Writing & Content
PromptBeginner5 minmarkdown
- **Trusting Content-Type headers**: Attackers set any Content-Type they want; validate actual content
not declared type
0
Explore
24,499 skills indexed with the new KISS metadata standard.
not declared type
Marshmallow
Joi
direct API calls)
external API checks)
GraphQL schemas)
XSS
valid foreign keys)
shipping address matches country)
parameterization for SQL)
content types
account numbers
lengths (min/max for strings)
SQL injection cheat sheets)
URLs
database errors
URL encoding
UNIQUE
types
APIs
actionable messages that guide correction without exposing system internals
escaping context-specific threats
XSS escaping
data sanitization