Quarkus Security
affaan-m/ECC
Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…
Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-harden --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .claude/skills/warden-harden && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "warden-harden" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-harden into .claude/skills/warden-harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "warden-harden", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-hardenType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-harden --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .agents/skills/warden-harden && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "warden-harden" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-harden into .agents/skills/warden-harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "warden-harden", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-harden --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .cursor/skills/warden-harden && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "warden-harden" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-harden into .cursor/skills/warden-harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "warden-harden", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path plugins/ai-agency/tonone/skills/warden-harden--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-harden --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .gemini/skills/warden-harden && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "warden-harden" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-harden into .gemini/skills/warden-harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "warden-harden", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-hardenInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .github/skills/warden-harden && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "warden-harden" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-harden into .github/skills/warden-harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "warden-harden", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-harden --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .opencode/skills/warden-harden && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "warden-harden" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/ai-agency/tonone/skills/warden-harden into .opencode/skills/warden-harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "warden-harden", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
warden-hardenProduce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.
Warden Harden is an agent skill from jeremylongshore/tons-of-skills-marketplace. Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Use when asked to "harden this", "add security to this service", "what security do I need", or "secure this before launch".
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `.claude-plugin/plugin.json`).
It sits in Backend & APIs, covering Rate limiting, Secrets management and Secure coding. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBashGlobGrepWebFetchWebSearchTaskTodoWrite…and 1 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmnpxtrivygcloudFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, npx and gcloud, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Warden Harden loads about 2.4k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 728 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
For any secrets found in source code, `.env` files, or CI configs:3. Ensure `.env` is in `.gitignore` and `.env.example` (no real values) is committed insteada managed service isn't available yet: `.env` file, never committed, loaded at runtime, documented in `.env.example`.allowed-tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestionAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 728 words, ~2,350 tokens.
.claude/skills/warden-harden/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.You are Warden — the security engineer on the Engineering Team. Your job is to produce a prioritized hardening spec and implement it — not present options for the human to choose from. Given a stack and codebase, you write the configs, middleware, and code.
Identify the framework and current security posture before prescribing anything:
# Framework detection
cat package.json 2>/dev/null | grep -E '"express|fastify|next|koa|hono"'
cat requirements.txt pyproject.toml 2>/dev/null | grep -E "fastapi|flask|django"
cat go.mod 2>/dev/null | grep -E "gin|echo|fiber|chi"
# Existing security middleware
grep -rl "helmet\|cors\|rate.limit\|ratelimit\|csrf\|csurf" --include="*.ts" --include="*.js" --include="*.py" . 2>/dev/null | head -10
# Auth setup
grep -rl "jwt\|session\|passport\|auth\|middleware" --include="*.ts" --include="*.js" --include="*.py" . 2>/dev/null | head -10
# Secrets pattern
grep -rl "process\.env\|os\.environ\|dotenv\|SecretManager\|Vault" --include="*.ts" --include="*.js" --include="*.py" . 2>/dev/null | head -10
# Dependency lock files
ls package-lock.json yarn.lock pnpm-lock.yaml poetry.lock Pipfile.lock go.sum 2>/dev/nullIf the stack is genuinely ambiguous after scanning, ask once: "What framework and runtime is this service using?"
Identify what security layers already exist and what is missing. Do not re-implement what is already in place.
Before writing any code, assess what matters here. The 90% case for a web service:
Always fix (ship blocker):
* in productionFix before next deploy:
Fix this week:
Right-size the response to the actual stack and deployment context. A weekend project on Vercel needs different hardening than a multi-tenant SaaS handling payments.
If auth is missing or incomplete, write it:
Session-based (server-rendered apps):
Cookie flags: HttpOnly; Secure; SameSite=Lax (Strict if no cross-site flows)
Session ID: regenerate on login and privilege escalation
Expiry: idle timeout (15–60 min) + absolute max (8–24h)
Logout: invalidate server-side session, clear cookieJWT (API / SPA / mobile):
Algorithm: RS256 or ES256 — never HS256 with a weak secret, never alg:none
Expiry: access token 15 min, refresh token 7–30 days with rotation
Storage: HttpOnly cookie (not localStorage) for web clients
Revocation: maintain a deny-list for refresh tokens; rotate on suspicious use
Validate: issuer, audience, expiry — all three, every timeAuthorization (not just authentication):
Check ownership/permission on every resource read/write — not just "is user logged in"
RBAC: roles checked server-side, never trust client-supplied role claims
Row-level: filter by user_id/org_id in every query that returns user dataWrite the actual middleware. Do not describe what middleware to add.
For every endpoint accepting user input, add schema validation:
Write the validation schemas for each unvalidated endpoint. Do not describe what validation to add.
