Expert Security
ReJeCtAll/ExpertTeam-Codex
安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.
$ npx skills add addyosmani/agent-skills --skill security-and-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install addyosmani/agent-skills security-and-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/addyosmani/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-and-hardening .claude/skills/security-and-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-and-hardening" agent skill from https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardening into .claude/skills/security-and-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-and-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add addyosmani/agent-skills --skill security-and-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install addyosmani/agent-skills security-and-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/addyosmani/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-and-hardening .agents/skills/security-and-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-and-hardening" agent skill from https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardening into .agents/skills/security-and-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-and-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add addyosmani/agent-skills --skill security-and-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install addyosmani/agent-skills security-and-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/addyosmani/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-and-hardening .cursor/skills/security-and-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-and-hardening" agent skill from https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardening into .cursor/skills/security-and-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-and-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/addyosmani/agent-skills.git --path skills/security-and-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add addyosmani/agent-skills --skill security-and-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install addyosmani/agent-skills security-and-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/addyosmani/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-and-hardening .gemini/skills/security-and-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-and-hardening" agent skill from https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardening into .gemini/skills/security-and-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-and-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install addyosmani/agent-skills security-and-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add addyosmani/agent-skills --skill security-and-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/addyosmani/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-and-hardening .github/skills/security-and-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-and-hardening" agent skill from https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardening into .github/skills/security-and-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-and-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add addyosmani/agent-skills --skill security-and-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install addyosmani/agent-skills security-and-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/addyosmani/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-and-hardening .opencode/skills/security-and-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-and-hardening" agent skill from https://github.com/addyosmani/agent-skills/tree/main/skills/security-and-hardening into .opencode/skills/security-and-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-and-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-and-hardeningApplies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.
The skill begins with the stance that every external input is hostile and every authorization check mandatory. Before adding controls, the agent maps trust boundaries, including HTTP requests, form fields, uploads, webhooks, third-party APIs, queues, LLM output and local values such as another process's command line or a path in a job payload. It names the assets worth protecting, runs a STRIDE pass over each boundary with the usual mitigations, and writes abuse cases next to use cases so the first test is a misuse attempt.
It frames missing design work as OWASP A04, Insecure Design, and goes on to a three-tier boundary system whose details are cut off in the excerpt. The description also covers auditing an input handler or login flow against the OWASP Top Ten, triaging package audit findings, assessing supply-chain risk in a new package, and personal-data work under GDPR or CCPA. A reference file holds hardening patterns.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1be8e34. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
genai.owasp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security and Hardening loads about 4.4k tokens when it runs, and up to ~7.6k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 2,214 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
e` is committed with placeholders; real `.env*` files and key material are gitignored; grep the staged diff before commiAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from addyosmani/agent-skills at commit 1be8e34, republished under its MIT licence (© addyosmani). 2,214 words, ~4,383 tokens.
.claude/skills/security-and-hardening/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Security-first development practices for web applications. Treat every external input as hostile, every secret as sacred, and every authorization check as mandatory. Security isn't a phase — it's a constraint on every line of code that touches user data, authentication, or external systems.
Controls bolted on without a threat model are guesses. Before hardening, spend five minutes thinking like an attacker:
| Threat | Ask | Typical mitigation |
|---|---|---|
| Spoofing | Can someone impersonate a user/service? | Authentication, signature verification |
| Tampering | Can data be altered in transit or at rest? | Integrity checks, parameterized queries, HTTPS |
| Repudiation | Can an action be denied later? | Audit logging of security events |
| Information disclosure | Can data leak? | Encryption, field allowlists, generic errors |
| Denial of service | Can it be overwhelmed? | Rate limiting, input size caps, timeouts |
| Elevation of privilege | Can a user gain rights they shouldn't? | Authorization checks, least privilege |
If you can't name the trust boundaries for a feature, you're not ready to secure it. This is OWASP A04: Insecure Design — most breaches begin in design, not code.
eval() or innerHTML with user-provided dataThe rules below are the workflow; a concrete implementation of each lives in references/hardening-patterns.md. Open the section you need when you reach that code, not before.
