Agent skill

Prompt Security Hardening

by ed3dai in ed3dai/ed3d-plugins

A skill your agent uses when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…

No licenceAuto-check: warningsAgent Workflows

Install Prompt Security Hardening

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ed3dai/ed3d-plugins prompt-security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ed3dai/ed3d-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ed3d-extending-claude/skills/prompt-security-hardening .claude/skills/prompt-security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
prompt-security-hardening
GitHub stars
250
Token cost
~2.5k tokens
SKILL.md length
694 words
Files
1
Skills in repo
34
Repo updated
First seen
Licence
None found

At a glance

A skill your agent uses when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…

  • Works in 7 steps: Never Read Secret Values Into Context → Never Hardcode Secrets in Generated Code… → Set Restrictive File Permissions on… → …
  • CLAUDE.md files
  • SKILL.md covers 1. Never Read Secret Values…, 2. Never Hardcode Secrets in…, 3. Set Restrictive File… and 4. Verify .gitignore Before…, plus 5 more sections
  • Calls git, curl and psql; reaches github.com; needs STRIPE_SECRET_KEY and ANTHROPIC_API_KEY

What it does

Prompt Security Hardening is an agent skill from ed3dai/ed3d-plugins. Use when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations - prevents secrets leakage into LLM context, unsafe shell patterns, and credential exposure

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Security review, Skill authoring and Secrets management. It works with Git. The repository describes itself as: Ed's repo of Claude Code plugins, centered around a research-plan-implement workflow. Only a tiny bit cursed. If you're lucky.

When your agent uses it

  • CLAUDE.md files
  • Any directives that involve shell commands
  • Environment variables
  • API credentials

Example prompts

  • “/prompt-security-hardening”

Requirements

  • Python 3
  • Docker
  • A credential in STRIPE_SECRET_KEY
  • A credential in ANTHROPIC_API_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Never Read Secret Values Into Context
  2. Never Hardcode Secrets in Generated Code or Directives
  3. Set Restrictive File Permissions on Sensitive Files
  4. Verify .gitignore Before Creating Secret-Bearing Files
  5. Keep Secrets Out of URLs and Process-Visible Arguments
  6. Sanitize External Input in Shell Commands
  7. Guard Against Context Contamination From Files

What it can do on your machine

Read from SKILL.md and the folder at commit 0c90f4b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • curl
    • psql

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STRIPE_SECRET_KEY
    • ANTHROPIC_API_KEY
    • API_TOKEN
    • GITHUB_TOKEN
    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Prompt Security Hardening loads about 2.5k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 694 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:98
    s that contain or will contain secrets (`.env`, `.envrc`, config files, key files), set restrictive permissions immediat
  • NoteMentions a .env fileSKILL.md:102
    touch .env && chmod 600 .env
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:106
    chmod 600 ~/.ssh/id_ed25519
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:107
    chmod 644 ~/.ssh/id_ed25519.pub
  • NoteMentions a .env fileSKILL.md:113
    to use a key with open permissions, but `.env` files and config files have no such guardrail.
  • NoteMentions a .env fileSKILL.md:117
    Before creating `.env`, `.envrc`, or any file that will contain secrets, verify the gitignore rules will exclude it. If
  • NoteMentions a .env fileSKILL.md:121
    git check-ignore -v .env || echo ".env" >> .gitignore
  • NoteMentions a .env fileSKILL.md:122
    touch .env && chmod 600 .env
  • NoteMentions a .env fileSKILL.md:128
    to any file that will hold credentials: `.env`, `.envrc`, `secrets.conf`, `credentials.json`, key files, MCP configurati
  • NoteMentions a .env fileSKILL.md:207
    - `.env`, `.envrc`, `*.env.*`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 694 words (~2,467 tokens).

“Your context window is sent to an API provider. Every secret that enters your context is a secret leaked to a third party. This skill defines the security boundaries you operate within.”

— opening of SKILL.md by ed3dai
name
prompt-security-hardening
user-invocable
false

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/ed3d-extending-claude/skills/prompt-security-hardening of ed3dai/ed3d-plugins.

Open the folder on GitHubat commit 0c90f4b

Compare with similar skills

Prompt Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Prompt Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Prompt Security Hardening this skilled3dai/ed3d-plugins250—~2.5kAutomated safety check: WarnNone
Harness Evolution Feedback Looprevfactory/harness9.1k—~855Automated safety check: PassApache-2.0
Reviewing Claude Configbitwarden/ai-plugins155—~4.2kAutomated safety check: PassCustom licence
Project KickoffStanshy/AgentHub202—~528Automated safety check: NotesMIT
Repo Auditzebbern/claude-code-guide4.7k—~831Automated safety check: PassMIT
Darwin Skill Optimizeralchaincyf/darwin-skill6.2k1 repos~4.7kAutomated safety check: PassMIT

Similar skills

  • Collects feedback on how an agent harness performed, generalizes it, and updates the harness agents, skills and orchestrator along with a change-history table.

