Use Security Best Practices safely

OpenAI's Security Best Practices skill reviews Python, JS/TS, and Go code for security issues and gives concrete guidance.

Published on 09.09.2026

What the Security Best Practices skill does

The Security Best Practices skill comes from OpenAI's official openai/skills repository, where it lives in the project's curated section. According to the provider, the skill performs language- and framework-specific security best-practice reviews and suggests concrete improvements. It is designed to trigger specifically when users explicitly ask for security best-practice guidance, a security review or report, or help with secure-by-default coding. According to the documentation, it is explicitly not meant for general code review, debugging, or other non-security tasks, which is intended to avoid unwanted triggering. Currently supported languages are Python, JavaScript/TypeScript, and Go.

How it works: detection, references, and application

The skill's workflow begins by identifying all languages and frameworks used in the current project context, and according to the documentation both frontend and backend technologies should be considered. It then searches an internal references directory for matching documents whose filenames follow a fixed pattern of language, framework, and deployment area, for example for a specific language-framework combination or for general, framework-agnostic recommendations for a language. If matching reference files are found, the skill reads them completely before starting an assessment or writing new code. If no reference exists for a particular combination, the skill, per the description, falls back on generally known security principles or, when uncertain, additionally researches the topic online.

Three operating modes in practice

After gathering information, the skill can operate in three different modes. In the first, primary mode, it uses the gathered knowledge immediately to write secure code from the outset, which is particularly suited to new projects or newly added features. In the second mode, it acts passively in the background during ongoing development work and flags critical or especially severe violations of the security guidance without reporting every minor deviation, keeping attention on the genuinely important issues. In the third mode, upon explicit request, it produces a structured vulnerability report with concrete fix suggestions for existing code, which is suitable for targeted security audits.

Prerequisites and setup

To use the skill, it must be loaded into a compatible agent environment that supports the skill format of the openai/skills repository; the skill definition itself exists as a configuration file with a name and description, complemented by a directory containing the language- and framework-specific reference documents. Before applying it to a concrete project, it is worth briefly checking this reference directory to see which language-framework combinations already have detailed documentation available and where the skill instead has to rely on general knowledge. Since the currently supported languages are limited to Python, JavaScript, TypeScript, and Go, teams working with other technology stacks should scrutinize the results more critically or bring in supplementary tools.

Security, limitations, and best practices

The skill does not replace a dedicated security tool such as a vulnerability scanner or static code analysis; rather, it supplements development work with contextual expertise directly within the conversation with the AI assistant. Its recommendations should be supplemented, especially for security-critical applications, by established automated review tools and, when in doubt, by human security expertise, because the depth of the analysis depends significantly on whether a reference already exists for the given language-framework combination. When no such reference exists and the skill falls back on general knowledge or a one-off online search, the depth of the analysis can vary. On the positive side, the narrow, well-defined scope explicitly avoids triggering unsolicited security warnings on every code change, which makes the skill less intrusive and more targeted in daily use than an always-on review process.

Published on 09.09.2026

Categories

Frequently asked questions

When should the skill trigger?

According to the provider, only for explicitly requested security guidance, a security report, or secure-by-default coding for supported languages.

Which languages are explicitly supported?

The official description names Python, JavaScript, TypeScript, and Go.

Does the skill replace a security assessment?

No. Recommendations must be checked against the project and supplemented with controlled testing and professional approval.