Software Security And AppSec
Use this skill for application-layer security: authentication, authorization, input and output handling, cryptography, supply-chain controls, API security, threat modeling, and security reviews. It is the AppSec decision layer, not general backend or infrastructure hardening.
Quick Reference
| Task |
Use |
| Risk-category framing |
references/owasp-top-10.md |
| Auth and authorization choices |
references/authentication-authorization.md, assets/web-application/template-authentication.md, assets/web-application/template-authorization.md |
| Input handling, uploads, rendering, and common bugs |
references/input-validation.md, references/common-vulnerabilities.md |
| Secure design and threat modeling |
references/secure-design-principles.md, references/threat-modeling-guide.md |
| API and supply-chain security |
references/api-security-patterns.md, references/supply-chain-security.md, assets/api/template-secure-api.md |
| Crypto, password hashing, and transport choices |
references/cryptography-standards.md |
| Agentic, LLM, and MCP application design |
references/agentic-llm-appsec.md (testing lives in qa-security-testing) |
| Mobile secure storage, pinning policy, attestation |
assets/mobile/template-mobile-security.md |
| Secret-storage selection |
See "Secret-Storage Selection" below — choosing encrypted vs plaintext at the provider, and how to verify after storing |
| Incident response and security program framing |
references/incident-response-playbook.md, references/security-business-value.md, references/operational-playbook.md |