    9.1k GitHub stars~855 tokensUpdated 13 days ago
    Agent WorkflowsAuto-check passed
  • Reviewing Claude Config

    bitwarden/ai-plugins

    Official

    Reviews Claude configuration files for security, structure, and prompt engineering quality.

    155 GitHub stars~4.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Project Kickoff

    Stanshy/AgentHub

    Initialize new project with CLAUDE.md, .knowledge/ structure, company rules, and git

    202 GitHub stars~528 tokensUpdated 6 mo ago
    Agent WorkflowsAuto-check: notes
  • Repo Audit

    zebbern/claude-code-guide

    Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

    4.7k GitHub stars~831 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed
  • Neat-Freak Knowledge Closeout

    KKKKhazix/khazix-skills

    Brings project docs, agent rule files, authorized memory and leftover workspace files back in line with what the code and runtime actually do at the end of a work session.

    21k GitHub stars~1.9k tokensUpdated 9 days ago
    Agent WorkflowsAuto-check passed

More from ed3dai/ed3d-plugins

All 34 skills in this repo
  • Systematic Debugging

    ed3dai/ed3d-plugins

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes - four-phase framework (root cause investigation, pattern analysis, hypothesis…

    250 GitHub starsUsed in 3 repos~2.4k tokens
    Auto-check passed
  • A skill your agent uses when creating or editing skills, before deployment, to verify they work under pressure and resist rationalization - applies RED-GREEN-REFACTOR cycle to process documentation…

    250 GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check passed
  • Brainstorming

    ed3dai/ed3d-plugins

    A skill your agent uses when creating or developing anything, before writing code or implementation plans - refines rough ideas into fully-formed designs through structured Socratic questioning…

    250 GitHub starsUsed in 1 repo~4.3k tokens
    Auto-check passed
  • Writing Good Tests

    ed3dai/ed3d-plugins

    A skill your agent uses when writing or reviewing tests - covers test philosophy, condition-based waiting, mocking strategy, and test isolation

    250 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Writing Skills

    ed3dai/ed3d-plugins

    A skill your agent uses when creating new skills, editing existing skills, or verifying skills work before deployment - applies TDD to process documentation by testing with subagents before writing…

    250 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Coding Effectively

    ed3dai/ed3d-plugins

    ALWAYS use this skill when writing or refactoring code. An agent skill from ed3dai/ed3d-plugins.

    250 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Prompt Security Hardening

What does Prompt Security Hardening do?

A skill your agent uses when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…. Prompt Security Hardening is an agent skill from ed3dai/ed3d-plugins.

When should I use Prompt Security Hardening?

Prompt Security Hardening fits situations like: CLAUDE.md files; any directives that involve shell commands; environment variables; API credentials.

How do I install Prompt Security Hardening in Claude Code?

Run `npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a claude-code`. Or copy the skill folder (plugins/ed3d-extending-claude/skills/prompt-security-hardening in ed3dai/ed3d-plugins) into .claude/skills/prompt-security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Prompt Security Hardening in Codex?

Run `npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a codex`. Or copy the skill folder (plugins/ed3d-extending-claude/skills/prompt-security-hardening in ed3dai/ed3d-plugins) into .agents/skills/prompt-security-hardening in your project. Codex loads it when a task matches its description.

Can I use Prompt Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ed3dai/ed3d-plugins --skill prompt-security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prompt-security-hardening, .gemini/skills/prompt-security-hardening, .github/skills/prompt-security-hardening and .opencode/skills/prompt-security-hardening in your project.

What does Prompt Security Hardening need to run?

Going by SKILL.md and its folder, Prompt Security Hardening needs the command-line tools its instructions call (git, curl and psql) and credentials named STRIPE_SECRET_KEY, ANTHROPIC_API_KEY, API_TOKEN and GITHUB_TOKEN. Our summary lists: Python 3; Docker; A credential in STRIPE_SECRET_KEY; A credential in ANTHROPIC_API_KEY.

Does Prompt Security Hardening access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Prompt Security Hardening safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Prompt Security Hardening use?

No licence was found for Prompt Security Hardening or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Prompt Security Hardening use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Prompt Security Hardening?

Skills that share tags, products or a category with Prompt Security Hardening: Harness Evolution Feedback Loop (revfactory/harness, 9.1k stars), Reviewing Claude Config (bitwarden/ai-plugins, 155 stars), Project Kickoff (Stanshy/AgentHub, 202 stars) and Repo Audit (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Prompt Security Hardening?

ed3dai (a GitHub organization) maintains it in ed3dai/ed3d-plugins, which has 250 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on September 6, 2026.

Source: ed3dai/ed3d-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.