Harness Evolution Feedback Loop
revfactory/harness
Collects feedback on how an agent harness performed, generalizes it, and updates the harness agents, skills and orchestrator along with a change-history table.
A skill your agent uses when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .claude/skills/prompt-security-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "prompt-security-hardening" agent skill from https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardening into .claude/skills/prompt-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prompt-security-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .agents/skills/prompt-security-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "prompt-security-hardening" agent skill from https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardening into .agents/skills/prompt-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prompt-security-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .cursor/skills/prompt-security-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "prompt-security-hardening" agent skill from https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardening into .cursor/skills/prompt-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prompt-security-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ed3dai/ed3d-plugins.git --path plugins/ed3d-extending-claude/skills/prompt-security-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .gemini/skills/prompt-security-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "prompt-security-hardening" agent skill from https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardening into .gemini/skills/prompt-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prompt-security-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .github/skills/prompt-security-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "prompt-security-hardening" agent skill from https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardening into .github/skills/prompt-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prompt-security-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .opencode/skills/prompt-security-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "prompt-security-hardening" agent skill from https://github.com/ed3dai/ed3d-plugins/tree/main/plugins/ed3d-extending-claude/skills/prompt-security-hardening into .opencode/skills/prompt-security-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "prompt-security-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
prompt-security-hardeningA skill your agent uses when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…
Prompt Security Hardening is an agent skill from ed3dai/ed3d-plugins. Use when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations - prevents secrets leakage into LLM context, unsafe shell patterns, and credential exposure
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Security review, Skill authoring and Secrets management. It works with Git. The repository describes itself as: Ed's repo of Claude Code plugins, centered around a research-plan-implement workflow. Only a tiny bit cursed. If you're lucky.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0c90f4b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitcurlpsqlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
STRIPE_SECRET_KEYANTHROPIC_API_KEYAPI_TOKENGITHUB_TOKENJWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Prompt Security Hardening loads about 2.5k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 694 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
s that contain or will contain secrets (`.env`, `.envrc`, config files, key files), set restrictive permissions immediattouch .env && chmod 600 .envchmod 600 ~/.ssh/id_ed25519chmod 644 ~/.ssh/id_ed25519.pubto use a key with open permissions, but `.env` files and config files have no such guardrail.Before creating `.env`, `.envrc`, or any file that will contain secrets, verify the gitignore rules will exclude it. Ifgit check-ignore -v .env || echo ".env" >> .gitignoretouch .env && chmod 600 .envto any file that will hold credentials: `.env`, `.envrc`, `secrets.conf`, `credentials.json`, key files, MCP configurati- `.env`, `.envrc`, `*.env.*`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 694 words (~2,467 tokens).
“Your context window is sent to an API provider. Every secret that enters your context is a secret leaked to a third party. This skill defines the security boundaries you operate within.”
Just SKILL.md in plugins/ed3d-extending-claude/skills/prompt-security-hardening of ed3dai/ed3d-plugins.
Open the folder on GitHubat commit 0c90f4b
Prompt Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Prompt Security Hardening this skilled3dai/ed3d-plugins | 250 | — | ~2.5k | Automated safety check: Warn | None | |
| Harness Evolution Feedback Looprevfactory/harness | 9.1k | — | ~855 | Automated safety check: Pass | Apache-2.0 | |
| Reviewing Claude Configbitwarden/ai-plugins | 155 | — | ~4.2k | Automated safety check: Pass | Custom licence | |
| Project KickoffStanshy/AgentHub | 202 | — | ~528 | Automated safety check: Notes | MIT | |
| Repo Auditzebbern/claude-code-guide | 4.7k | — | ~831 | Automated safety check: Pass | MIT | |
| Darwin Skill Optimizeralchaincyf/darwin-skill | 6.2k | 1 repos | ~4.7k | Automated safety check: Pass | MIT |
revfactory/harness
Collects feedback on how an agent harness performed, generalizes it, and updates the harness agents, skills and orchestrator along with a change-history table.
bitwarden/ai-plugins
Reviews Claude configuration files for security, structure, and prompt engineering quality.
Stanshy/AgentHub
Initialize new project with CLAUDE.md, .knowledge/ structure, company rules, and git
zebbern/claude-code-guide
Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.
alchaincyf/darwin-skill
Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.
KKKKhazix/khazix-skills
Brings project docs, agent rule files, authorized memory and leftover workspace files back in line with what the code and runtime actually do at the end of a work session.
ed3dai/ed3d-plugins
A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes - four-phase framework (root cause investigation, pattern analysis, hypothesis…
ed3dai/ed3d-plugins
A skill your agent uses when creating or editing skills, before deployment, to verify they work under pressure and resist rationalization - applies RED-GREEN-REFACTOR cycle to process documentation…
ed3dai/ed3d-plugins
A skill your agent uses when creating or developing anything, before writing code or implementation plans - refines rough ideas into fully-formed designs through structured Socratic questioning…
ed3dai/ed3d-plugins
A skill your agent uses when writing or reviewing tests - covers test philosophy, condition-based waiting, mocking strategy, and test isolation
ed3dai/ed3d-plugins
A skill your agent uses when creating new skills, editing existing skills, or verifying skills work before deployment - applies TDD to process documentation by testing with subagents before writing…
ed3dai/ed3d-plugins
ALWAYS use this skill when writing or refactoring code. An agent skill from ed3dai/ed3d-plugins.
Works with
Categories
A skill your agent uses when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…. Prompt Security Hardening is an agent skill from ed3dai/ed3d-plugins.
Prompt Security Hardening fits situations like: CLAUDE.md files; any directives that involve shell commands; environment variables; API credentials.
Run `npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a claude-code`. Or copy the skill folder (plugins/ed3d-extending-claude/skills/prompt-security-hardening in ed3dai/ed3d-plugins) into .claude/skills/prompt-security-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a codex`. Or copy the skill folder (plugins/ed3d-extending-claude/skills/prompt-security-hardening in ed3dai/ed3d-plugins) into .agents/skills/prompt-security-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prompt-security-hardening, .gemini/skills/prompt-security-hardening, .github/skills/prompt-security-hardening and .opencode/skills/prompt-security-hardening in your project.
Going by SKILL.md and its folder, Prompt Security Hardening needs the command-line tools its instructions call (git, curl and psql) and credentials named STRIPE_SECRET_KEY, ANTHROPIC_API_KEY, API_TOKEN and GITHUB_TOKEN. Our summary lists: Python 3; Docker; A credential in STRIPE_SECRET_KEY; A credential in ANTHROPIC_API_KEY.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
No licence was found for Prompt Security Hardening or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Prompt Security Hardening: Harness Evolution Feedback Loop (revfactory/harness, 9.1k stars), Reviewing Claude Config (bitwarden/ai-plugins, 155 stars), Project Kickoff (Stanshy/AgentHub, 202 stars) and Repo Audit (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ed3dai (a GitHub organization) maintains it in ed3dai/ed3d-plugins, which has 250 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on September 6, 2026.
Source: ed3dai/ed3d-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.