Quarkus Security
Hardened Quarkus for Muse: JWT and OIDC auth, @RolesAllowed RBAC, Bean Validation, parameterized Panache queries, BCrypt, CORS, rate limiting, audit logging, and CVE scanning.
- What
- Hardened Quarkus for Muse: JWT and OIDC auth, @RolesAllowed RBAC, Bean Validation, parameterized Panache queries, BCrypt, CORS, rate limiting, audit logging, and CVE scanning.
- Cost
- Free
- Needs
- Use "Quarkus Security" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: security implementation patterns for Quarkus applications, so Muse wires authentication and authorization the safe way. Covers JWT authentication (MicroProfile JWT, SmallRye) and OIDC configuration with secrets from environment variables, custom authentication filters, role-based access control with @RolesAllowed and programmatic SecurityIdentity checks including ownership verification, input validation with Bean Validation annotations and custom validators, SQL injection prevention via parameterized Panache queries and parameterized native queries (never string concatenation), BCrypt password hashing with a dedicated service, CORS configuration with explicit origins and methods, secrets management via environment variables or HashiCorp Vault (never in application.properties), rate limiting with the X-Forwarded-For spoofing warning (use the container remote address or an authenticated identity, configure trusted proxies), security headers (X-Frame-Options, HSTS, CSP without unsafe-inline scripts), audit logging of sensitive operations, and dependency CVE scanning with OWASP dependency-check. Includes BAD/GOOD code pairs throughout. Use when adding authentication or authorization, validating input, managing secrets, or hardening a Quarkus application. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: security guidance, not a penetration test; rate limiting and CORS must be adapted to your deployment topology (proxies, containers); examples target recent Quarkus versions. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Quarkus Security" with your Muse. Prerequisites: none to install. Pure guidance; a Quarkus project helps. Never paste real secrets into a chat. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/quarkus-security/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Harden this Quarkus endpoint (auth, input validation, secrets): [paste code or describe the endpoint]." 3. Ask it to check JWT/OIDC wiring, @RolesAllowed coverage, parameterized queries, BCrypt usage, CORS origins, and that no secret lives in application.properties. Tip: ask "audit this resource class for OWASP Top 10 issues" for a focused pass. Safety: a skill is plain-text instructions; it runs nothing by itself. This is guidance, not a pentest. Review generated code before merging.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.