skills
Use when the user asks to "set up my founder social-selling routine", "build a daily engagement block for target accounts", or "turn funding / hiring signals into selling plays"; produces the founder/seller daily operating block — a time-boxed engagement-block spec (substantive value-add comments on target-account posts, never a pitch), warm-touch-before-ask cadence rules, trigger-response plays consuming the social-pulse-monitor B2B trigger watchlist (funding / hiring / launch signals), and a q
oaustegard/claude-skills
Generate hierarchical _FEATURES.md files that describe what a codebase DOES from a user/consumer perspective, anchored to source symbols via tree-sitting. Supports large complex codebases through feature-driven decomposition into sub-feature files. Uses a multi-pass synthesis: orientation → detail → overview rewrite. Use when someone says "what does this do", "document features", "feature inventory", "_FEATURES.md", or needs to understand a codebase's purpose before modifying it. Complements tre
apollographql/skills
Guide for creating effective skills for Apollo GraphQL and GraphQL development. Use this skill when: (1) users want to create a new skill, (2) users want to update an existing skill, (3) users ask about skill structure or best practices, (4) users need help writing SKILL.md files.
terrylica/cc-skills
Park a draft message/text in macOS Notes for the operator to review and edit, then read it back before acting (e.g. before sending to a real person). Notes is the source of truth (AppleScript CRUD, iCloud-synced, provenance-stamped with the Claude Code session UUID); Stickies is a best-effort view-only desktop mirror. Use whenever you draft something a human should confirm/edit before it is sent or committed — messages, replies, announcements, anything outbound. TRIGGERS - park this draft, park