Agent skill

Security Hardening

by ancoleman in ancoleman/ai-design-components

Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles.

MITAuto-check passedSecurity

Install Security Hardening

skills CLI
$ npx skills add ancoleman/ai-design-components --skill security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ancoleman/ai-design-components security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-hardening .claude/skills/security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-hardening
GitHub stars
526
Token cost
~3.5k tokens
SKILL.md length
1,024 words
Files
14 (incl. scripts, references)
Skills in repo
75
Repo updated
First seen
Licence
MIT

At a glance

Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles.

  • Works in 5 steps: Default Deny, Explicit Allow → Least Privilege Access → Defense in Depth → …
  • Hardening production infrastructure
  • SKILL.md covers Purpose, When to Use This Skill, Hardening Layers and Core Hardening Principles, plus 5 more sections
  • Runs Python and Shell scripts from its folder; calls trivy, kubectl and docker; reaches raw.githubusercontent.com

What it does

Security Hardening is an agent skill from ancoleman/ai-design-components. Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. Use when hardening production infrastructure, meeting compliance requirements, or implementing defense-in-depth security.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `examples/kubernetes/network-policy-hardened.yaml`, `examples/kubernetes/pod-security-hardened.yaml` and `outputs.yaml`).

It sits in Security, covering Security review, Threat modeling and Secure coding. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.

When your agent uses it

  • Hardening production infrastructure
  • Meeting compliance requirements
  • Implementing defense-in-depth security

Example prompts

  • “Use the security-hardening skill to reduce attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and…”
  • “/security-hardening”

Requirements

  • Python 3
  • A Bash shell
  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Default Deny, Explicit Allow
  2. Least Privilege Access
  3. Defense in Depth
  4. Minimal Attack Surface
  5. Fail Securely

What it can do on your machine

Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • trivy
    • kubectl
    • docker
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Hardening loads about 3.5k tokens when it runs, and up to ~27k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 1,024 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~27k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 1,024 words, ~3,531 tokens.

Download SKILL.mdSave it as .claude/skills/security-hardening/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
security-hardening
description
Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. Use when hardening production infrastructure, meeting compliance requirements, or implementing defense-in-depth security.

Security Hardening

Purpose

Proactive reduction of attack surface across infrastructure layers through systematic configuration hardening, least-privilege enforcement, and automated security controls. Applies industry-standard CIS Benchmarks and zero-trust principles to operating systems, containers, cloud configurations, networks, and databases.

When to Use This Skill

Invoke this skill when:

  • Hardening production infrastructure before deployment
  • Meeting compliance requirements (SOC 2, PCI-DSS, HIPAA, FedRAMP)
  • Implementing zero-trust security architecture
  • Reducing container or cloud misconfiguration risks
  • Preparing for security audits or penetration tests
  • Automating security baseline enforcement
  • Responding to vulnerability scan findings

Hardening Layers

Security hardening applies across five infrastructure layers:

Layer 1: Operating System (Linux)
  • Kernel parameter tuning (sysctl)
  • SSH configuration hardening
  • User and group management
  • File system permissions and mount options
  • Service minimization
  • SELinux/AppArmor enforcement
Layer 2: Container
  • Minimal base images (Chainguard, Distroless, Alpine)
  • Non-root container execution
  • Read-only root filesystems
  • Seccomp and AppArmor profiles
  • Resource limits and capabilities dropping
  • Pod Security Standards enforcement
Layer 3: Cloud Configuration
  • IAM least privilege and MFA enforcement
  • Network security groups and NACL configuration
  • Encryption at rest and in transit
  • Public access blocking
  • Logging and monitoring enablement
  • CSPM (Cloud Security Posture Management) integration
Layer 4: Network
  • Default-deny network policies
  • Network segmentation and micro-segmentation
  • TLS/mTLS enforcement
  • Firewall rule minimization
  • DNS security (DNSSEC, DNS filtering)
Layer 5: Database
  • Authentication and authorization hardening
  • Connection encryption (SSL/TLS)
  • Audit logging enablement
  • Network isolation and access control
  • Role-based permissions with least privilege

Core Hardening Principles

1. Default Deny, Explicit Allow

Start with all access denied, explicitly permit only required operations. Apply default-deny firewall rules and network policies, then allow specific traffic.

2. Least Privilege Access

Grant minimum permissions required for operation. Use RBAC, IAM policies with specific resources, and database roles with limited permissions (no DELETE or DDL unless required).

3. Defense in Depth

Implement multiple overlapping security controls: network firewalls, authentication, authorization, audit logging, and encryption working together.

4. Minimal Attack Surface

Remove unnecessary components, services, and permissions. Use minimal container base images, disable unused services, and drop all Linux capabilities unless required.

