Agent skill

Cb Security Hardening

by BlkLeg in BlkLeg/CircuitBreaker

Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

MITAuto-check passedBackend & APIs

Install Cb Security Hardening

skills CLI
$ npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BlkLeg/CircuitBreaker cb-security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cb-security-hardening .claude/skills/cb-security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cb-security-hardening
GitHub stars
201
Token cost
~2.1k tokens
SKILL.md length
737 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

  • Works in 12 steps: Authentication Is Always Enforced → Timing-Safe Token Comparison → Session Revocation on Password Change → …
  • Modifying authentication logic
  • SKILL.md covers 1. Authentication Is Always…, 2. Timing-Safe Token Comparison, 3. Session Revocation on… and 4. SSRF Prevention — URL…, plus 10 more sections
  • Calls docker and openssl; needs CB_DB_PASSWORD and CB_VAULT_KEY

What it does

Cb Security Hardening is an agent skill from BlkLeg/CircuitBreaker. Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. Use when modifying authentication logic, security headers, Docker configuration, credential handling, session management, URL validation, WebSocket auth, NATS bus auth, agent enrollment, or any code in core/security.py, core/rbac.py, core/agentcrypto.py, core/networkacl.py, middleware/securityheaders.py, core/urlvalidation.py, docker-compose.yml, or docker/{nginx.mono.conf,entrypoint-mono.sh,supervisord.mono.conf}.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Security review, Containers and Authentication. It works with Docker and NGINX. The repository describes itself as: Bring your homelab to life. A self-hosted IPAM and service mapper that visualizes complex hardware, compute, and network relationships in real-time. The licence is MIT.

When your agent uses it

  • Modifying authentication logic
  • Security headers
  • Docker configuration
  • Credential handling

Example prompts

  • “Use the cb-security-hardening skill to enforce Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx”
  • “/cb-security-hardening”

Requirements

  • Python 3
  • Docker
  • A credential in CB_API_TOKEN
  • A credential in CB_VAULT_KEY

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Authentication Is Always Enforced
  2. Timing-Safe Token Comparison
  3. Session Revocation on Password Change
  4. SSRF Prevention — URL Scheme Validation
  5. Security Headers
  6. Transport Security — HTTPS Redirect
  7. Docker Socket Isolation
  8. Container Filesystem Immutability
  9. Redis Authentication
  10. Vault Key Rotation
  11. Mandatory Secrets
  12. Capability Restrictions

What it can do on your machine

Read from SKILL.md and the folder at commit fc44f2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CB_DB_PASSWORD
    • CB_VAULT_KEY
    • NATS_AUTH_TOKEN
    • CB_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cb Security Hardening loads about 2.1k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 737 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BlkLeg/CircuitBreaker at commit fc44f2e, republished under its MIT licence (© BlkLeg). 737 words, ~2,106 tokens.

Download SKILL.mdSave it as .claude/skills/cb-security-hardening/SKILL.md (or your agent's skills folder).
name
cb-security-hardening
description
Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. Use when modifying authentication logic, security headers, Docker configuration, credential handling, session management, URL validation, WebSocket auth, NATS bus auth, agent enrollment, or any code in core/security.py, core/rbac.py, core/agent_crypto.py, core/network_acl.py, middleware/security_headers.py, core/url_validation.py, docker-compose.yml, or docker/{nginx.mono.conf,entrypoint-mono.sh,supervisord.mono.conf}.

Circuit Breaker — Security Hardening Conventions

Codified from SECURITY_STANDING-1.md and SECURITY_STANDING-2.md audit reports.

1. Authentication Is Always Enforced

Authentication cannot be disabled after OOBE. The auth_enabled column on AppSettings is a one-way OOBE completion marker only.

