API security keeps your data safe from attacks. This skill shows you how to add authentication, rate limiting, and input validation to your REST APIs. You will learn to use security middleware like Helmet and CORS. Protect your endpoints from common threats like XSS and injection attacks.
This guide is for anyone building or updating APIs. Whether you are starting a new project or hardening a production system, these practices help meet compliance standards and secure high-traffic services. Follow the quick start example to add layers of defense quickly.
The reference guides cover Node.js, Python FastAPI, and API Gateway configurations. Use the best practices checklist to avoid common mistakes. Strong security means safer apps and happier users.
Global
mkdir -p ~/.claude/skills/api-security-hardeningProject
mkdir -p .claude/skills/api-security-hardeningSource Repository
Azure Compliancemicrosoft/azure-skills
Audit Azure compliance and Key Vault expiration with azqr scans
Firebase Security Rules Auditorfirebase/agent-skills
Find weak spots in Firestore rules and get clear fixes
Golang Securitysamber/cc-skills-golang
Find and fix security flaws in Go code using expert guidance and automated tools
Clerk Nextjs Patternsclerk/skills
Secure your Next.js app with Clerk middleware, server actions, and caching
Persona It Admingoogleworkspace/cli
Keep your digital workspace safe with IT admin security workflows
Two Factor Authentication Best Practicesbetter-auth/skills
Secure user logins with two-factor authentication using Better Auth
Gws Modelarmor Create Templategoogleworkspace/cli
Create new templates for Google Model Armor to protect AI apps from harmful content
Gws Modelarmor Sanitize Promptgoogleworkspace/cli
Clean user prompts safely with Google Model Armor templates