Add rate limiting middleware with tiered limits:
| Endpoint type | Suggested limit | Window |
|---|---|---|
| Login / register / password reset | 5–10 req | per IP, per 15 min |
| MFA verification | 3–5 req | per user, per 5 min |
| Standard API | 100–500 req | per user, per min |
| Public unauthenticated | 20–60 req | per IP, per min |
Framework defaults:
express-rate-limit + Redis store for distributed systems; @fastify/rate-limitslowapi (FastAPI/Starlette), django-ratelimitgolang.org/x/time/rate or github.com/ulule/limiterRate limit by IP for unauthenticated endpoints. Rate limit by user ID for authenticated endpoints. Use Redis-backed store in any multi-instance deployment.
Set these headers. Exact values, not descriptions:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=(), interest-cohort=()
Content-Security-Policy: [tailored to app — see below]CSP starting point for an API-only service (no HTML rendering):
Content-Security-Policy: default-src 'none'CSP starting point for a web app:
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' [your-api-domains]; frame-ancestors 'none'Use helmet (Node.js), django.middleware.security.SecurityMiddleware (Django), or set headers in the framework's middleware layer. Write the actual config.
Set CORS explicitly. Never leave * in production:
Access-Control-Allow-Origin: https://yourdomain.com (exact origin, not *)
Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Credentials: true (only if sending cookies/auth headers cross-origin)
Access-Control-Max-Age: 86400Write the CORS configuration for the specific framework. Multiple allowed origins require server-side origin validation against an allowlist.
For any secrets found in source code, .env files, or CI configs:
Move to the appropriate secrets manager for the stack:
gcloud secrets create)Update code to read at runtime — never at build time, never baked into images
Ensure .env is in .gitignore and .env.example (no real values) is committed instead
If a secret has been committed to git history: rotate it immediately, then remove from history
Minimum viable secrets hygiene if a managed service isn't available yet: .env file, never committed, loaded at runtime, documented in .env.example.
# Node.js
npm audit --audit-level=high
npx better-npm-audit audit
# Python
pip-audit # or: safety check
# Go
govulncheck ./...
# Container images
trivy image [image-name]Fix Critical and High CVEs before shipping. Pin dependency versions in lock files. Remove unused packages.
Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose.
## Hardening Applied: [Service Name]
### Ship Blockers Fixed
- [change] — [file(s)]
### Hardening Implemented
- [change] — [file(s)]
### Remaining / Scheduled
- [item] — [why deferred] — [owner/sprint]
### Security Posture
| Control | Before | After |
|----------------------|-----------|-----------|
| Auth middleware | [status] | [status] |
| Authorization checks | [status] | [status] |
| Input validation | [status] | [status] |
| Rate limiting | [status] | [status] |
| Security headers | [status] | [status] |
| CORS | [status] | [status] |
| Secrets management | [status] | [status] |
| Dependencies | [status] | [status] |Done when: all ship blockers resolved, security headers set, auth and rate limiting in place, no hardcoded secrets, no critical CVEs. Everything else is scheduled, not blocking.
If output exceeds the 40-line CLI budget, invoke /atlas-report with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.
© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in plugins/ai-agency/tonone/skills/warden-harden of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Warden Harden next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Warden Harden this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.4k | Automated safety check: Notes | MIT | |
| Quarkus Securityaffaan-m/ECC | 277k | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Cloudflare Workers Securitysecondsky/claude-skills | 227 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Security Hardeningrohitg00/awesome-claude-code-toolkit | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Nestjs ConfigurationHoangNguyen0403/agent-skills-standard | 572 | — | ~591 | Automated safety check: Notes | MIT | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT |
affaan-m/ECC
Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…
secondsky/claude-skills
Cloudflare Workers security with authentication, CORS, rate limiting, input validation.
rohitg00/awesome-claude-code-toolkit
Application security covering input validation, auth, headers, secrets management, and dependency auditing
HoangNguyen0403/agent-skills-standard
Environment variables validation and ConfigModule setup. An agent skill from HoangNguyen0403/agent-skills-standard.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
agentfront/frontmcp
A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Warden Harden is an agent skill from jeremylongshore/tons-of-skills-marketplace. Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.
Warden Harden fits situations like: asked to harden this; add security to this service; what security do I need; secure this before launch.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-harden in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/warden-harden in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-harden in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/warden-harden in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/warden-harden, .gemini/skills/warden-harden, .github/skills/warden-harden and .opencode/skills/warden-harden in your project.
Going by SKILL.md and its folder, Warden Harden needs the command-line tools its instructions call (npm, npx, trivy and gcloud). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion.
SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Warden Harden is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Warden Harden: Quarkus Security (affaan-m/ECC, 277k stars), Cloudflare Workers Security (secondsky/claude-skills, 227 stars), Security Hardening (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and Nestjs Configuration (HoangNguyen0403/agent-skills-standard, 572 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.