5. Fail Securely

On error or misconfiguration, default to secure state. Authentication failures deny access, missing configurations use restrictive defaults, and monitoring failures trigger immediate alerts.

Hardening Priority Framework

Prioritize hardening efforts based on exposure and data sensitivity:

Critical Priority: Internet-Facing Systems

Apply immediately:

  • Container hardening (minimal images, non-root, read-only)
  • Network segmentation (DMZ, WAF, DDoS protection)
  • TLS termination and certificate management
  • Rate limiting and authentication
  • Real-time monitoring and alerting

Tools: Trivy, Falco, ModSecurity, Cloudflare

High Priority: Systems with Sensitive Data

Apply before production:

  • Encryption at rest (AES-256, KMS-managed keys)
  • Strict access controls (RBAC, least privilege)
  • Comprehensive audit logging
  • Database connection encryption
  • Regular vulnerability scanning

Tools: Checkov, Prowler, Lynis, OpenSCAP

Standard Priority: Internal Systems

Apply systematically:

  • OS hardening (CIS Benchmarks)
  • Service minimization
  • Patch management automation
  • Configuration management
  • Basic monitoring

Tools: Ansible, Puppet, kube-bench, docker-bench-security

CIS Benchmark Integration

CIS (Center for Internet Security) Benchmarks provide industry-standard hardening guidance.

Automated CIS Scanning

Docker CIS Benchmark:

bash
docker run --rm -it \
  --net host \
  --pid host \
  --cap-add audit_control \
  -v /var/lib:/var/lib:ro \
  -v /var/run/docker.sock:/var/run/docker.sock:ro \
  -v /etc:/etc:ro \
  docker/docker-bench-security

Kubernetes CIS Benchmark:

bash
kubectl apply -f https://raw.githubusercontent.com/aquasecurity/kube-bench/main/job.yaml
kubectl logs job/kube-bench

Linux CIS Benchmark:

bash
# Using Lynis
lynis audit system --quick

# Using OpenSCAP
oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_cis \
  /usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
Key CIS Controls Mapping
CIS ControlHardening ActionLayer
4.1 Secure ConfigurationApply hardening baselinesAll layers
5.1 Account ManagementEnforce least privilege, MFAOS, Cloud
6.1 Access ControlRBAC, network policiesAll layers
8.1 Audit Log ManagementEnable comprehensive loggingAll layers
13.1 Network MonitoringDeploy IDS/IPS, flow logsNetwork
3.1 Data ProtectionEnable encryption at rest/transitCloud, Database

For detailed CIS control mapping, see references/cis-benchmark-mapping.md.

Container Base Image Selection

Choose base images based on security requirements and compatibility needs:

Use CaseRecommended BaseSizeCVEsTrade-off
Production appsChainguard Images~10MB0Minimal, zero CVEs
Minimal LinuxAlpine~5MBFewSmall, auditable
CompatibilityDistroless~20MBFewNo shell, harder debug
DebuggingDebian slim~80MBMoreHas debugging tools
Legacy appsUbuntu~100MBManyFull compatibility

Production recommendation: Chainguard Images or Distroless for production, Alpine for development.

Show full SKILL.md (400 more words)Show less

Verification and Auditing

Hardening must be verified continuously, not just at implementation.

Automated Security Scanning

Container vulnerability scanning:

bash
# Trivy: Comprehensive vulnerability and misconfiguration scanner
trivy image --severity HIGH,CRITICAL myapp:latest

# Grype: Fast vulnerability scanner
grype myapp:latest

Infrastructure as Code scanning:

bash
# Checkov: Multi-cloud IaC scanner
checkov -d terraform/ --framework terraform

# Terrascan: Policy-as-code scanner
terrascan scan -t terraform -d terraform/

Kubernetes security scanning:

bash
# Kubesec: Security risk analysis
kubesec scan k8s/deployment.yaml

# Polaris: Configuration validation
polaris audit --format=pretty

# Trivy K8s scanning
trivy k8s --report summary cluster

Cloud security posture:

bash
# Prowler: AWS security assessment
prowler aws --services s3 iam ec2

# ScoutSuite: Multi-cloud security audit
scout aws --services s3 iam ec2
Continuous Verification Pipeline

Integrate security scanning into CI/CD:

yaml
# GitHub Actions example
name: Security Hardening Verification

on:
  push:
    branches: [main]
  schedule:
    - cron: '0 0 * * *'  # Daily scan

jobs:
  container-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Build image
        run: docker build -t myapp:test .

