KNOLO / HUBPublishknolo.dev → Runtime
the3seus/app-security

Application Security Handbook

Practical application security for sessions, injection, secrets, and authz — written to be queried while you design or review.

Query pack Download
V5✓ Verified artifactPublisher-attestedApache-2.0v1.0.035 KB11 docsUpdated 1 day ago02
KNOWLEDGE CARD / README

Portable policy knowledge for local retrieval.

Application Security Handbook is original guidance for common web-app failure modes.

It points at OWASP as a source of broader catalogs; the text here is not a reproduction of those cheat sheets.

Query the decision, not the CVE number.

Intended use

Grounding design and code review. Lookup when choosing a session cookie, a query parameter, or a secret-storage approach.

Out of scope

Not a scanner, pentest, or compliance certification. Not a copy of OWASP Cheat Sheets. It does not authorize production changes.

Sources

Sample questions

!
Contains agent metadata

This Knowledge Image contains prompts, tool policy, namespace grants, or other agent registry metadata.

Mounting the pack for retrieval does not execute tools. Applying these policies affects your application only if your host explicitly honors them.

Credentials must never be stored inside a pack.
Inspect registry
Verified artifactContainer, digest, structure passed
Publisher-attestedLicense, sources, rights supplied
Not auditedIndependent quality signal

Artifact verification confirms integrity and format. It does not guarantee that the contained knowledge is factually correct.

Application Security Handbook — Knolo Hub