Writing & Content
PromptBeginner5 minmarkdown
- **Trusting Content-Type headers**: Attackers set any Content-Type they want; validate actual content
not declared type
0
Explore
23,791 skills indexed with the new KISS metadata standard.
not declared type
include patch-style diffs or clearly labeled file blocks inside the TODO.
Marshmallow
@Size
external API checks)
Joi
direct API calls)
GraphQL schemas)
XSS
shipping address matches country)
valid foreign keys)
parameterization for SQL)
content types
account numbers
lengths (min/max for strings)
database errors
SQL injection cheat sheets)
URL encoding
UNIQUE
APIs
types
escaping context-specific threats
XSS escaping
actionable messages that guide correction without exposing system internals