Application Security Handbook
Practical application security for sessions, injection, secrets, and authz — written to be queried while you design or review.
Portable policy knowledge for local retrieval.
Application Security Handbook is original guidance for common web-app failure modes.
It points at OWASP as a source of broader catalogs; the text here is not a reproduction of those cheat sheets.
Query the decision, not the CVE number.
Intended use
Grounding design and code review. Lookup when choosing a session cookie, a query parameter, or a secret-storage approach.
Out of scope
Not a scanner, pentest, or compliance certification. Not a copy of OWASP Cheat Sheets. It does not authorize production changes.
Sources
Sample questions
This Knowledge Image contains prompts, tool policy, namespace grants, or other agent registry metadata.
Mounting the pack for retrieval does not execute tools. Applying these policies affects your application only if your host explicitly honors them.
Credentials must never be stored inside a pack.