      - name: Scan with Trivy
        uses: aquasecurity/trivy-action@master
        with:
          image-ref: 'myapp:test'
          severity: 'CRITICAL,HIGH'
          exit-code: '1'  # Fail on findings

  iac-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Scan IaC with Checkov
        uses: bridgecrewio/checkov-action@master
        with:
          directory: terraform/
          framework: terraform
          soft_fail: false
Compliance Reporting

Generate compliance reports from scan results:

bash
# Generate CIS compliance report
kube-bench run --json > cis-report.json

# Generate vulnerability report
trivy image --format json --output vuln-report.json myapp:latest

# Aggregate reports for compliance dashboard
python scripts/generate-compliance-report.py \
  --cis cis-report.json \
  --vulns vuln-report.json \
  --output compliance-dashboard.html

Automation Tools

Hardening Automation
  • Ansible/Puppet/Chef: Configuration management for OS hardening
  • Terraform/Pulumi: Infrastructure as Code with security modules
  • Cloud Custodian: Cloud resource policy enforcement
  • OPA/Gatekeeper: Kubernetes policy enforcement
  • Kyverno: Kubernetes-native policy management
Scanning Tools
  • Trivy: Universal vulnerability and misconfiguration scanner
  • Checkov: IaC security and compliance scanner
  • Falco: Runtime security monitoring
  • Prowler: AWS security assessment tool
  • ScoutSuite: Multi-cloud security auditing
  • Lynis: Linux security auditing
  • docker-bench-security: Docker CIS benchmark scanner
  • kube-bench: Kubernetes CIS benchmark scanner
Monitoring Tools
  • Falco: Runtime threat detection for containers
  • Sysdig: Container security and monitoring
  • Wazuh: Host and endpoint security monitoring
  • OSSEC: Host-based intrusion detection

Quick Reference: Common Hardening Tasks

Harden SSH Access
bash
# Edit /etc/ssh/sshd_config.d/hardening.conf
PermitRootLogin no
PasswordAuthentication no
PermitEmptyPasswords no
MaxAuthTries 3
X11Forwarding no
ClientAliveInterval 300
ClientAliveCountMax 2

# Restart SSH
systemctl restart sshd
Harden Container Image
dockerfile
# Use minimal base
FROM cgr.dev/chainguard/python:latest

# Non-root user
USER nonroot

# Read-only filesystem
COPY --chown=nonroot:nonroot app /app
WORKDIR /app

# Drop all capabilities
ENTRYPOINT ["python", "-m", "app"]
Harden Kubernetes Pod
yaml
securityContext:
  runAsNonRoot: true
  runAsUser: 65534
  seccompProfile:
    type: RuntimeDefault
  allowPrivilegeEscalation: false
  readOnlyRootFilesystem: true
  capabilities:
    drop: ["ALL"]
Harden AWS S3 Bucket
hcl
resource "aws_s3_bucket_public_access_block" "secure" {
  bucket = aws_s3_bucket.data.id

  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}

resource "aws_s3_bucket_server_side_encryption_configuration" "secure" {
  bucket = aws_s3_bucket.data.id

  rule {
    apply_server_side_encryption_by_default {
      sse_algorithm = "aws:kms"
    }
  }
}
Harden Network with Default Deny
yaml
# Kubernetes NetworkPolicy: deny all ingress
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-ingress
  namespace: production
spec:
  podSelector: {}
  policyTypes:
  - Ingress
Harden Database Access
sql
-- PostgreSQL hardening
REVOKE ALL ON DATABASE app FROM PUBLIC;
REVOKE ALL ON SCHEMA public FROM PUBLIC;

CREATE ROLE app_user WITH LOGIN;
GRANT CONNECT ON DATABASE app TO app_user;
GRANT SELECT, INSERT, UPDATE ON app.orders TO app_user;

-- Force SSL connections
ALTER SYSTEM SET ssl = on;
-- In pg_hba.conf: hostssl all all 0.0.0.0/0 scram-sha-256

Detailed Hardening Guides

For layer-specific hardening guidance:

  • OS hardening: See references/linux-hardening.md
  • Container hardening: See references/container-hardening.md
  • Cloud hardening: See references/cloud-hardening.md
  • Network hardening: See references/network-hardening.md
  • Database hardening: See references/database-hardening.md

For automation scripts:

  • Python automation: See scripts/harden-linux.py
  • Container host setup: See scripts/harden-container-host.sh
  • Compliance reporting: See scripts/generate-compliance-report.py
  • Infrastructure scanning: See scripts/scan-infrastructure.sh

For working examples:

  • Linux configurations: See examples/linux/
  • Kubernetes manifests: See examples/kubernetes/
  • Terraform modules: See examples/terraform/
  • auth-security: Authentication and authorization patterns complement hardening
  • secret-management: Secure secrets handling is essential for hardening
  • kubernetes-operations: Pod security and RBAC hardening
  • infrastructure-as-code: Security scanning in IaC pipelines
  • building-ci-pipelines: Automated security scanning integration
  • observability: Security monitoring and alerting
  • compliance-frameworks: Mapping hardening to compliance requirements

