principle @community/principle-owasp-cryptographic-failures

Owasp Cryptographic Failures

Sensitive data must be encrypted in transit (TLS 1.2+) and at rest (AES-256 or ChaCha20-Poly1305). Passwords must use dedicated slow hash functions (bcrypt/Argon2id/scrypt).…

Skill
@community
Domain
security
Version
1.0.0
Quality
0.0
Edges
0 out · 0 in
Tokens
130/366/624
$ aoe install @community/principle-owasp-cryptographic-failures

Projection

Always in _index.xml · the agent never has to ask for this.

OwaspCryptographicFailures [principle] v1.0.0

OWASP Top 10 A02:2021 (formerly Sensitive Data Exposure) — failures related to cryptography or lack thereof that lead to exposure of sensitive data or system compromise.

Sensitive data must be encrypted in transit (TLS 1.2+) and at rest (AES-256 or ChaCha20-Poly1305). Passwords must use dedicated slow hash functions (bcrypt/Argon2id/scrypt). Deprecated algorithms (MD5, SHA-1, DES, RC4, ECB mode) must never appear in new code regardless of context.

Source

aoe-engine/examples/frontend-design/primes/compiled/@community/principle-owasp-cryptographic-failures/atom.yaml