Security Best Practices

Reviews security requirements in Python, JavaScript, TypeScript, and Go and recommends secure defaults.

Security Best Practices is an official curated OpenAI skill for Codex. According to the provider, it supports explicitly requested security guidance, security reports, and secure-by-default coding help for Python, JavaScript, TypeScript, and Go. The source is published in the official openai/skills repository under skills/.curated/security-best-practices, and the skill directory identifies Apache License 2.0 in LICENSE.txt. This catalog entry separates provider documentation from editorial interpretation: the provenance is verifiable, but every concrete recommendation still needs to be evaluated against the project, its dependencies, and its operating environment.

Purpose and Triggering

The skill is intended for a clear security context. According to the provider, it should trigger only when a person explicitly asks for security best practices, a security review, a security report, or secure-by-default coding help. It is not intended for general code review, ordinary debugging, or non-security tasks. That boundary matters because security guidance requires different evidence, priorities, and assumptions than a functional review. Before analysis begins, the team should therefore decide whether an existing codebase is being assessed, new implementation is being hardened, or a structured report is requested.

Languages and Frameworks

The first step is to identify all relevant languages and frameworks in the actual working context. The provider recommends determining the primary backend and frontend stack and checking both sides of a web application. The agent then looks for matching reference documents in the skill directory. The expected filenames use a language, framework, and stack pattern, alongside general language guidance. If no matching references exist, the agent may use well-known general security practices, but a report must disclose that concrete matching guidance was unavailable. This prevents a general recommendation from being presented as project-specific evidence.

Operating Modes

The primary mode uses the discovered guidance to write new code securely and with sensible defaults. In passive mode, the agent identifies especially consequential security issues while performing other development work and raises them for attention. A third mode produces a prioritized report when the user explicitly asks for one. According to the provider, that report should contain a short executive summary and clearly separated severity and urgency sections. Critical findings need an unambiguous impact statement, numbered references, and concrete code evidence with line numbers. After writing the report, the provider specifies the filename security_best_practices_report.md unless the user gives another location.

Safe Boundaries

Recommendations remain bounded by available sources and the visible project context. When the language or framework is unclear, the agent should inspect the repository and state its evidence. Customer-specific rules may intentionally override a best practice, and those exceptions should be documented so future reviewers understand the reason. For catalog use, a report must never contain secrets, credentials, or tokens. Security examples therefore need placeholder values and must avoid dangerous commands. Connected model or agent services may transmit code and context to their respective provider; analysis performed in a local working directory is not automatically a guarantee that no data leaves the system.

General Advice and Limits

The source includes general advice about avoiding predictable public resource identifiers and using sufficiently random identifiers where exposed resources require them. Its TLS guidance distinguishes development environments from real production architecture; missing TLS in local development is not automatically a finding. The source also cautions against blanket recommendations for secure cookies or HSTS when the deployment context is unknown. The skill does not replace an independent security assessment, controlled testing, or professional approval. Teams should validate recommendations against authentication, authorization, data classification, network paths, dependencies, logging, and incident response. Its value is a focused security workflow with explicit assumptions and relevant reference selection, not an automatic guarantee of safety.

Free
Provider
OpenAI
License
Apache-2.0
Last reviewed
09.09.2026

Repository and documentation

Categories

Compatible with

Codex