Bitrix Security: Install, Source and Security | FunnelSlayer

Bitrix Security

Published by bxmaximum in bitrix-framework-skills

No known issues224 installs

What this skill does

Bitrix security patterns — CSRF, XSS and link sanitizing, open redirects, SQL injection in ORM/ExpressionField, SSRF and local-file reads, uploads, rights checks, JWT, encrypted fields. Use when handling user input or auditing code.

Add Bitrix Security to your agent

Review the source and files first. When you are ready, copy the prompt instruction or use the CLI command supported by your environment.

Install with a prompt

Paste this into a compatible coding agent:

add this skill "bitrix-security" from https://github.com/bxmaximum/bitrix-framework-skills

Install with the CLI

Run this command in a controlled environment after reviewing the repository:

npx skills add https://github.com/bxmaximum/bitrix-framework-skills --skill bitrix-security

Skill instructions

Security

Baseline: main 23.0+ · Verified: main 26.800.0

General defaults (no superglobals, keep default prefilters, escape output) live in bitrix-framework.

TaskRead
CSRF, escaping, HTML sanitizing, link and redirect targets, raw-HTML sinksrules/csrf-xss.md
SQL injection (raw, ORM, ExpressionField), SSRF, local files, uploads, stored settingsrules/sql-ssrf.md
Rights checks, #[ActionAccess], REST scopes, JWT/JWK, encryption, 2FArules/jwt-crypto-access.md

Invariants

  • Untrusted: request data, and also DB-stored settings, imports, REST payloads. The type and owner of an entity come from its DB record, never from the request.
  • Whitelist whatever becomes SQL structure (field names, operators, functions, order keys), whatever its source.
  • Escape for the output context: HTML htmlspecialcharsbx(), JS Json::encode(), URLs through a scheme allow-list.
  • User input never goes unchecked into CFile::MakeFileArray(), file_get_contents(), unserialize(), redirect targets.
  • Authentication/Csrf filters don't authorize: check rights on the object in every action.

Files included

  • rules/csrf-xss.md
  • rules/jwt-crypto-access.md
  • rules/sql-ssrf.md
  • SKILL.md

More skills