V3 Security Overhaul

ruvnet/ruflo/v3/@claude-flow/cli/.claude/skills/v3-security-overhaul

by ruvnet58e0ae7e14e68aab45a4127d6f42f567bbcfb328No license74K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated today

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

Instructions onlySecurity
AI-generated overview

Orchestrates a security overhaul for claude-flow v3, fixing critical CVEs and applying secure-by-default patterns.

What it does
This skill coordinates a security architecture overhaul for claude-flow v3 by dispatching specialized security agents to design a threat model, remediate critical CVEs, and build security testing. It documents fixes for vulnerable dependencies, weak password hashing, and hardcoded credentials, and it prescribes secure coding patterns such as Zod input validation, path sanitization, and shell-free command execution. It also defines success metrics covering security score, CVE resolution, test coverage, and documented implementation. It produces guidance and remediation instructions rather than executable scripts.
When to use it
Use it when performing a security-first implementation or overhaul of claude-flow v3. It fits work that must address the listed critical CVEs and adopt secure-by-default development practices. It is also suited to establishing threat models, security boundaries, and security test coverage for that codebase.
Requirements
An agent environment able to dispatch specialized subagents or tasks; Node.js and npm for the dependency update and audit commands; the bcrypt and zod packages for the shown patterns. No scripts ship with the skill.

V3 Security Overhaul

What This Skill Does

Orchestrates comprehensive security overhaul for claude-flow v3, addressing critical vulnerabilities and establishing security-first development practices using specialized v3 security agents.

Quick Start

bash
# Initialize V3 security domain (parallel)Task("Security architecture", "Design v3 threat model and security boundaries", "v3-security-architect")Task("CVE remediation", "Fix CVE-1, CVE-2, CVE-3 critical vulnerabilities", "security-auditor")Task("Security testing", "Implement TDD London School security framework", "test-architect")

Critical Security Fixes

CVE-1: Vulnerable Dependencies

bash
npm update @anthropic-ai/claude-code@^2.0.31npm audit --audit-level high

CVE-2: Weak Password Hashing

typescript
// ❌ Old: SHA-256 with hardcoded saltconst hash = crypto.createHash('sha256').update(password + salt).digest('hex');
// ✅ New: bcrypt with 12 roundsimport bcrypt from 'bcrypt';const hash = await bcrypt.hash(password, 12);

CVE-3: Hardcoded Credentials

typescript
// ✅ Generate secure random credentialsconst apiKey = crypto.randomBytes(32).toString('hex');

Security Patterns

Input Validation (Zod)

typescript
import { z } from 'zod';
const TaskSchema = z.object({  taskId: z.string().uuid(),  content: z.string().max(10000),  agentType: z.enum(['security', 'core', 'integration'])});

Path Sanitization

typescript
function securePath(userPath: string, allowedPrefix: string): string {  const resolved = path.resolve(allowedPrefix, userPath);  if (!resolved.startsWith(path.resolve(allowedPrefix))) {    throw new SecurityError('Path traversal detected');  }  return resolved;}

Safe Command Execution

typescript
import { execFile } from 'child_process';
// ✅ Safe: No shell interpretationconst { stdout } = await execFile('git', [userInput], { shell: false });

Success Metrics

  • Security Score: 90/100 (npm audit + custom scans)
  • CVE Resolution: 100% of critical vulnerabilities fixed
  • Test Coverage: >95% security-critical code
  • Implementation: All secure patterns documented and tested

Source and attribution

Source:ruvnet/rufloinv3/@claude-flow/cli/.claude/skills/v3-security-overhaulat commit58e0ae7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal