Skip to content

Pack · v0.1.0

Security engineer (application security checklist)

AI coding-agent instructions for: Application-security work for web/API projects: threat modelling, an OWASP Top 10:2025 review, authorization (IDOR) tests, dependency and secret…

About this pack

AI coding-agent instructions for: Application-security work for web/API projects: threat modelling, an OWASP Top 10:2025 review, authorization (IDOR) tests, dependency and secret hygiene, with small tested tools instead of just advice.

What is inside (20 files)

  • .cursor/rules/00-core.mdc
  • .cursor/rules/10-security.mdc
  • AGENTS.md
  • CLAUDE.md
  • CONTRIBUTING.md
  • LICENSE
  • README.md
  • docs/SOURCES.md
  • docs/STARTER_CHECKLIST.md
  • skills/accessibility-audit/SKILL.md
  • skills/authz-and-idor-testing/SKILL.md
  • skills/owasp-top10-review/SKILL.md
  • skills/supply-chain-and-secrets/SKILL.md
  • skills/threat-model-review/SKILL.md
  • templates/eslint.config.mjs
  • templates/fixtures/bad.js
  • templates/fixtures/good.js
  • templates/scripts/scan-secrets.mjs
  • templates/src/invoices.mjs
  • templates/test/security.test.mjs

Good to know

How do I get it?
Sign in, pay once with Stripe Checkout, then download the zip from My library. Links are short-lived; you can re-download any time.
Does it work with my agent?
Packs use plain AGENTS.md, CLAUDE.md, Cursor rules and SKILL.md files, so any agent that reads those formats can use them.
Are claims verified?
Unverified items are labelled [UNVERIFIED] inside each pack. Not affiliated with any tool or engine vendor.

Related