bundle-security
sdieunidou/symfony-bundle-forgeSecurity best practices for Symfony bundles — SECURITY.md & private disclosure, deny-by-default config, Twig auto-escaping, JSON-in-HTML hex encoding,…
Scores out of 100 · grade B
2026-08-10Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score82/100
- no commits in the last 12 weeks
Adopted
20% of the score0/100
- No install or star signal yet.
Documented
15% of the score38/100
- No usage example or code block.
- 314-word body.
Install
npx skills add sdieunidou/symfony-bundle-forge/bundle-securityWhat it says it does
Security best practices for Symfony bundles — SECURITY.md & private disclosure, deny-by-default config, Twig auto-escaping, JSON-in-HTML hex encoding, reflected-input encoding, path-traversal/SSRF defense, query/regex escaping, CSRF, secure cookies & vetted crypto, XXE, no secrets in source, composer audit. Use when reviewing or hardening a bundle's security, writing a security policy, or handling user input/output/paths/tokens/cookies. Triggers — bundle security, SECURITY.md, XSS bundle, path traversal, SSRF, CSRF token, secure cookie, XXE, json_encode raw, composer audit, deny by default.
Also in sdieunidou/symfony-bundle-forge
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| scaffolding-a-bundlesdieunidou/symfony-bundle-forge | clean | Skill | no signal | 2 months ago | |
| bundle-testingsdieunidou/symfony-bundle-forge | clean | Skill | no signal | 2 months ago | |
| symfony-bundle-rubricsdieunidou/symfony-bundle-forge | clean | Skill | no signal | 2 months ago | |
| bundle-architectsdieunidou/symfony-bundle-forge | clean | Subagent | no signal | 2 months ago | |
| bundle-auditorsdieunidou/symfony-bundle-forge | clean | Subagent | no signal | 2 months ago | |
| bundle-ci-cdsdieunidou/symfony-bundle-forge | Missing files | Skill | no signal | 2 months ago |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,507 installs | yesterday | |
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | yesterday | |
| asocoreyhaines31/marketingskills | clean | Security | 46,239 installs | yesterday | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,843 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=sdieunidou%2Fsymfony-bundle-forge)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
