smithery/robotti-io

input-validation-hardening

Process for tightening input validation, canonicalization, and safe parsing to prevent injection and logic abuse.

Installation

$ npx skills add smithery/robotti-io --skill input-validation-hardening

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/robotti-io.

npx skills add smithery/robotti-io

Browse all from smithery/robotti-io

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,856 B
  • docs SUMMARY.md 147 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

Input Validation Hardening

When to use

Use this skill when asked to validate inputs, harden request parsing, or prevent injection/abuse.

Inputs to collect (if available)

  • Entry points (HTTP endpoints, consumers, file parsers)
  • Data sensitivity and trust boundaries
  • Existing validation libraries/patterns in the codebase
  • Known attack/abuse cases (payloads, bypass attempts)

Step-by-step process

  1. Inventory inputs

- HTTP params/body/headers, file uploads, message payloads, env vars, CLI args

  1. Define schemas

- Prefer typed schemas (DTOs) and allow-lists - Enforce length, charset, ranges, and required fields

  1. Canonicalize early

- Normalize encoding, trim, and apply consistent parsing (dates, IDs, enums)

  1. Validate before use

- Reject unknown fields if possible - Ensure IDs map to authorized resources (ownership/tenant checks)

  1. Protect sinks

- Parameterize DB queries - Avoid dynamic execution (eval, shell, template injection)

  1. Add tests

- Boundary tests (min/max), malformed inputs, and common payloads

Output

  • Proposed schema(s)
  • Where to enforce validation (middleware/controller boundary)
  • Tests added/updated

Repo integration (optional)

Related prompts:

  • validate-input-handling.prompt.md
  • scan-for-insecure-apis.prompt.md

Output format

  • Inventory: inputs and boundaries
  • Proposed schema(s) (high-level)
  • Enforcement point: where validation should occur
  • Test plan: boundary + malicious inputs

Examples

  • “Public JSON API” → reject unknown fields, enforce max sizes, and add negative tests for type confusion and oversized payloads.