Security Review Checklist
ZeroDeng01/sublinkPro
Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.
Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cb-security-hardening .claude/skills/cb-security-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cb-security-hardening" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardening into .claude/skills/cb-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-security-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/cb-security-hardening .agents/skills/cb-security-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cb-security-hardening" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardening into .agents/skills/cb-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-security-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/cb-security-hardening .cursor/skills/cb-security-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cb-security-hardening" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardening into .cursor/skills/cb-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-security-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BlkLeg/CircuitBreaker.git --path .claude/skills/cb-security-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/cb-security-hardening .gemini/skills/cb-security-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cb-security-hardening" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardening into .gemini/skills/cb-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-security-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/cb-security-hardening .github/skills/cb-security-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cb-security-hardening" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardening into .github/skills/cb-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-security-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/cb-security-hardening .opencode/skills/cb-security-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cb-security-hardening" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-security-hardening into .opencode/skills/cb-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-security-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cb-security-hardeningEnforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.
Cb Security Hardening is an agent skill from BlkLeg/CircuitBreaker. Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. Use when modifying authentication logic, security headers, Docker configuration, credential handling, session management, URL validation, WebSocket auth, NATS bus auth, agent enrollment, or any code in core/security.py, core/rbac.py, core/agentcrypto.py, core/networkacl.py, middleware/securityheaders.py, core/urlvalidation.py, docker-compose.yml, or docker/{nginx.mono.conf,entrypoint-mono.sh,supervisord.mono.conf}.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Security review, Containers and Authentication. It works with Docker and NGINX. The repository describes itself as: Bring your homelab to life. A self-hosted IPAM and service mapper that visualizes complex hardware, compute, and network relationships in real-time. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fc44f2e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockeropensslFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CB_DB_PASSWORDCB_VAULT_KEYNATS_AUTH_TOKENCB_API_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cb Security Hardening loads about 2.1k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 737 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from BlkLeg/CircuitBreaker at commit fc44f2e, republished under its MIT licence (© BlkLeg). 737 words, ~2,106 tokens.
.claude/skills/cb-security-hardening/SKILL.md (or your agent's skills folder).Codified from SECURITY_STANDING-1.md and SECURITY_STANDING-2.md audit reports.
Authentication cannot be disabled after OOBE. The auth_enabled column on AppSettings is a one-way OOBE completion marker only.
Rules:
auth_enabled is False post-bootstrapget_optional_user returns None only when no jwt_secret exists (pre-OOBE)require_write_auth always raises 401 when user_id is Nonerequire_role / require_scope in core/rbac.py never return a synthetic admin for unauthenticated requestsws_discovery.py, ws_telemetry.py, ws_topology.py, ws_monitors.py, ws_agents.py) must validate JWT — no anonymous sentinel when auth_enabled is False. The one deliberate exception is the agent /enroll and /link sockets, mounted without Depends(require_auth) because the Noise IK handshake performed inside them is that router's authentication (core/agent_crypto.py) — do not "fix" it by adding the dependencyAppSettingsUpdate schema must not include auth_enabledAuthContext (apps/frontend/src, JavaScript/JSX) has no authEnabled state or setAuthEnabled — auth is always on!isAuthenticated redirects to /login (not authEnabled && !isAuthenticated)All sensitive token comparisons must use hmac.compare_digest, never ==.
# Correct
import hmac
if api_token and raw_token and hmac.compare_digest(raw_token, api_token):
return 0
# Wrong — timing side-channel
if api_token and raw_token == api_token:
return 0Applies to: CB_API_TOKEN, any bearer token comparison, webhook signature verification.
When a user changes their password, all other active sessions must be revoked.
from app.services.user_service import _hash_token, revoke_all_sessions
token = _extract_token(request)
except_hash = _hash_token(token) if token else None
revoke_all_sessions(db, user_id, except_token_hash=except_hash)An audit log entry (action="password_changed") must also be written.
core/url_validation.py must reject all non-HTTP(S) schemes before any IP resolution:
_ALLOWED_SCHEMES = frozenset({"http", "https"})
scheme = (parsed.scheme or "").lower()
if scheme not in _ALLOWED_SCHEMES:
raise ValueError(f"URL scheme '{scheme}' is not allowed.")This blocks file://, gopher://, ftp://, dict://, etc.
All responses must include these headers (set in both middleware/security_headers.py and docker/nginx.mono.conf):
| Header | Value |
|---|---|
| Content-Security-Policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'strict-dynamic'; ... |
| X-Content-Type-Options | nosniff |
| X-Frame-Options | DENY |
| Referrer-Policy | strict-origin-when-cross-origin |
| Strict-Transport-Security | max-age=63072000; includeSubDomains |
| Permissions-Policy | camera=(), microphone=(), geolocation=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=() |
Rules:
'strict-dynamic' must remain in script-src to progressively override 'unsafe-inline'frame-ancestors 'none' from CSPX-Frame-Options from DENYdocker/nginx.mono.conf must have two server blocks:
301 redirect to https:// for all paths except /api/v1/health (exempt for Docker healthchecks)Never serve application content over plain HTTP.
The Docker socket is not mounted by default in docker-compose.yml.
Opt-in methods:
docker compose -f docker-compose.yml -f docker-compose.socket.yml up -dCB_DOCKER_HOST=tcp://proxy:2375Backend Docker discovery code (docker_discovery.py, discovery_safe.py) must check CB_DOCKER_HOST env var first, falling back to the local socket only if present.
docker-compose.yml must specify:
read_only: true
tmpfs:
- /tmp:size=100M
- /run:size=10M
- /var/log:size=50M
- /var/lib/nginx:size=10M
- /var/lib/postgresql:size=10MOnly /data is a persistent writable bind mount. Never add writable volume mounts without explicit justification.
