csrf-protection
✓Implement Cross-Site Request Forgery (CSRF) protection for API routes.当您需要保护 POST/PUT/DELETE 端点、实施令牌验证、防止跨站点攻击或安全表单提交时,请使用此技能。 Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation".
SKILL.md
Imagine you're logged into your banking app. In another tab, you visit a malicious website. That website contains hidden code that submits a form to your bank: "Transfer $10,000 to attacker's account." Because you're logged in, your browser automatically sends your session cookie, and the bank processes the transfer.
This is Cross-Site Request Forgery—tricking your browser into making requests you didn't intend.
Router DNS Hijacking (2008): A CSRF vulnerability in several home routers allowed attackers to change router DNS settings by tricking users into visiting a malicious website. Victims lost no money but were redirected to phishing sites for months. Millions of routers were affected.
Implement Cross-Site Request Forgery (CSRF) protection for API routes.当您需要保护 POST/PUT/DELETE 端点、实施令牌验证、防止跨站点攻击或安全表单提交时,请使用此技能。 Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation". 来源:harperaa/secure-claude-skills。
可引用信息
为搜索与 AI 引用准备的稳定字段与命令。
- 安装命令
npx skills add https://github.com/harperaa/secure-claude-skills --skill csrf-protection- 分类
- !安全工具
- 认证
- ✓
- 收录时间
- 2026-02-01
- 更新时间
- 2026-02-18
快速解答
什么是 csrf-protection?
Implement Cross-Site Request Forgery (CSRF) protection for API routes.当您需要保护 POST/PUT/DELETE 端点、实施令牌验证、防止跨站点攻击或安全表单提交时,请使用此技能。 Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation". 来源:harperaa/secure-claude-skills。
如何安装 csrf-protection?
打开你的终端或命令行工具(如 Terminal、iTerm、Windows Terminal 等) 复制并运行以下命令:npx skills add https://github.com/harperaa/secure-claude-skills --skill csrf-protection 安装完成后,技能将自动配置到你的 AI 编程环境中,可以在 Claude Code 或 Cursor 中使用
这个 Skill 的源码在哪?
https://github.com/harperaa/secure-claude-skills
详情
- 分类
- !安全工具
- 来源
- skills.sh
- 收录时间
- 2026-02-01