Built on affaan-m/ECC by @affaan-m (260,388 stars, MIT). All credit for the original idea to them. This fork improves and repackages it; upstream license preserved in UPSTREAM_LICENSE.
A Claude Code skill that helps you find and fix common security bugs in Perl code.
Perl makes it easy to read input, open files, run tools, and query a database.
Small mistakes in these tasks can expose files, secrets, or user data.
This skill gives Claude Code clear rules for safer Perl. It covers taint mode, input checks, file paths, shell commands, SQL, web apps, passwords, cookies, and sessions.
It is for Perl developers, code reviewers, and teams that maintain old or new Perl apps.
Replace YOUR_GITHUB_USER with the repo owner, then run this one command:
mkdir -p ~/.claude/skills/perl-security && curl -fsSL https://raw.githubusercontent.com/YOUR_GITHUB_USER/secure-perl-plus/main/skill/SKILL.md -o ~/.claude/skills/perl-security/SKILL.mdThe skill has one file and no extra packages.
Open Claude Code in a Perl project and ask:
Use the perl-security skill to review this code. Check user input, file paths, shell commands, SQL, passwords, cookies, and sessions. Show the risks and give safe fixes.
Expected output:
Risk: User data is placed in a shell command string.
Fix: Use the list form of system and pass each value as its own item.
Risk: SQL values are joined into the query text.
Fix: Use DBI placeholders and pass values to execute().
You can also ask Claude Code to check one file or one part of an app:
Use perl-security to check upload.pl for unsafe paths and weak input checks.
The skill plugs into your normal review and repair flow. It gives Claude Code ten core rules, safe Perl examples, and clear checks for common risks.
- 全体を日本語の包括的リファレンスから、簡潔で平易な英語の実践ガイドへ書き直した。
- 冒頭に10項目の「Core Rules」を追加し、最小権限、秘密情報の非記録、用途別エスケープなどの基本方針を明示した。
- 適用範囲にパスワード、Cookie、セッションを追加し、入力検証には範囲・件数・デコード・リクエストサイズの確認を加えた。
- テイント解除例を強化し、未定義値、
./..、ファイル名長、整数の上下限を検証するようにした。 - 単純なメール正規表現を推奨例から外し、重要な検証では実績あるメールモジュールを使うよう改めた。
This project is released under the MIT License.
The upstream MIT license is preserved in UPSTREAM_LICENSE.
