Agent skill

Hardening Siti

by ccplugins in ccplugins/awesome-claude-code-plugins

Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app.

Apache-2.0Auto-check: notesSecurity

Install Hardening Siti

skills CLI
$ npx skills add ccplugins/awesome-claude-code-plugins --skill hardening-siti -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccplugins/awesome-claude-code-plugins hardening-siti --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/web-security-guard/skills/hardening-siti .claude/skills/hardening-siti && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hardening-siti
GitHub stars
970
Token cost
~875 tokens
SKILL.md length
366 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app.

  • Works in 8 steps: Security headers → Input e output → Cookie e sessioni → …
  • Costruisci unapp
  • SKILL.md covers Regole obbligatorie and Checklist finale
  • Calls npm

What it does

Hardening Siti is an agent skill from ccplugins/awesome-claude-code-plugins. Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. Copre security headers, CSP, HTTPS, validazione input, cookie, CORS, upload, gestione errori e OWASP Top 10. Trigger - "crea un sito", "costruisci un'app", "metti in sicurezza", "proteggi il sito", "hardening", "security headers", "build a website".

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secure coding and Web application vulnerabilities. The repository describes itself as: Awesome Claude Code plugins — a curated list of slash commands, subagents, MCP servers, and hooks for Claude Code. The licence is Apache-2.0.

When your agent uses it

  • Costruisci unapp
  • Metti in sicurezza
  • Proteggi il sito
  • Security headers

Example prompts

  • “crea un sito”
  • “costruisci un”
  • “metti in sicurezza”
  • “/hardening-siti”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Security headers
  2. Input e output
  3. Cookie e sessioni
  4. CORS
  5. Upload di file
  6. Errori e log
  7. Segreti e dipendenze
  8. HTTPS

What it can do on your machine

Read from SKILL.md and the folder at commit 5bd4f16. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hardening Siti loads about 875 tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 366 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~875

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:49
    repo: usare variabili d'ambiente e file `.env` in `.gitignore`.
  • NoteMentions a .env fileSKILL.md:50
    - Generare sempre `.gitignore` con `.env`, `node_modules`, credenziali.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccplugins/awesome-claude-code-plugins at commit 5bd4f16, republished under its Apache-2.0 licence (© ccplugins). 366 words, ~875 tokens.

Download SKILL.mdSave it as .claude/skills/hardening-siti/SKILL.md (or your agent's skills folder).
name
hardening-siti
description
Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. Copre security headers, CSP, HTTPS, validazione input, cookie, CORS, upload, gestione errori e OWASP Top 10. Trigger - "crea un sito", "costruisci un'app", "metti in sicurezza", "proteggi il sito", "hardening", "security headers", "build a website".

Hardening Siti

Quando si costruisce o si modifica un sito/app, applicare SEMPRE queste regole di sicurezza senza che l'utente debba chiederlo. Segnalare nel riepilogo finale quali protezioni sono state applicate.

Regole obbligatorie

1. Security headers

Applicare su ogni risposta HTML:

Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'

In Node/Express usare helmet(). In Django attivare SECURE_* settings. Su hosting statico (Netlify/Vercel/GitHub Pages) usare il file headers della piattaforma. Adattare la CSP alle risorse reali del sito (CDN, font, analytics) — mai usare unsafe-inline per gli script; preferire nonce o hash.