Rules:

  • Never add a code path that skips auth when auth_enabled is False post-bootstrap
  • get_optional_user returns None only when no jwt_secret exists (pre-OOBE)
  • require_write_auth always raises 401 when user_id is None
  • require_role / require_scope in core/rbac.py never return a synthetic admin for unauthenticated requests
  • WebSocket handlers (ws_discovery.py, ws_telemetry.py, ws_topology.py, ws_monitors.py, ws_agents.py) must validate JWT — no anonymous sentinel when auth_enabled is False. The one deliberate exception is the agent /enroll and /link sockets, mounted without Depends(require_auth) because the Noise IK handshake performed inside them is that router's authentication (core/agent_crypto.py) — do not "fix" it by adding the dependency
  • The AppSettingsUpdate schema must not include auth_enabled
  • Frontend AuthContext (apps/frontend/src, JavaScript/JSX) has no authEnabled state or setAuthEnabled — auth is always on
  • Frontend route gating: !isAuthenticated redirects to /login (not authEnabled && !isAuthenticated)

2. Timing-Safe Token Comparison

All sensitive token comparisons must use hmac.compare_digest, never ==.

python
# Correct
import hmac
if api_token and raw_token and hmac.compare_digest(raw_token, api_token):
    return 0

# Wrong — timing side-channel
if api_token and raw_token == api_token:
    return 0

Applies to: CB_API_TOKEN, any bearer token comparison, webhook signature verification.

3. Session Revocation on Password Change

When a user changes their password, all other active sessions must be revoked.

python
from app.services.user_service import _hash_token, revoke_all_sessions

token = _extract_token(request)
except_hash = _hash_token(token) if token else None
revoke_all_sessions(db, user_id, except_token_hash=except_hash)

An audit log entry (action="password_changed") must also be written.

4. SSRF Prevention — URL Scheme Validation

core/url_validation.py must reject all non-HTTP(S) schemes before any IP resolution:

python
_ALLOWED_SCHEMES = frozenset({"http", "https"})

scheme = (parsed.scheme or "").lower()
if scheme not in _ALLOWED_SCHEMES:
    raise ValueError(f"URL scheme '{scheme}' is not allowed.")

This blocks file://, gopher://, ftp://, dict://, etc.

5. Security Headers

All responses must include these headers (set in both middleware/security_headers.py and docker/nginx.mono.conf):

HeaderValue
Content-Security-Policydefault-src 'self'; script-src 'self' 'unsafe-inline' 'strict-dynamic'; ...
X-Content-Type-Optionsnosniff
X-Frame-OptionsDENY
Referrer-Policystrict-origin-when-cross-origin
Strict-Transport-Securitymax-age=63072000; includeSubDomains
Permissions-Policycamera=(), microphone=(), geolocation=(), payment=(), usb=(), magnetometer=(), gyroscope=(), accelerometer=()

Rules:

  • 'strict-dynamic' must remain in script-src to progressively override 'unsafe-inline'
  • Never remove frame-ancestors 'none' from CSP
  • Never weaken X-Frame-Options from DENY

6. Transport Security — HTTPS Redirect

docker/nginx.mono.conf must have two server blocks:

  1. Port 80 — returns 301 redirect to https:// for all paths except /api/v1/health (exempt for Docker healthchecks)
  2. Port 443 — main HTTPS server with TLS termination

Never serve application content over plain HTTP.

7. Docker Socket Isolation

The Docker socket is not mounted by default in docker-compose.yml.

Opt-in methods:

  1. Override file: docker compose -f docker-compose.yml -f docker-compose.socket.yml up -d
  2. TCP proxy: set CB_DOCKER_HOST=tcp://proxy:2375

Backend Docker discovery code (docker_discovery.py, discovery_safe.py) must check CB_DOCKER_HOST env var first, falling back to the local socket only if present.

8. Container Filesystem Immutability

docker-compose.yml must specify:

yaml
read_only: true
tmpfs:
  - /tmp:size=100M
  - /run:size=10M
  - /var/log:size=50M
  - /var/lib/nginx:size=10M
  - /var/lib/postgresql:size=10M

Only /data is a persistent writable bind mount. Never add writable volume mounts without explicit justification.

