Writing & Content
PromptBeginner5 minmarkdown
- **Trusting Content-Type headers**: Attackers set any Content-Type they want; validate actual content
not declared type
0
Explore
21,114 skills indexed with the new KISS metadata standard.
not declared type
@Size
direct API calls)
Marshmallow
Joi
external API checks)
GraphQL schemas)
XSS
valid foreign keys)
shipping address matches country)
content types
account numbers
parameterization for SQL)
URLs
lengths (min/max for strings)
SQL injection cheat sheets)
database errors
URL encoding
UNIQUE
types
APIs
actionable messages that guide correction without exposing system internals
XSS escaping
escaping context-specific threats