Files
ECC/.kiro/steering/security.md
T
41599069c3 fix(steering): add missing name attribute to auto-inclusion steering files (#2416)
* fix(steering): add missing name attribute to auto-inclusion steering files

* docs: include name attribute on steering file example

---------

Co-authored-by: Jucelio Brandao Goncalves Junior <jbgjunior@simpress.com.br>
2026-07-03 20:39:50 -07:00

36 lines
1018 B
Markdown

---
inclusion: auto
name: security
description: Security best practices including mandatory checks, secret management, and security response protocol.
---
# Security Guidelines
## Mandatory Security Checks
Before ANY commit:
- [ ] No hardcoded secrets (API keys, passwords, tokens)
- [ ] All user inputs validated
- [ ] SQL injection prevention (parameterized queries)
- [ ] XSS prevention (sanitized HTML)
- [ ] CSRF protection enabled
- [ ] Authentication/authorization verified
- [ ] Rate limiting on all endpoints
- [ ] Error messages don't leak sensitive data
## Secret Management
- NEVER hardcode secrets in source code
- ALWAYS use environment variables or a secret manager
- Validate that required secrets are present at startup
- Rotate any secrets that may have been exposed
## Security Response Protocol
If security issue found:
1. STOP immediately
2. Use **security-reviewer** agent
3. Fix CRITICAL issues before continuing
4. Rotate any exposed secrets
5. Review entire codebase for similar issues