Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Analyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit session handling, check for session fixation risks, review session timeout configurations, or validate session ID generation security. Trigger with phrases like "check session security", "audit session management", "review session handling", or "session fixation vulnerability".
.claude/skills/jeremylongshore-checking-session-security/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | 47% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 8% | 0% |
| case-19 | ✓→✗ | ▼ Worse | 27% | 0% |
| case-09 | ✓→✓ | = Same ✓ | 31% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 29% | 0% |
Audit session management implementations in web applications to identify vulnerabilities including session fixation (CWE-384), insufficient session expiration (CWE-613), and cleartext transmission of session tokens (CWE-319).
${CLAUDE_SKILL_DIR}/session.config.*, settings.py, application.yml)${CLAUDE_SKILL_DIR}/security-reports/**/auth/**, **/session/**, **/middleware/**, and framework-specific files (settings.py, application.yml, web.config).Date.now(), Math.random(), sequential IDs, or timestamp-based tokens (CWE-330).req.session.regenerate() in Express, request.session.cycle_key() in Django). Flag any login handler that sets authenticated = true without regenerating the session ID.HttpOnly (prevents XSS-based token theft), Secure (HTTPS-only transmission), SameSite=Lax|Strict (CSRF mitigation), and __Host-/__Secure- prefix usage. Flag any missing attribute.${CLAUDE_SKILL_DIR}/security-reports/session-security-YYYYMMDD.md with per-finding severity, CWE mapping, vulnerable code snippet, and remediated code example.See ${CLAUDE_SKILL_DIR}/references/implementation.md for the detailed implementation guide. See ${CLAUDE_SKILL_DIR}/references/critical-findings.md for example vulnerability patterns with before/after code.
${CLAUDE_SKILL_DIR}/security-reports/session-security-YYYYMMDD.md with findings by severity| Error | Cause | Solution | |-------|-------|----------| | No session handling code found in ${CLAUDE_SKILL_DIR}/ | Unusual file structure or framework | Search for framework-specific patterns; request explicit file paths | | Unknown session framework | Custom or uncommon session library | Apply fundamental session security principles; note limited framework-specific guidance | | Cannot analyze minified/compiled code | Production bundles instead of source | Request unminified source code; document limitation | | Non-standard session implementation | Custom session management bypassing framework | Apply extra scrutiny; custom implementations are higher risk (CWE-384, CWE-613) | | Session config in environment variables, not code | Externalized configuration | Request .env.example or deployment config documentation |
${CLAUDE_SKILL_DIR}/references/critical-findings.md -- example vulnerability patterns${CLAUDE_SKILL_DIR}/references/errors.md -- full error handling reference| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-08 | fail→pass | 13,793 | 11,224 | -19% | 1 | 1 | 0% | 2,069 | 3,040 | +47% | 0 | 0 | — |
case-09 | pass→pass | 14,643 | 10,888 | -26% | 1 | 1 | 0% | 2,345 | 3,077 | +31% | 0 | 0 | — |
case-01 | fail→fail | 6,094 | 7,958 | +31% | 1 | 1 | 0% | 605 | 2,203 | +264% | 0 | 0 | — |
case-02 | fail→fail | 22,563 | 12,896 | -43% | 1 | 1 | 0% | 3,410 | 2,569 | -25% | 0 | 0 | — |
case-03 | fail→fail | 21,137 | 21,418 | +1% | 1 | 1 | 0% | 2,658 | 4,598 | +73% | 0 | 0 | — |
case-04 | pass→pass | 11,029 | 17,169 | +56% | 1 | 1 | 0% | 1,997 | 2,586 | +29% | 0 | 0 | — |
case-05 | pass→pass | 17,251 | 14,521 | -16% | 1 | 1 | 0% | 2,225 | 2,723 | +22% | 0 | 0 | — |
case-06 | pass→pass | 11,310 | 14,485 | +28% | 1 | 1 | 0% | 1,976 | 2,667 | +35% | 0 | 0 | — |
case-07 | pass→pass | 11,529 | 11,032 | -4% | 1 | 1 | 0% | 1,863 | 3,182 | +71% | 0 | 0 | — |
case-10 | pass→pass | 10,484 | 8,960 | -15% | 1 | 1 | 0% | 1,484 | 2,653 | +79% | 0 | 0 | — |
case-11 | pass→pass | 17,174 | 13,692 | -20% | 1 | 1 | 0% | 2,523 | 3,278 | +30% | 0 | 0 | — |
case-12 | pass→pass | 16,494 | 16,577 | +1% | 1 | 1 | 0% | 1,950 | 2,577 | +32% | 0 | 0 | — |
case-13 | pass→pass | 7,818 | 6,942 | -11% | 1 | 1 | 0% | 1,432 | 2,264 | +58% | 0 | 0 | — |
case-14 | pass→pass | 12,625 | 14,104 | +12% | 1 | 1 | 0% | 2,071 | 3,575 | +73% | 0 | 0 | — |
case-15 | fail→fail | 6,332 | 11,048 | +74% | 1 | 1 | 0% | 1,109 | 1,956 | +76% | 0 | 0 | — |
case-16 | pass→pass | 11,042 | 9,540 | -14% | 1 | 1 | 0% | 1,848 | 2,970 | +61% | 0 | 0 | — |
case-17 | pass→pass | 14,997 | 13,719 | -9% | 1 | 1 | 0% | 2,229 | 2,984 | +34% | 0 | 0 | — |
case-18 | fail→pass | 14,615 | 6,957 | -52% | 1 | 1 | 0% | 2,154 | 2,331 | +8% | 0 | 0 | — |
case-19 | pass→fail | 14,054 | 10,976 | -22% | 1 | 1 | 0% | 1,786 | 2,260 | +27% | 0 | 0 | — |
case-20 | pass→pass | 17,259 | 10,406 | -40% | 1 | 1 | 0% | 3,266 | 3,267 | +0% | 0 | 0 | — |
case-21 | pass→pass | 20,698 | 17,658 | -15% | 1 | 1 | 0% | 4,011 | 4,647 | +16% | 0 | 0 | — |
case-22 | pass→pass | 13,148 | 8,802 | -33% | 1 | 1 | 0% | 2,025 | 2,581 | +27% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +5 percentage points is the difference between those two pass rates over the 22 comparable cases. 2 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.