Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

secure-perl-plus

hero

License: MIT Works with Claude Code Skill version Language: Perl

Built on affaan-m/ECC by @affaan-m (260,388 stars, MIT). All credit for the original idea to them. This fork improves and repackages it; upstream license preserved in UPSTREAM_LICENSE.

A Claude Code skill that helps you find and fix common security bugs in Perl code.

🔒 Why

Perl makes it easy to read input, open files, run tools, and query a database.

Small mistakes in these tasks can expose files, secrets, or user data.

This skill gives Claude Code clear rules for safer Perl. It covers taint mode, input checks, file paths, shell commands, SQL, web apps, passwords, cookies, and sessions.

It is for Perl developers, code reviewers, and teams that maintain old or new Perl apps.

⚡ Install

Replace YOUR_GITHUB_USER with the repo owner, then run this one command:

mkdir -p ~/.claude/skills/perl-security && curl -fsSL https://raw.githubusercontent.com/YOUR_GITHUB_USER/secure-perl-plus/main/skill/SKILL.md -o ~/.claude/skills/perl-security/SKILL.md

The skill has one file and no extra packages.

🛠️ Usage

Open Claude Code in a Perl project and ask:

Use the perl-security skill to review this code. Check user input, file paths, shell commands, SQL, passwords, cookies, and sessions. Show the risks and give safe fixes.

Expected output:

Risk: User data is placed in a shell command string.
Fix: Use the list form of system and pass each value as its own item.

Risk: SQL values are joined into the query text.
Fix: Use DBI placeholders and pass values to execute().

You can also ask Claude Code to check one file or one part of an app:

Use perl-security to check upload.pl for unsafe paths and weak input checks.

The skill plugs into your normal review and repair flow. It gives Claude Code ten core rules, safe Perl examples, and clear checks for common risks.

🔄 What we changed vs upstream

  • 全体を日本語の包括的リファレンスから、簡潔で平易な英語の実践ガイドへ書き直した。
  • 冒頭に10項目の「Core Rules」を追加し、最小権限、秘密情報の非記録、用途別エスケープなどの基本方針を明示した。
  • 適用範囲にパスワード、Cookie、セッションを追加し、入力検証には範囲・件数・デコード・リクエストサイズの確認を加えた。
  • テイント解除例を強化し、未定義値、./..、ファイル名長、整数の上下限を検証するようにした。
  • 単純なメール正規表現を推奨例から外し、重要な検証では実績あるメールモジュールを使うよう改めた。

📄 License

This project is released under the MIT License.

The upstream MIT license is preserved in UPSTREAM_LICENSE.

About

Claude Code skill to find and fix Perl security bugs with taint mode, safe SQL, files, web guards, and checks. Built by @affaan-m.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors