home / skills / pluginagentmarketplace / custom-plugin-python / security
This skill helps you write secure Python code by applying OWASP-aligned practices, preventing vulnerabilities, and auditing dependencies.
npx playbooks add skill pluginagentmarketplace/custom-plugin-python --skill securityReview the files below or copy the command above to add this skill to your agents.
---
name: Security
description: Python security best practices, OWASP, and vulnerability prevention
version: "2.1.0"
sasmp_version: "1.3.0"
bonded_agent: 07-best-practices
bond_type: PRIMARY_BOND
# Skill Configuration
retry_strategy: exponential_backoff
observability:
logging: true
metrics: vulnerability_count
---
# Python Security Skill
## Overview
Implement secure Python code practices and protect applications from common vulnerabilities.
## Topics Covered
### Common Vulnerabilities
- SQL injection prevention
- Command injection
- Path traversal
- Deserialization attacks
- SSRF vulnerabilities
### Secure Coding
- Input validation
- Output encoding
- Secure file handling
- Secrets management
- Environment variables
### Authentication
- Password hashing (bcrypt, argon2)
- JWT implementation
- Session security
- OAuth integration
- API key management
### Dependency Security
- pip audit usage
- Safety scanner
- Snyk for Python
- Dependabot setup
- Vulnerability databases
### Security Testing
- Bandit static analysis
- Security unit tests
- Penetration testing basics
- SAST/DAST tools
- Code review checklist
## Prerequisites
- Python fundamentals
- Web development basics
## Learning Outcomes
- Write secure Python code
- Prevent common attacks
- Audit dependencies
- Implement authentication securely
This skill teaches practical Python security best practices and guided defenses against common vulnerabilities like SQL injection, SSRF, and deserialization attacks. It focuses on secure coding patterns, dependency auditing, and hardening authentication flows so you can reduce risk in real projects. Content is pragmatic and geared toward developers who already know Python and basic web concepts.
The skill inspects application layers and recommends concrete changes: input validation, output encoding, safe file and secret handling, and secure session/token handling. It also integrates dependency security tools (pip-audit, Safety, Snyk) and static analysis (Bandit) into a repeatable workflow for ongoing vulnerability detection. You get checklists, code patterns, and testing guidance to verify fixes and reduce false positives.
Is this skill suitable for beginners?
It assumes basic Python and web development knowledge; beginners can follow along but may need foundational learning first.
Which tools should I run in CI?
Run pip-audit or Safety for dependencies and Bandit for static code checks; optionally include Snyk or a commercial scanner for continuous monitoring.