·csrf-protection
!

csrf-protection

harperaa/secure-claude-skills

Implement Cross-Site Request Forgery (CSRF) protection for API routes.当您需要保护 POST/PUT/DELETE 端点、实施令牌验证、防止跨站点攻击或安全表单提交时,请使用此技能。 Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation".

9安装·0热度·@harperaa

安装

$npx skills add https://github.com/harperaa/secure-claude-skills --skill csrf-protection

SKILL.md

Imagine you're logged into your banking app. In another tab, you visit a malicious website. That website contains hidden code that submits a form to your bank: "Transfer $10,000 to attacker's account." Because you're logged in, your browser automatically sends your session cookie, and the bank processes the transfer.

This is Cross-Site Request Forgery—tricking your browser into making requests you didn't intend.

Router DNS Hijacking (2008): A CSRF vulnerability in several home routers allowed attackers to change router DNS settings by tricking users into visiting a malicious website. Victims lost no money but were redirected to phishing sites for months. Millions of routers were affected.

Implement Cross-Site Request Forgery (CSRF) protection for API routes.当您需要保护 POST/PUT/DELETE 端点、实施令牌验证、防止跨站点攻击或安全表单提交时,请使用此技能。 Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation". 来源:harperaa/secure-claude-skills。

查看原文

可引用信息

为搜索与 AI 引用准备的稳定字段与命令。

安装命令
npx skills add https://github.com/harperaa/secure-claude-skills --skill csrf-protection
分类
!安全工具
认证
收录时间
2026-02-01
更新时间
2026-02-18

快速解答

什么是 csrf-protection?

Implement Cross-Site Request Forgery (CSRF) protection for API routes.当您需要保护 POST/PUT/DELETE 端点、实施令牌验证、防止跨站点攻击或安全表单提交时,请使用此技能。 Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation". 来源:harperaa/secure-claude-skills。

如何安装 csrf-protection?

打开你的终端或命令行工具(如 Terminal、iTerm、Windows Terminal 等) 复制并运行以下命令:npx skills add https://github.com/harperaa/secure-claude-skills --skill csrf-protection 安装完成后,技能将自动配置到你的 AI 编程环境中,可以在 Claude Code 或 Cursor 中使用

这个 Skill 的源码在哪?

https://github.com/harperaa/secure-claude-skills

详情

分类
!安全工具
来源
skills.sh
收录时间
2026-02-01