Agent skill

Security Hardening

by chmonitor in chmonitor/chmonitor

RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.

GPL-3.0Auto-check passedBackend & APIs

Install Security Hardening

skills CLI
$ npx skills add chmonitor/chmonitor --skill security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install chmonitor/chmonitor security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-hardening .claude/skills/security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-hardening
GitHub stars
299
Token cost
~440 tokens
SKILL.md length
204 words
Files
1
Skills in repo
53
Repo updated
First seen
Licence
GPL-3.0

At a glance

RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.

  • Tasks that involve Authorization and RBAC
  • SKILL.md covers RBAC (Role-Based Access Control), Row Policies, Quotas and Network Security, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Security review

What it does

Security Hardening is an agent skill from chmonitor/chmonitor. RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.

Its SKILL.md is about 440 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC, Security review and Network security. The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve Security review
  • Tasks that involve Network security

Example prompts

  • “/security-hardening”

What it can do on your machine

Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Hardening loads about 440 tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 204 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~440

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 204 words, ~440 tokens.

Download SKILL.mdSave it as .claude/skills/security-hardening/SKILL.md (or your agent's skills folder).
name
security-hardening
description
RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.

Security Hardening

RBAC (Role-Based Access Control)

  • Create roles: CREATE ROLE analyst
  • Grant permissions: GRANT SELECT ON db.* TO analyst
  • Assign to users: GRANT analyst TO user1
  • Hierarchical: roles can inherit from other roles
  • Check grants: SHOW GRANTS FOR user1
  • Inspect user: SHOW CREATE USER username
  • Password rotation: ALTER USER username IDENTIFIED BY 'new_password'

Row Policies

  • Restrict row access per user: CREATE ROW POLICY p ON db.table FOR SELECT USING tenant_id = currentUser()
  • Policies are AND-ed together
  • Use for multi-tenant data isolation
  • Check policies: system.row_policies

Quotas

  • Limit resource usage per user/IP: CREATE QUOTA q FOR user1 ... LIMIT max_queries = 100
  • Quota intervals: per hour, per day, etc.
  • Limits: max_queries, max_result_rows, max_read_rows, max_execution_time
  • Monitor: system.quota_usage

Network Security

  • Restrict user access by IP: CREATE USER u HOST IP '10.0.0.0/8'
  • Use TLS for client connections
  • Inter-server encryption for replication
  • Separate ports for internal vs external access

Audit Logging

  • Enable system.session_log for login tracking
  • system.query_log records all queries with user info
  • system.text_log for server-level events
  • Configure log retention with TTL

Best Practices

  • Principle of least privilege — grant only needed permissions
  • Use roles, not direct user grants
  • Separate read-only and admin users
  • Enable quotas for all non-admin users
  • Regular audit of grants and access patterns
  • Use readonly = 1 setting for monitoring connections

© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security-hardening of chmonitor/chmonitor.

Open the folder on GitHubat commit fc39ef0

Compare with similar skills

Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Hardening this skillchmonitor/chmonitor299—~440Automated safety check: PassGPL-3.0
Robotics Securityarpitg1304/robotics-agent-skills368—~7.8kAutomated safety check: WarnApache-2.0
Sec Checkwaynesutton/markdown-site628—~753Automated safety check: PassMIT
Gamma Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: NotesMIT
Hex Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: PassMIT
Hootsuite Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~876Automated safety check: NotesMIT

Similar skills

  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    368 GitHub stars~7.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    628 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Gamma Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Implement security best practices for Gamma integration. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Hex Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Hex security best practices for secrets and access control.

    2.8k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Hootsuite Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Hootsuite security best practices for secrets and access control.

    2.8k GitHub stars~876 tokensUpdated today
    Backend & APIsAuto-check: notes
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes

More from chmonitor/chmonitor

All 53 skills in this repo
  • Hyperframes Creative

    chmonitor/chmonitor

    Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.

    299 GitHub starsUsed in 5 repos~1.3k tokens
    Auto-check passed
  • Hyperframes Media

    chmonitor/chmonitor

    Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…

    299 GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check: notes
  • Remotion To Hyperframes

    chmonitor/chmonitor

    Port an existing Remotion (React) composition to HyperFrames HTML.

    299 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Music To Video

    chmonitor/chmonitor

    A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.

    299 GitHub starsUsed in 1 repo~4k tokens
    Auto-check: notes
  • Hyperframes Animation

    chmonitor/chmonitor

    All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…

    299 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • Faceless Explainer

    chmonitor/chmonitor

    turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…

    299 GitHub stars~4.5k tokensUpdated 3 days ago
    Auto-check: notes

Questions about Security Hardening

What does Security Hardening do?

RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices. Security Hardening is an agent skill from chmonitor/chmonitor. RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.

When should I use Security Hardening?

Security Hardening fits situations like: tasks that involve Authorization and RBAC; tasks that involve Security review; tasks that involve Network security.

How do I install Security Hardening in Claude Code?

Run `npx skills add chmonitor/chmonitor --skill security-hardening -a claude-code`. Or copy the skill folder (.agents/skills/security-hardening in chmonitor/chmonitor) into .claude/skills/security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Security Hardening in Codex?

Run `npx skills add chmonitor/chmonitor --skill security-hardening -a codex`. Or copy the skill folder (.agents/skills/security-hardening in chmonitor/chmonitor) into .agents/skills/security-hardening in your project. Codex loads it when a task matches its description.

Can I use Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-hardening, .gemini/skills/security-hardening, .github/skills/security-hardening and .opencode/skills/security-hardening in your project.

What does Security Hardening need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Hardening is instructions for the agent only.

Does Security Hardening access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Hardening use?

Security Hardening is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Hardening use?

About 440 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Hardening?

Skills that share tags, products or a category with Security Hardening: Robotics Security (arpitg1304/robotics-agent-skills, 368 stars), Sec Check (waynesutton/markdown-site, 628 stars), Gamma Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Hex Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Hardening?

chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 299 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.

Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.