Agent skill
triatu-security
Security practices for Triatu. Use when adding data access, Server Actions, logging, or Supabase policies, and when reviewing security risks.
Stars
163
Forks
31
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/data/triatu-security
SKILL.md
Triatu Security
Quick start
- Validate inputs with Zod before any infrastructure call.
- Apply rate limiting in critical Server Actions.
- Avoid PII in logs; use
lib/loggeranddebugonly in dev. - Rely on Supabase RLS for data isolation.
Workflow
- Identify entry points (Server Actions or route handlers).
- Add Zod validation for inputs.
- Add rate limiting where abuse is possible.
- Use security logging for suspicious events.
- Ensure adapters enforce least-privilege access.
- Record new risks in
docs/PROJECT_AUDIT.md.
References
docs/SECURITY.mddocs/DEVELOPMENT.mddocs/PROJECT_AUDIT.md
Didn't find tool you were looking for?