Security Best Practices
Reviews security requirements in Python, JavaScript, TypeScript, and Go and recommends secure defaults.
- Skill Road
- Security Best Practices
Security Best Practices is an official curated OpenAI skill for Codex. According to the provider, it supports explicitly requested security guidance, security reports, and secure-by-default coding help for Python, JavaScript, TypeScript, and Go. The source is published in the official openai/skills repository under skills/.curated/security-best-practices, and the skill directory identifies Apache License 2.0 in LICENSE.txt. This catalog entry separates provider documentation from editorial interpretation: the provenance is verifiable, but every concrete recommendation still needs to be evaluated against the project, its dependencies, and its operating environment.
Purpose and Triggering
The skill is intended for a clear security context. According to the provider, it should trigger only when a person explicitly asks for security best practices, a security review, a security report, or secure-by-default coding help. It is not intended for general code review, ordinary debugging, or non-security tasks. That boundary matters because security guidance requires different evidence, priorities, and assumptions than a functional review. Before analysis begins, the team should therefore decide whether an existing codebase is being assessed, new implementation is being hardened, or a structured report is requested.
Languages and Frameworks
The first step is to identify all relevant languages and frameworks in the actual working context. The provider recommends determining the primary backend and frontend stack and checking both sides of a web application. The agent then looks for matching reference documents in the skill directory. The expected filenames use a language, framework, and stack pattern, alongside general language guidance. If no matching references exist, the agent may use well-known general security practices, but a report must disclose that concrete matching guidance was unavailable. This prevents a general recommendation from being presented as project-specific evidence.
Operating Modes
The primary mode uses the discovered guidance to write new code securely and with sensible defaults. In passive mode, the agent identifies especially consequential security issues while performing other development work and raises them for attention. A third mode produces a prioritized report when the user explicitly asks for one. According to the provider, that report should contain a short executive summary and clearly separated severity and urgency sections. Critical findings need an unambiguous impact statement, numbered references, and concrete code evidence with line numbers. After writing the report, the provider specifies the filename security_best_practices_report.md unless the user gives another location.
Safe Boundaries
Recommendations remain bounded by available sources and the visible project context. When the language or framework is unclear, the agent should inspect the repository and state its evidence. Customer-specific rules may intentionally override a best practice, and those exceptions should be documented so future reviewers understand the reason. For catalog use, a report must never contain secrets, credentials, or tokens. Security examples therefore need placeholder values and must avoid dangerous commands. Connected model or agent services may transmit code and context to their respective provider; analysis performed in a local working directory is not automatically a guarantee that no data leaves the system.
General Advice and Limits
The source includes general advice about avoiding predictable public resource identifiers and using sufficiently random identifiers where exposed resources require them. Its TLS guidance distinguishes development environments from real production architecture; missing TLS in local development is not automatically a finding. The source also cautions against blanket recommendations for secure cookies or HSTS when the deployment context is unknown. The skill does not replace an independent security assessment, controlled testing, or professional approval. Teams should validate recommendations against authentication, authorization, data classification, network paths, dependencies, logging, and incident response. Its value is a focused security workflow with explicit assumptions and relevant reference selection, not an automatic guarantee of safety.
- Provider
- OpenAI
- License
- Apache-2.0
- Last reviewed
- 09.09.2026
Repository and documentation
Categories
Compatible with
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026