Patterns: Injection, XSS, Access control.
httpOnly, secure, and sameSite: 'lax' or 'strict' (the CSRF defense; 'none' sends the cookie on cross-site requests), with a bounded maxAge.Pattern: Authentication.
default-src 'self' and is tightened, not loosened.* with credentials.passwordHash, reset tokens) before any response. Error bodies are generic; internals go to server logs only.Patterns: Misconfiguration, Sensitive data exposure.
Patterns: Schema validation, File upload.
Any URL the user influences — webhooks, import-from-URL, image proxies, link previews — can be aimed at internal services. Allowlist scheme and host, resolve all DNS records and reject any private or reserved address (loopback, link-local 169.254.169.254, private, unique-local, for IPv4 and IPv6), and forbid redirects. That check still has a DNS-rebinding TOCTOU gap: for high-risk surfaces, pin the resolved IP or put a filtering agent in front.
Pattern: SSRF.
A delete, move, or overwrite is only as safe as the value naming its target, and trust follows who wrote that value, not which channel delivered it: another process's command line is as attacker-controlled as a form field. A shape check proves well-formedness, not authorization. Before the call, require all three: the resolved target (symlinks resolved) sits under an allowlisted root; it is at least one level below that root; and it carries ownership evidence read before the operation. On refusal, log the rejected target and stop; never fall back to a broader default path.
Why the check is weaker than it reads (marker self-attestation, check/use races): Destructive paths. Worked code: ../../references/security-checklist.md.
Limit the API generally and auth endpoints strictly (about 10 attempts per 15 minutes). Once more than one process serves traffic, in-memory counters silently become max × instances, or never fire on serverless: back the limiter with a shared store.
Pattern: Rate limiting.
Secrets come from the environment. .env.example is committed with placeholders; real .env* files and key material are gitignored; grep the staged diff before committing. A secret that reaches a remote is compromised the moment it lands: rotate it first, then purge history.
Pattern: Secrets management.
packageManager (when present), the lockfile, and CI; stop on disagreement or competing lockfiles. Pin the manager version.npm audit fix --force or equivalent) automatically, since forced fixes may cross declared dependency ranges; preview, read changelogs, test each upgrade. Document every deferral with a reason and a review date.cross-env vs crossenv). Review new dependencies, lockfile diffs, and script-policy changes together: ownership, maintenance, release age, provenance, transitive graph. Verify registry signatures where supported (npm audit signatures, pnpm audit signatures) and treat their absence as a signal to investigate, not automatic proof of compromise (A06, LLM03).Triage decision tree: Dependency audit triage. Manager matrix and install-script gate: ../../references/security-checklist.md.
Hardening asks "can an attacker read it?" Privacy asks "should we hold it at all, and for how long?" The cheapest data to protect, breach, and comply over is the data you never collected; treat personal data as a liability to minimize.
observability-and-instrumentation skill makes the same point from the ops side).Classification table: Data classification. A privacy incident starts the breach-notification clock; run the postmortem with the debugging-and-error-recovery skill.
Calling an LLM — chatbots, summarizers, agents, RAG — adds a new attack surface; map it to the OWASP Top 10 for LLM Applications (2025):
eval, SQL, a shell, innerHTML, or a file path; parse defensively, validate against a schema, then encode.Pattern: LLM output handling.
Before sign-off, walk ../../references/security-checklist.md: it covers authentication, authorization, input, data protection and privacy, headers and CORS, dependencies and supply chain, AI/LLM, and error handling, plus the OWASP quick-reference tables.