Anti-Patterns to Avoid

❌ Hardening only at deployment

  • Hardening is continuous; scan and verify regularly

❌ Applying all controls blindly

  • Prioritize based on risk and exposure

❌ No verification

  • Always verify hardening is applied and effective

❌ Security through obscurity

  • Obscurity is not security; use proven controls

❌ Hardening without testing

  • Test hardening changes don't break functionality

❌ Manual hardening at scale

  • Automate hardening for consistency and repeatability

Getting Started

  1. Assess current posture: Run CIS benchmark scans
  2. Prioritize: Internet-facing → sensitive data → internal
  3. Apply baseline hardening: OS, container, cloud basics
  4. Automate: Use scripts and IaC for consistency
  5. Verify continuously: Integrate scanning into CI/CD
  6. Monitor: Deploy runtime security monitoring
  7. Iterate: Review and improve hardening regularly

For step-by-step implementation, start with references/linux-hardening.md or references/container-hardening.md based on infrastructure type.

© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references) in skills/security-hardening of ancoleman/ai-design-components.

  • SKILL.md
  • examples/kubernetes/network-policy-hardened.yaml
  • examples/kubernetes/pod-security-hardened.yaml
  • examples/linux/ssh-hardening.conf
  • examples/linux/sysctl-hardening.conf
  • outputs.yaml
  • references/cis-benchmark-mapping.md
  • references/cloud-hardening.md
  • references/container-hardening.md
  • references/database-hardening.md
  • references/linux-hardening.md
  • references/network-hardening.md
  • scripts/harden-linux.py
  • scripts/scan-infrastructure.sh

Open the folder on GitHubat commit 76551b7

Compare with similar skills

Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Hardening this skillancoleman/ai-design-components526—~3.5kAutomated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security And Hardeningdzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.0
Secure By Designooiyeefei/ccc494—~1.5kAutomated safety check: PassMIT
Security Scanericrisco/rsc-harness167—~2.8kAutomated safety check: NotesMIT
Security Assessmentrsmdt/the-startup551—~1.3kAutomated safety check: PassMIT

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Secure By Design

    ooiyeefei/ccc

    Run an enterprise security review of a system design or existing code before it ships.

    494 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    167 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Assessment

    rsmdt/the-startup

    Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment.

    551 GitHub stars~1.3k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from ancoleman/ai-design-components

All 75 skills in this repo
  • Building AI Chat

    ancoleman/ai-design-components

    Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.

    526 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check passed
  • Building Forms

    ancoleman/ai-design-components

    Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.

    526 GitHub stars~3.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Tables

    ancoleman/ai-design-components

    Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.

    526 GitHub stars~1.8k tokensUpdated 10 mo ago
    Auto-check passed
  • Creating Dashboards

    ancoleman/ai-design-components

    Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    Auto-check passed
  • Designing Layouts

    ancoleman/ai-design-components

    Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.

    526 GitHub stars~1.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Displaying Timelines

    ancoleman/ai-design-components

    Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.

    526 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed

Categories

Questions about Security Hardening

What does Security Hardening do?

Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. Security Hardening is an agent skill from ancoleman/ai-design-components. Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles.

When should I use Security Hardening?

Security Hardening fits situations like: hardening production infrastructure; meeting compliance requirements; implementing defense-in-depth security.

How do I install Security Hardening in Claude Code?

Run `npx skills add ancoleman/ai-design-components --skill security-hardening -a claude-code`. Or copy the skill folder (skills/security-hardening in ancoleman/ai-design-components) into .claude/skills/security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Security Hardening in Codex?

Run `npx skills add ancoleman/ai-design-components --skill security-hardening -a codex`. Or copy the skill folder (skills/security-hardening in ancoleman/ai-design-components) into .agents/skills/security-hardening in your project. Codex loads it when a task matches its description.

Can I use Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-hardening, .gemini/skills/security-hardening, .github/skills/security-hardening and .opencode/skills/security-hardening in your project.

What does Security Hardening need to run?

Going by SKILL.md and its folder, Security Hardening needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (trivy, kubectl, docker and python). Our summary lists: Python 3; A Bash shell; Docker.

Does Security Hardening access the network?

SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Hardening use?

Security Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Hardening use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to Security Hardening?

Skills that share tags, products or a category with Security Hardening: Security Audit Scanner (ruvnet/ruflo, 74k stars), Security And Hardening (dzhalaevd/Donatello, 135 stars), Secure By Design (ooiyeefei/ccc, 494 stars) and Security Scan (ericrisco/rsc-harness, 167 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Hardening?

ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.

Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.