Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
davila7 avatar

Senior Security

  • 880 installs
  • 29.9k repo stars
  • Updated July 27, 2026
  • davila7/claude-code-templates

senior-security is a secure-coding skill that provides cryptography patterns, anti-pattern guidance, and implementation examples for developers implementing authentication, data protection, or sensitive operations.

About

senior-security is a reference skill from davila7/claude-code-templates focused on cryptography implementation and senior-level secure coding practices. It documents patterns with descriptions, when-to-use scenarios, TypeScript implementation examples, benefits, and trade-offs so agents apply vetted approaches instead of inventing crypto primitives. Developers reach for senior-security when building login flows, token handling, encryption at rest or in transit, or any sensitive operation where a mistake is costly. The skill emphasizes best-practice implementations and flags common anti-patterns across multiple pattern sections. It complements llm-security, which targets OWASP LLM threats, by focusing on general application cryptography and secure engineering discipline.

  • Comprehensive senior-level cryptography and security pattern reference
  • Includes When-to-Use scenarios, full TypeScript implementations, benefits, and trade-offs for each pattern
  • Covers code organization, performance considerations, security best practices, and common patterns (A, B, C)
  • Explicit anti-patterns section to help avoid costly security mistakes
  • Recommended tools and resources section for ongoing reference

Senior Security by the numbers

  • 880 all-time installs (skills.sh)
  • +24 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #403 of 2,209 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
npx skills add https://github.com/davila7/claude-code-templates --skill senior-security

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs880
repo stars29.9k
Security audit3 / 3 scanners passed
Last updatedJuly 27, 2026
Repositorydavila7/claude-code-templates

How do you implement cryptography without common mistakes?

Get battle-tested cryptography patterns, secure coding practices, and anti-pattern guidance when implementing authentication, data protection, or sensitive operations.

Who is it for?

Backend and full-stack developers implementing auth, encryption, or secrets handling who want pattern-level guidance during codegen.

Skip if: Pure LLM prompt-injection or RAG abuse cases should use llm-security rather than senior-security cryptography patterns.

When should I use this skill?

A developer implements authentication, encryption, key management, or asks for secure coding or cryptography best practices.

What you get

Secure TypeScript implementations, documented crypto patterns, and anti-pattern guidance for authentication and data-protection code.

  • Secure implementation examples
  • Documented crypto pattern choices

Files

SKILL.mdMarkdownGitHub ↗

Senior Security

Complete toolkit for senior security with modern tools and best practices.

Quick Start

Main Capabilities

This skill provides three core capabilities through automated scripts:

# Script 1: Threat Modeler
python scripts/threat_modeler.py [options]

# Script 2: Security Auditor
python scripts/security_auditor.py [options]

# Script 3: Pentest Automator
python scripts/pentest_automator.py [options]

Core Capabilities

1. Threat Modeler

Automated tool for threat modeler tasks.

Features:

  • Automated scaffolding
  • Best practices built-in
  • Configurable templates
  • Quality checks

Usage:

python scripts/threat_modeler.py <project-path> [options]

2. Security Auditor

Comprehensive analysis and optimization tool.

Features:

  • Deep analysis
  • Performance metrics
  • Recommendations
  • Automated fixes

Usage:

python scripts/security_auditor.py <target-path> [--verbose]

3. Pentest Automator

Advanced tooling for specialized tasks.

Features:

  • Expert-level automation
  • Custom configurations
  • Integration ready
  • Production-grade output

Usage:

python scripts/pentest_automator.py [arguments] [options]

Reference Documentation

Security Architecture Patterns

Comprehensive guide available in references/security_architecture_patterns.md:

  • Detailed patterns and practices
  • Code examples
  • Best practices
  • Anti-patterns to avoid
  • Real-world scenarios

Penetration Testing Guide

Complete workflow documentation in references/penetration_testing_guide.md:

  • Step-by-step processes
  • Optimization strategies
  • Tool integrations
  • Performance tuning
  • Troubleshooting guide

Cryptography Implementation

Technical reference guide in references/cryptography_implementation.md:

  • Technology stack details
  • Configuration examples
  • Integration patterns
  • Security considerations
  • Scalability guidelines

Tech Stack

Languages: TypeScript, JavaScript, Python, Go, Swift, Kotlin Frontend: React, Next.js, React Native, Flutter Backend: Node.js, Express, GraphQL, REST APIs Database: PostgreSQL, Prisma, NeonDB, Supabase DevOps: Docker, Kubernetes, Terraform, GitHub Actions, CircleCI Cloud: AWS, GCP, Azure

Development Workflow

1. Setup and Configuration

# Install dependencies
npm install
# or
pip install -r requirements.txt

# Configure environment
cp .env.example .env

2. Run Quality Checks

# Use the analyzer script
python scripts/security_auditor.py .

# Review recommendations
# Apply fixes

3. Implement Best Practices

Follow the patterns and practices documented in:

  • references/security_architecture_patterns.md
  • references/penetration_testing_guide.md
  • references/cryptography_implementation.md

Best Practices Summary

Code Quality

  • Follow established patterns
  • Write comprehensive tests
  • Document decisions
  • Review regularly

Performance

  • Measure before optimizing
  • Use appropriate caching
  • Optimize critical paths
  • Monitor in production

Security

  • Validate all inputs
  • Use parameterized queries
  • Implement proper authentication
  • Keep dependencies updated

Maintainability

  • Write clear code
  • Use consistent naming
  • Add helpful comments
  • Keep it simple

Common Commands

# Development
npm run dev
npm run build
npm run test
npm run lint

# Analysis
python scripts/security_auditor.py .
python scripts/pentest_automator.py --analyze

# Deployment
docker build -t app:latest .
docker-compose up -d
kubectl apply -f k8s/

Troubleshooting

Common Issues

Check the comprehensive troubleshooting section in references/cryptography_implementation.md.

Getting Help

  • Review reference documentation
  • Check script output messages
  • Consult tech stack documentation
  • Review error logs

Resources

  • Pattern Reference: references/security_architecture_patterns.md
  • Workflow Guide: references/penetration_testing_guide.md
  • Technical Guide: references/cryptography_implementation.md
  • Tool Scripts: scripts/ directory

Related skills

How it compares

Use senior-security for crypto and auth implementation patterns; use llm-security for LLM-specific threat models.

FAQ

What does senior-security cover?

senior-security covers cryptography implementation patterns, secure coding practices, and anti-pattern guidance for authentication and data protection. Each pattern includes TypeScript examples, benefits, and trade-offs.

How is senior-security different from llm-security?

senior-security focuses on general cryptography and secure application coding. llm-security addresses OWASP Top 10 for LLM Applications such as prompt injection in agent and RAG systems.

Is Senior Security safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.