⚡AgentSkills
⚙️ Backend Engineering · Auth & Security Basics

Validate all external input at the boundary

Parse, don't validate: coerce untrusted input into typed values once at the edge.

foundation~25 minBackend EngineersAPI DevelopersPlatform Engineers

Steps

  1. 1Define schemas per endpoint covering body, query, params, headers
  2. 2Reject unknown fields by default; allowlists beat blocklists
  3. 3Coerce types explicitly; fail closed on ambiguity
  4. 4Return field-level errors machines can render
  5. 5Reuse the same schemas for client-side forms where possible
  6. 6Fuzz one nasty payload corpus against public endpoints in CI

Common Pitfalls

  • ▲Validating in UI but trusting raw req.body server-side
  • ▲Mass assignment from spreads straight into ORM updates

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill auth-security-input-validation-zod
Install globally
$ npx skills add aniruddhaadak80/skills --skill auth-security-input-validation-zod -g

Tags

#validation#security#backend-engineering#auth-security

Related skills

Cookies, rotation, and revocation done right for server-rendered apps.

⚙️ Backend Engineering·~35m