2. Input e output
  • Validare OGNI input lato server (tipo, lunghezza, formato, whitelist). La validazione client è solo UX.
  • Query al database SOLO parametrizzate o via ORM. Mai concatenare stringhe in SQL.
  • Escapare l'output nei template (autoescaping attivo). Mai inserire input utente in innerHTML, eval, attributi evento o URL senza sanitizzazione.
  • Path file: mai costruire percorsi da input utente; usare ID mappati o path.basename + directory fissa.
  • Cookie di sessione: HttpOnly; Secure; SameSite=Lax (o Strict per azioni sensibili).
  • Rigenerare l'ID sessione al login. Scadenza assoluta e per inattività.
  • Protezione CSRF su ogni form/azione che modifica stato (token CSRF o SameSite + verifica Origin).
4. CORS
  • Mai Access-Control-Allow-Origin: * su endpoint autenticati. Whitelist esplicita di origin.
5. Upload di file
  • Whitelist di estensioni E content-type verificato sul contenuto reale (magic bytes).
  • Rinominare i file con ID casuali, salvarli FUORI dalla web root o su storage separato, limitare la dimensione.
Show full SKILL.md (136 more words)Show less
6. Errori e log
  • Mai mostrare stack trace o dettagli interni all'utente; pagina di errore generica + log lato server.
  • Loggare login, errori di autenticazione, pagamenti e azioni amministrative (senza dati sensibili nei log).
7. Segreti e dipendenze
  • Mai chiavi/API key/password nel codice o nella repo: usare variabili d'ambiente e file .env in .gitignore.
  • Generare sempre .gitignore con .env, node_modules, credenziali.
  • Usare versioni aggiornate delle dipendenze; consigliare npm audit / pip-audit (vedi skill sicurezza-github per l'automazione).
8. HTTPS
  • Tutto il traffico in HTTPS, redirect da HTTP, HSTS attivo. In sviluppo locale va bene HTTP ma documentare la differenza.

Checklist finale

Prima di consegnare un sito/app, verificare: headers presenti, query parametrizzate, validazione server, cookie sicuri, CSRF, niente segreti nel codice, errori generici, .gitignore corretto. Elencare all'utente le protezioni applicate e gli eventuali punti che richiedono configurazione sul suo hosting.

© ccplugins, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/web-security-guard/skills/hardening-siti of ccplugins/awesome-claude-code-plugins.

Open the folder on GitHubat commit 5bd4f16

Compare with similar skills

Hardening Siti next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hardening Siti compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hardening Siti this skillccplugins/awesome-claude-code-plugins970—~875Automated safety check: NotesApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Fix Strix Security Findingsusestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Security and Hardeningaddyosmani/agent-skills103k1 repos~4.4kAutomated safety check: NotesMIT

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    67k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    103k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from ccplugins/awesome-claude-code-plugins

All 68 skills in this repo
  • AI Meeting

    ccplugins/awesome-claude-code-plugins

    Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.

    970 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Fastapi App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.

    970 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Flutter App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.

    970 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Nextjs App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Next.js (App Router, TypeScript) web app with current packages and no deprecated APIs.

    970 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Dev Report

    ccplugins/awesome-claude-code-plugins

    Write up a coding session for a non-technical stakeholder — the context, what was built, and the engineering reasoning behind it — the way a senior engineer briefs a product manager who does not…

    970 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Difesa Attacchi

    ccplugins/awesome-claude-code-plugins

    Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che…

    970 GitHub stars~781 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hardening Siti

What does Hardening Siti do?

Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. Hardening Siti is an agent skill from ccplugins/awesome-claude-code-plugins. Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app.

When should I use Hardening Siti?

Hardening Siti fits situations like: costruisci unapp; metti in sicurezza; proteggi il sito; security headers.

How do I install Hardening Siti in Claude Code?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill hardening-siti -a claude-code`. Or copy the skill folder (plugins/web-security-guard/skills/hardening-siti in ccplugins/awesome-claude-code-plugins) into .claude/skills/hardening-siti in your project. Claude Code loads it when a task matches its description.

How do I install Hardening Siti in Codex?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill hardening-siti -a codex`. Or copy the skill folder (plugins/web-security-guard/skills/hardening-siti in ccplugins/awesome-claude-code-plugins) into .agents/skills/hardening-siti in your project. Codex loads it when a task matches its description.

Can I use Hardening Siti in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccplugins/awesome-claude-code-plugins --skill hardening-siti -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hardening-siti, .gemini/skills/hardening-siti, .github/skills/hardening-siti and .opencode/skills/hardening-siti in your project.

What does Hardening Siti need to run?

Going by SKILL.md and its folder, Hardening Siti needs the command-line tools its instructions call (npm).

Does Hardening Siti access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Hardening Siti safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Hardening Siti use?

Hardening Siti is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hardening Siti use?

About 875 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hardening Siti?

Skills that share tags, products or a category with Hardening Siti: Security And Hardening (penpot/penpot, 61k stars), Fix Strix Security Findings (usestrix/strix, 67k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hardening Siti?

ccplugins (a GitHub organization) maintains it in ccplugins/awesome-claude-code-plugins, which has 970 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on August 12, 2026.

Source: ccplugins/awesome-claude-code-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.