9. Redis Authentication

Embedded Redis must use --requirepass. The password is:

  • Auto-generated at first container start (openssl rand -base64 32) to /data/.redis_pass
  • Injected into CB_REDIS_URL by docker/entrypoint-mono.sh when not user-supplied
  • Read by docker/supervisord.mono.conf at Redis process start

Never run Redis without requirepass inside the container.

Show full SKILL.md (275 more words)Show less

10. Vault Key Rotation

The Fernet vault key auto-rotates via an APScheduler daily job (04:30):

  • Reads vault_key_rotation_days (default 90) and vault_key_rotated_at from AppSettings
  • Calls rotate_vault_key() which re-encrypts all credentials, persists the new key, and hot-swaps the in-memory vault

When modifying vault-related code, ensure the rotation path remains functional and tested.

Anything newly stored with vault.encrypt must be added to rotate_vault_key. A location the rotation skips survives as ciphertext the new key cannot read. The agent server keys were skipped, and the first rotation broke every agent handshake (issue #168). tests/services/test_vault_rotation_coverage.py fails when a module that encrypts with the vault is missing from its ROTATED_BY_MODULE map; add the location to the rotation and seed it in that test, never just silence the map.

11. Mandatory Secrets

docker-compose.yml must fail-fast on missing secrets:

yaml
environment:
  - CB_DB_PASSWORD=${CB_DB_PASSWORD:?Set CB_DB_PASSWORD}
  - CB_VAULT_KEY=${CB_VAULT_KEY:?Set CB_VAULT_KEY}
  - NATS_AUTH_TOKEN=${NATS_AUTH_TOKEN:?Set NATS_AUTH_TOKEN for internal bus auth}

Never remove the :? error syntax. Never add defaults for secret values.

12. Capability Restrictions

Docker containers must run with:

yaml
security_opt:
  - no-new-privileges:true
cap_drop:
  - ALL
cap_add:
  - NET_RAW
  - NET_BIND_SERVICE
  - CHOWN
  - SETUID
  - SETGID
  - DAC_OVERRIDE
  - KILL   # root supervisord must signal its breaker-owned programs on stop
stop_grace_period: 60s   # > the largest stopwaitsecs in supervisord.mono.conf

Never add capabilities without documenting why. KILL is there because supervisord runs as root and its programs run as breaker. Without CAP_KILL, every SIGTERM on docker stop fails with EPERM, Docker SIGKILLs the container, and Postgres needs crash recovery. tests/build/test_mono_stop_is_clean.py enforces both lines.

Validation Checklist

When reviewing security-sensitive changes:

  • No == for token/secret comparison — use hmac.compare_digest
  • No code path allows unauthenticated writes post-OOBE
  • WebSocket handlers validate JWT (no anonymous bypass)
  • URL inputs validate scheme is HTTP(S) only
  • All security headers present in both middleware and nginx
  • Docker socket not mounted in default compose
  • read_only: true on container, only /data writable
  • Redis uses requirepass
  • Secrets use ${VAR:?error} in compose — no defaults
  • Password changes revoke other sessions
  • Vault rotation scheduler job intact

Reference

© BlkLeg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cb-security-hardening of BlkLeg/CircuitBreaker.

Open the folder on GitHubat commit fc44f2e

Compare with similar skills

Cb Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cb Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cb Security Hardening this skillBlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT
Security Review ChecklistZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMIT
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence
Odoo Docker Deploymentsickn33/agentic-awesome-skills47k2 repos~1.2kAutomated safety check: NotesMIT
Memstack Deployment Hetzner Setupcwinvestments/memstack423—~4.1kAutomated safety check: NotesProprietary
Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package189—~2.4kAutomated safety check: NotesMIT

Similar skills

  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Odoo Docker Deployment

    sickn33/agentic-awesome-skills

    Production-ready Docker and docker-compose setup for Odoo with PostgreSQL, persistent volumes, environment-based configuration, and Nginx reverse proxy.

