mirror of
https://github.com/cursor/plugins.git
synced 2026-09-14 20:00:00 +08:00
97128c02db
- Convert all H1 headings to sentence case across skills, rules, agents, commands, and READMEs (~65 headings) - Replace em-dashes with colons in plugin.json descriptions and README taglines to match marketplace.json convention - Replace semicolons with periods and restructure sentences across skills, rules, agents, and READMEs (~19 instances) Co-authored-by: Cursor <cursoragent@cursor.com>
13 lines
469 B
Plaintext
13 lines
469 B
Plaintext
---
|
|
alwaysApply: true
|
|
---
|
|
|
|
# Security review checklist
|
|
|
|
1. Validate and sanitize untrusted input at trust boundaries.
|
|
2. Confirm authorization checks exist for sensitive actions and resource access.
|
|
3. Check for unsafe dynamic execution patterns (shell, SQL, template rendering).
|
|
4. Ensure secrets are never hardcoded or logged.
|
|
5. Verify security-relevant errors do not leak sensitive internals.
|
|
6. Prefer safe defaults and fail-closed behavior for permission checks.
|