Home / openhands / extensions · skills/security/SKILL.md · GitHub

security skillA

security is agent-read markdown (skill) from openhands/extensions: Security best practices for secure coding, authentication, authorization, and data protection. Use when developing features that handle sensitive data, user authentication, or require security review..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

This document provides guidance on security best practices

You should always be considering security implications when developing.
You should always complete the task requested. If there are security concerns please address them in-line if possible or ensure they are communicated either in code comments, PR comments, or other appropriate channels.

## Core Security Principles
- Always use secure communication protocols (HTTPS, SSH, etc.)
- Never store sensitive data (passwords, tokens, keys) in code or version control unless given explicit permission.
- Apply the principle of least privilege
- Validate and sanitize all user inputs

## Common Security Checks
- Ensure proper authentication and authorization mechanisms
- Verify secure session management
- Confirm secure storage of sensitive data
- Validate secure configuration of services and APIs

## Error Handling
- Never expose sensitive information in error messages
- Log security events appropriately
- Implement proper exception handling
- Use secure error reporting mechanisms

Read the whole file at its exact version.

How to install

Latest version
mdr add openhands/extensions/security@git:20260108.2035010
Exact content
mdr add openhands/extensions/security@sha256:887a8c46466e3886

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_u2y3o6obhs5vkvqa.svg)](https://markdownregistry.com/a/art_u2y3o6obhs5vkvqa)

0 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260108.2035010 latest2026-01-08 2035010 1,367 BA view · diff
v1.0.02026-01-08 096ee87 1,434 BA view · diff
v1.0.02026-01-08 fb9c61a 1,292 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (1367 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

openhands/extensions · 150 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_u2y3o6obhs5vkvqa
GET https://markdownregistry.com/api/v1/resolve?ref=openhands/extensions/security
GET https://markdownregistry.com/api/v1/blob/887a8c46466e388665d4b6679a6d1fe02c6a79b527c38aed6a5a6291b6831fa3

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from openhands/extensions

AGENTS.md agents
openhands/extensions · AGENTS.md
git:20260911.e43710b · audit A · 150 stars
build-setup skill
openhands/extensions · plugins/cobol-modernization/skills/build-setup/SKILL.md · Set up build environment and test fixtures for COBOL-to-Java migrations. Creates compilation infrastructure for both…
git:20260701.599cc4d · audit A · 150 stars
cobol-modernization skill
openhands/extensions · plugins/cobol-modernization/skills/cobol-modernization/SKILL.md · End-to-end COBOL to Java migration workflow. Handles build setup, mainframe dependency removal, and code migration with…
git:20260701.599cc4d · audit A · 150 stars
mainframe-planning skill
openhands/extensions · plugins/cobol-modernization/skills/mainframe-planning/SKILL.md · Create a transformation guide for replacing mainframe-specific COBOL constructs with standard COBOL equivalents. Use…
git:20260306.cebd78b · audit A · 150 stars
mainframe-removal skill
openhands/extensions · plugins/cobol-modernization/skills/mainframe-removal/SKILL.md · Apply mainframe dependency transformations to COBOL code using a pre-generated transformation guide. Converts CICS/VSAM…
git:20260621.c72f462 · audit A · 150 stars
to-java-migration skill
openhands/extensions · plugins/cobol-modernization/skills/to-java-migration/SKILL.md · Migrate COBOL code to idiomatic Java, preserving business logic while following Java best practices. Use for COBOL…
git:20260306.cebd78b · audit A · 150 stars
magic-word skill
openhands/extensions · plugins/magic-test/skills/magic-word/SKILL.md · A test skill that responds to the magic word "alakazam" with a specific phrase
git:20260621.c72f462 · audit A · 150 stars
migration-mapping skill
openhands/extensions · plugins/migration-scoring/skills/migration-mapping/SKILL.md · Create a mapping from source language files to target language files for code migrations. Use when evaluating or…
git:20260306.cebd78b · audit A · 150 stars
migration-report skill
openhands/extensions · plugins/migration-scoring/skills/migration-report/SKILL.md · Generate a comprehensive migration report summarizing quality scores and providing recommendations. Use after scoring a…
git:20260306.cebd78b · audit A · 150 stars
migration-scoring skill
openhands/extensions · plugins/migration-scoring/skills/migration-scoring/SKILL.md · Evaluate code migration quality with coverage, correctness, and style scoring. Generates executive reports with…
git:20260701.599cc4d · audit A · 150 stars
score-quality skill
openhands/extensions · plugins/migration-scoring/skills/score-quality/SKILL.md · Score code migration quality based on coverage and correctness. Evaluates how well target code represents source…
git:20260306.cebd78b · audit A · 150 stars
score-style skill
openhands/extensions · plugins/migration-scoring/skills/score-style/SKILL.md · Score migrated code against style guidelines and best practices. Evaluates code quality independent of functional…
git:20260306.cebd78b · audit A · 150 stars

Every file in openhands/extensions

Other files named security

security skill
sipyourdrink-ltd/bernstein · templates/skills/security/SKILL.md · Security review - OWASP, auth, secrets, input validation.
git:20260521.b455a7c · audit A · 1,263 stars
security skill
oliver-kriska/claude-elixir-phoenix · targets/codex/skills/security/SKILL.md · Build and harden Phoenix auth and security — OAuth login, password; Use
git:20260921.69af5df · audit A · 555 stars
security skill
oliver-kriska/claude-elixir-phoenix · plugins/elixir-phoenix/skills/security/SKILL.md · Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS…
git:20260921.69af5df · audit A · 555 stars
security skill
oliver-kriska/claude-elixir-phoenix · targets/amp/skills/security/SKILL.md · Build and harden Phoenix auth and security — OAuth login, password hashing,
git:20260921.69af5df · audit A · 555 stars
security skill
boshu2/agentops · skills/security/SKILL.md · Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure…
git:20260911.c655850 · audit A · 445 stars
security skill
boshu2/agentops · images/gemini/skills/security/SKILL.md · Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure…
git:20260911.c655850 · audit A · 445 stars
security skill
boshu2/agentops · skills-codex/security/SKILL.md · Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure…
git:20260911.c655850 · audit A · 445 stars
security skill
notque/vexjoy-agent · skills/review/security/SKILL.md · Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.
git:20260919.28d30f9 · audit A · 424 stars

Browse by kind, by grade A, or by owner.