| Rationalization | Reality |
|---|---|
| "This is an internal tool, security doesn't matter" | Internal tools get compromised. Attackers target the weakest link. |
| "We'll add security later" | Security retrofitting is 10x harder than building it in. Add it now. |
| "No one would try to exploit this" | Automated scanners will find it. Security by obscurity is not security. |
| "The framework handles security" | Frameworks provide tools, not guarantees. You still need to use them correctly. |
| "It's just a prototype" | Prototypes become production. Security habits from day one. |
| "Threat modeling is overkill here" | Five minutes of "how would I attack this?" prevents the design flaws no control can patch later. |
| "It's just LLM output, it's only text" | That "text" can be a SQL statement, a script tag, or a shell command. Treat it like any untrusted input. |
| "The audit passed, so the dependency is safe" | Audits match known advisories. They do not detect a newly malicious package or make unreviewed install scripts safe to execute. |
| "Collect it now, we might need it later" | Data you don't hold can't be breached, subpoenaed, or mis-deleted. "Might need it" is breach scope, not a purpose. |
| "We'll handle deletion requests manually" | Manual erasure misses backups, caches, and analytics copies. If the schema can't find a user's data, you can't honor the request — design for it. |
| "Compliance is legal's problem, not ours" | Export, deletion, retention, and consent are schema and code. Legal can't bolt them on after you've smeared PII across ten systems. |
*) originsevalAfter implementing security-relevant code:
© addyosmani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/security-and-hardening of addyosmani/agent-skills.
Open the folder on GitHubat commit 1be8e34
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in addyosmani/agent-skills, which our catalogue first saw on October 7, 2026.
Security and Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security and Hardening this skilladdyosmani/agent-skills | 105k | 1 repos | ~4.4k | Automated safety check: Notes | MIT | |
| Expert SecurityReJeCtAll/ExpertTeam-Codex | 113 | — | ~780 | Automated safety check: Pass | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| Security Audit Scannerruvnet/ruflo | 74k | 1 repos | ~823 | Automated safety check: Pass | MIT | |
| Security And Hardeningdzhalaevd/Donatello | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | |
| Securing AI Systemstrilwu/secskills | 157 | — | ~2.9k | Automated safety check: Pass | MIT |
ReJeCtAll/ExpertTeam-Codex
安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
dzhalaevd/Donatello
Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
jabrena/plinth
A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…
addyosmani/agent-skills
Guides a conversation that takes a vague idea through divergent and convergent thinking and ends in a markdown one-pager covering scope and assumptions.
addyosmani/agent-skills
Asks one question at a time, each with a best guess attached, until the agent is about 95 percent sure what you really want, before any plan, spec or code.
addyosmani/agent-skills
Meta-skill for choosing which workflow skill fits the task at hand, plus always-on habits: surface assumptions, stop on confusion, push back, keep it simple and stay in scope.
addyosmani/agent-skills
Connects an agent to a real Chrome instance through the Chrome DevTools MCP server, so it can inspect the DOM, read console errors and profile performance directly.
addyosmani/agent-skills
Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.
addyosmani/agent-skills
Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.
Categories
Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. The skill begins with the stance that every external input is hostile and every authorization check mandatory. Before adding controls, the agent maps trust boundaries, including HTTP requests, form fields, uploads, webhooks, third-party APIs, queues, LLM output and local values such as another process's command line or a path in a job payload.
Security and Hardening fits situations like: building a feature that accepts user input or handles sessions; reviewing a login flow or input handler against the OWASP Top Ten; triaging dependency audit findings or judging a new package's supply-chain risk; adding file uploads, webhooks or payment handling.
Run `npx skills add addyosmani/agent-skills --skill security-and-hardening -a claude-code`. Or copy the skill folder (skills/security-and-hardening in addyosmani/agent-skills) into .claude/skills/security-and-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add addyosmani/agent-skills --skill security-and-hardening -a codex`. Or copy the skill folder (skills/security-and-hardening in addyosmani/agent-skills) into .agents/skills/security-and-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add addyosmani/agent-skills --skill security-and-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-and-hardening, .gemini/skills/security-and-hardening, .github/skills/security-and-hardening and .opencode/skills/security-and-hardening in your project.
Going by SKILL.md and its folder, Security and Hardening needs the command-line tools its instructions call (npm and pnpm).
SKILL.md names 1 domain. As links in the text: genai.owasp.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security and Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security and Hardening: Expert Security (ReJeCtAll/ExpertTeam-Codex, 113 stars), Security And Hardening (penpot/penpot, 61k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Security And Hardening (dzhalaevd/Donatello, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
addyosmani (a GitHub user) maintains it in addyosmani/agent-skills, which has 104,602 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 10, 2026.
Source: addyosmani/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.