Spot security footguns in an API design

Reviews an API, config schema, or library interface for footguns—calls that are easy to get wrong, defaults that leak risk, or patterns that punish the secure choice.

Best for: Engineers shipping an API who want to find the painful or dangerous parts before users do.

Engineering / code-reviewatomicfor-engineersno-setupfrom-text

Topics

agent-skills

Source

Creator's repository · trailofbits/skills

View on GitHub

License: CC-BY-SA-4.0