CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. harperaa
  4. /
  5. secure-claude-skills
  6. /
  7. Csrf Protection

Csrf Protection

Editor's Note

This wraps your Next.js API routes with CSRF protection using HMAC-SHA256 signed tokens that are session-bound and single-use. You fetch a token from /api/csrf before making POST/PUT/DELETE requests, include it in the X-CSRF-Token header, and withCsrf() handles verification automatically. The implementation is solid: HTTP-only cookies, SameSite=Strict, and tokens that expire after one use. Honestly, CSRF protection is one of those things that's easy to skip because nothing breaks without it, but the documentation here does a good job explaining why it matters with real examples like the 2008 router hijacking attacks. Works well layered with rate limiting for things like contact forms or account changes.

Install

npx skills add https://github.com/harperaa/secure-claude-skills --skill csrf-protection
Votes
0
Installs158
GitHub Stars8
Categories
Security
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment

Related Security Skills

View all →
security-audit-scanner

tbartel74/Vigil-Code

0
8
Automated security scanning for Vigil Guard v2.0.0. Use for OWASP Top 10 checks, TruffleHog secret detection, npm/pip vulnerability scanning, 3-branch service security, heuristics-service audit, and CI/CD security pipelines.
permission-auditor

useai-pro/openclaw-skills-security

0
377
58
permission auditor
supabase-audit-auth-config

yoanbernabeu/supabase-pentest-skills

0
237
43
supabase audit auth config
supabase-audit-auth-users

yoanbernabeu/supabase-pentest-skills

0
208
43
supabase audit auth users
supabase-audit-auth-signup

yoanbernabeu/supabase-pentest-skills

0
205
43
supabase audit auth signup
supabase-audit-authenticated

yoanbernabeu/supabase-pentest-skills

0
182
43
supabase audit authenticated