    47k GitHub starsUsed in 2 repos~1.2k tokens
    DevOps & CloudAuto-check: notes
  • Memstack Deployment Hetzner Setup

    cwinvestments/memstack

    A skill your agent uses when the user says 'Hetzner', 'VPS setup', 'server provisioning', 'deploy to VPS', 'hetzner-setup', 'cloud server', or needs to provision, harden, and deploy applications to…

    423 GitHub stars~4.1k tokensUpdated 14 days ago
    DevOps & CloudAuto-check: notes
  • Frappe Ops Deployment

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.

    189 GitHub stars~2.4k tokensUpdated 23 days ago
    DevOps & CloudAuto-check: notes
  • Francis Thinking

    francis-build/francis

    Invoke on ANY Francis task — routes, WebSocket, SSE, streaming, real-time, chat, Plug middleware, auth, CORS, static assets, deploy, Dockerfile, JSON API, uploads, sessions, use Francis, ws/2…

    107 GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from BlkLeg/CircuitBreaker

  • Cb Build Test

    BlkLeg/CircuitBreaker

    How Circuit Breaker is built, tested, packaged, and kept secret-safe — the make dev/verify/test targets, the PostgreSQL integration test database and its fixtures, the mono Docker image and native…

    201 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Cb Code Quality

    BlkLeg/CircuitBreaker

    Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.

    201 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Cb Realtime API

    BlkLeg/CircuitBreaker

    How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…

    201 GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Cb Release

    BlkLeg/CircuitBreaker

    How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…

    201 GitHub stars~1.8k tokensUpdated 5 days ago
    Auto-check passed
  • Cb Automation

    BlkLeg/CircuitBreaker

    The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…

    201 GitHub stars~2.4k tokensUpdated 5 days ago
    Auto-check passed

Works with

Questions about Cb Security Hardening

What does Cb Security Hardening do?

Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. Cb Security Hardening is an agent skill from BlkLeg/CircuitBreaker. Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

When should I use Cb Security Hardening?

Cb Security Hardening fits situations like: modifying authentication logic; security headers; Docker configuration; credential handling.

How do I install Cb Security Hardening in Claude Code?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a claude-code`. Or copy the skill folder (.claude/skills/cb-security-hardening in BlkLeg/CircuitBreaker) into .claude/skills/cb-security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Cb Security Hardening in Codex?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a codex`. Or copy the skill folder (.claude/skills/cb-security-hardening in BlkLeg/CircuitBreaker) into .agents/skills/cb-security-hardening in your project. Codex loads it when a task matches its description.

Can I use Cb Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BlkLeg/CircuitBreaker --skill cb-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cb-security-hardening, .gemini/skills/cb-security-hardening, .github/skills/cb-security-hardening and .opencode/skills/cb-security-hardening in your project.

What does Cb Security Hardening need to run?

Going by SKILL.md and its folder, Cb Security Hardening needs the command-line tools its instructions call (docker and openssl) and credentials named CB_DB_PASSWORD, CB_VAULT_KEY, NATS_AUTH_TOKEN and CB_API_TOKEN. Our summary lists: Python 3; Docker; A credential in CB_API_TOKEN; A credential in CB_VAULT_KEY.

Does Cb Security Hardening access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cb Security Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cb Security Hardening use?

Cb Security Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cb Security Hardening use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cb Security Hardening?

Skills that share tags, products or a category with Cb Security Hardening: Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars), Code Security (semgrep/skills, 324 stars), Odoo Docker Deployment (sickn33/agentic-awesome-skills, 47k stars) and Memstack Deployment Hetzner Setup (cwinvestments/memstack, 423 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cb Security Hardening?

BlkLeg (a GitHub user) maintains it in BlkLeg/CircuitBreaker, which has 201 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.

Source: BlkLeg/CircuitBreaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.