Embedded Redis must use --requirepass. The password is:
openssl rand -base64 32) to /data/.redis_passCB_REDIS_URL by docker/entrypoint-mono.sh when not user-supplieddocker/supervisord.mono.conf at Redis process startNever run Redis without requirepass inside the container.
The Fernet vault key auto-rotates via an APScheduler daily job (04:30):
vault_key_rotation_days (default 90) and vault_key_rotated_at from AppSettingsrotate_vault_key() which re-encrypts all credentials, persists the new key, and hot-swaps the in-memory vaultWhen modifying vault-related code, ensure the rotation path remains functional and tested.
Anything newly stored with vault.encrypt must be added to rotate_vault_key.
A location the rotation skips survives as ciphertext the new key cannot read.
The agent server keys were skipped, and the first rotation broke every agent
handshake (issue #168). tests/services/test_vault_rotation_coverage.py fails
when a module that encrypts with the vault is missing from its
ROTATED_BY_MODULE map; add the location to the rotation and seed it in that
test, never just silence the map.
docker-compose.yml must fail-fast on missing secrets:
environment:
- CB_DB_PASSWORD=${CB_DB_PASSWORD:?Set CB_DB_PASSWORD}
- CB_VAULT_KEY=${CB_VAULT_KEY:?Set CB_VAULT_KEY}
- NATS_AUTH_TOKEN=${NATS_AUTH_TOKEN:?Set NATS_AUTH_TOKEN for internal bus auth}Never remove the :? error syntax. Never add defaults for secret values.
Docker containers must run with:
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
cap_add:
- NET_RAW
- NET_BIND_SERVICE
- CHOWN
- SETUID
- SETGID
- DAC_OVERRIDE
- KILL # root supervisord must signal its breaker-owned programs on stop
stop_grace_period: 60s # > the largest stopwaitsecs in supervisord.mono.confNever add capabilities without documenting why. KILL is there because
supervisord runs as root and its programs run as breaker. Without CAP_KILL,
every SIGTERM on docker stop fails with EPERM, Docker SIGKILLs the container,
and Postgres needs crash recovery. tests/build/test_mono_stop_is_clean.py
enforces both lines.
When reviewing security-sensitive changes:
== for token/secret comparison — use hmac.compare_digestread_only: true on container, only /data writablerequirepass${VAR:?error} in compose — no defaults© BlkLeg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/cb-security-hardening of BlkLeg/CircuitBreaker.
Open the folder on GitHubat commit fc44f2e
Cb Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cb Security Hardening this skillBlkLeg/CircuitBreaker | 201 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Security Review ChecklistZeroDeng01/sublinkPro | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Code Securitysemgrep/skills | 324 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Odoo Docker Deploymentsickn33/agentic-awesome-skills | 47k | 2 repos | ~1.2k | Automated safety check: Notes | MIT | |
| Memstack Deployment Hetzner Setupcwinvestments/memstack | 423 | — | ~4.1k | Automated safety check: Notes | Proprietary | |
| Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package | 189 | — | ~2.4k | Automated safety check: Notes | MIT |
ZeroDeng01/sublinkPro
Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
sickn33/agentic-awesome-skills
Production-ready Docker and docker-compose setup for Odoo with PostgreSQL, persistent volumes, environment-based configuration, and Nginx reverse proxy.
cwinvestments/memstack
A skill your agent uses when the user says 'Hetzner', 'VPS setup', 'server provisioning', 'deploy to VPS', 'hetzner-setup', 'cloud server', or needs to provision, harden, and deploy applications to…
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.
francis-build/francis
Invoke on ANY Francis task — routes, WebSocket, SSE, streaming, real-time, chat, Plug middleware, auth, CORS, static assets, deploy, Dockerfile, JSON API, uploads, sessions, use Francis, ws/2…
BlkLeg/CircuitBreaker
How Circuit Breaker is built, tested, packaged, and kept secret-safe — the make dev/verify/test targets, the PostgreSQL integration test database and its fixtures, the mono Docker image and native…
BlkLeg/CircuitBreaker
Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.
BlkLeg/CircuitBreaker
How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…
BlkLeg/CircuitBreaker
How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…
BlkLeg/CircuitBreaker
The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…
Categories
Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. Cb Security Hardening is an agent skill from BlkLeg/CircuitBreaker. Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.
Cb Security Hardening fits situations like: modifying authentication logic; security headers; Docker configuration; credential handling.
Run `npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a claude-code`. Or copy the skill folder (.claude/skills/cb-security-hardening in BlkLeg/CircuitBreaker) into .claude/skills/cb-security-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a codex`. Or copy the skill folder (.claude/skills/cb-security-hardening in BlkLeg/CircuitBreaker) into .agents/skills/cb-security-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cb-security-hardening, .gemini/skills/cb-security-hardening, .github/skills/cb-security-hardening and .opencode/skills/cb-security-hardening in your project.
Going by SKILL.md and its folder, Cb Security Hardening needs the command-line tools its instructions call (docker and openssl) and credentials named CB_DB_PASSWORD, CB_VAULT_KEY, NATS_AUTH_TOKEN and CB_API_TOKEN. Our summary lists: Python 3; Docker; A credential in CB_API_TOKEN; A credential in CB_VAULT_KEY.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cb Security Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cb Security Hardening: Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars), Code Security (semgrep/skills, 324 stars), Odoo Docker Deployment (sickn33/agentic-awesome-skills, 47k stars) and Memstack Deployment Hetzner Setup (cwinvestments/memstack, 423 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BlkLeg (a GitHub user) maintains it in BlkLeg/CircuitBreaker, which has 201 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.
Source: BlkLeg/CircuitBreaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.