# Clojure Security

> Use when reviewing Clojure or ClojureScript code for security issues, auditing for RCE via read-string / eval, unsafe Java deserialization, SQL injection through string concatenation, XXE in clojure.xml or data.xml, Hiccup / Selmer template injection, CLJS DOM XSS, atom check-then-act races, spec or Malli error-message data leaks, or interpreting clj-kondo / Semgrep / gitleaks / clj-watson findings on a Clojure codebase.

## Facts
- Page: https://tashan.sh/capability/skill-cleancoders-clojure-security
- tashan id: skill:cleancoders/clojure-security
- Source: https://github.com/cleancoders/agent-plugins
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: 98.0
- Freshness: 96.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- Official: no

## Install

```sh
cp -r clojure-security ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-15 by tashan (https://tashan.sh) from public evidence. Scorer s5.
