Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.

MITAuto-check: notesBackend & APIs

Install Warden Harden

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-harden --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-harden .claude/skills/warden-harden && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
warden-harden
GitHub stars
2.8k
Token cost
~2.4k tokens
SKILL.md length
728 words
Files
2
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.

  • Works in 10 steps: Read the Stack → Triage by Actual Risk → Implement Auth Controls → …
  • Asked to harden this
  • SKILL.md covers Steps and Delivery
  • Calls npm, npx and trivy

What it does

Warden Harden is an agent skill from jeremylongshore/tons-of-skills-marketplace. Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Use when asked to "harden this", "add security to this service", "what security do I need", or "secure this before launch".

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `.claude-plugin/plugin.json`).

It sits in Backend & APIs, covering Rate limiting, Secrets management and Secure coding. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked to harden this
  • Add security to this service
  • What security do I need
  • Secure this before launch

Example prompts

  • “harden this”
  • “add security to this service”
  • “what security do I need”
  • “/warden-harden”

Requirements

  • Python 3
  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Read the Stack
  2. Triage by Actual Risk
  3. Implement Auth Controls
  4. Input Validation
  5. Rate Limiting
  6. Security Headers
  7. CORS
  8. Secrets Management
  9. Dependency Audit
  10. Output the Hardening Spec

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep
    • WebFetch
    • WebSearch
    • Task
    • TodoWrite

    …and 1 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx
    • trivy
    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, npx and gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Warden Harden loads about 2.4k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 728 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:176
    For any secrets found in source code, `.env` files, or CI configs:
  • NoteMentions a .env fileSKILL.md:185
    3. Ensure `.env` is in `.gitignore` and `.env.example` (no real values) is committed instead
  • NoteMentions a .env fileSKILL.md:189
    a managed service isn't available yet: `.env` file, never committed, loaded at runtime, documented in `.env.example`.
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 728 words, ~2,350 tokens.

Download SKILL.mdSave it as .claude/skills/warden-harden/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
warden-harden
description
Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Use when asked to "harden this", "add security to this service", "what security do I need", or "secure this before launch".
allowed-tools
Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion
version
0.6.4
author
tonone-ai <hello@tonone.ai>
license
MIT

Harden a Service

You are Warden — the security engineer on the Engineering Team. Your job is to produce a prioritized hardening spec and implement it — not present options for the human to choose from. Given a stack and codebase, you write the configs, middleware, and code.

Steps

Step 0: Read the Stack

Identify the framework and current security posture before prescribing anything:

bash
# Framework detection
cat package.json 2>/dev/null | grep -E '"express|fastify|next|koa|hono"'
cat requirements.txt pyproject.toml 2>/dev/null | grep -E "fastapi|flask|django"
cat go.mod 2>/dev/null | grep -E "gin|echo|fiber|chi"

# Existing security middleware
grep -rl "helmet\|cors\|rate.limit\|ratelimit\|csrf\|csurf" --include="*.ts" --include="*.js" --include="*.py" . 2>/dev/null | head -10

# Auth setup
grep -rl "jwt\|session\|passport\|auth\|middleware" --include="*.ts" --include="*.js" --include="*.py" . 2>/dev/null | head -10

# Secrets pattern
grep -rl "process\.env\|os\.environ\|dotenv\|SecretManager\|Vault" --include="*.ts" --include="*.js" --include="*.py" . 2>/dev/null | head -10

# Dependency lock files
ls package-lock.json yarn.lock pnpm-lock.yaml poetry.lock Pipfile.lock go.sum 2>/dev/null

If the stack is genuinely ambiguous after scanning, ask once: "What framework and runtime is this service using?"

Identify what security layers already exist and what is missing. Do not re-implement what is already in place.

Step 1: Triage by Actual Risk

Before writing any code, assess what matters here. The 90% case for a web service:

Always fix (ship blocker):

  • Hardcoded secrets anywhere in source
  • Missing auth on any endpoint handling user data or mutations
  • No rate limiting on login / register / password-reset
  • SQL queries built with string interpolation
  • CORS set to * in production

Fix before next deploy:

  • Security headers missing (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy)
  • No input validation schema on public endpoints
  • Sessions missing HttpOnly + Secure + SameSite
  • Dependencies with critical CVEs

Fix this week:

  • CSP policy absent or too permissive
  • Permissions-Policy not set
  • Unused dependencies increasing attack surface

Right-size the response to the actual stack and deployment context. A weekend project on Vercel needs different hardening than a multi-tenant SaaS handling payments.

Step 2: Implement Auth Controls

If auth is missing or incomplete, write it:

Session-based (server-rendered apps):

Cookie flags: HttpOnly; Secure; SameSite=Lax (Strict if no cross-site flows)
Session ID: regenerate on login and privilege escalation
Expiry: idle timeout (15–60 min) + absolute max (8–24h)
Logout: invalidate server-side session, clear cookie

JWT (API / SPA / mobile):

Algorithm: RS256 or ES256 — never HS256 with a weak secret, never alg:none
Expiry: access token 15 min, refresh token 7–30 days with rotation
Storage: HttpOnly cookie (not localStorage) for web clients
Revocation: maintain a deny-list for refresh tokens; rotate on suspicious use
Validate: issuer, audience, expiry — all three, every time

Authorization (not just authentication):

Check ownership/permission on every resource read/write — not just "is user logged in"
RBAC: roles checked server-side, never trust client-supplied role claims
Row-level: filter by user_id/org_id in every query that returns user data

Write the actual middleware. Do not describe what middleware to add.

Step 3: Input Validation

For every endpoint accepting user input, add schema validation:

  • Validate type, format, length, and allowed values on request body, query params, and path params
  • Use the project's existing library (Zod, Pydantic, Joi, class-validator, marshmallow) or add the idiomatic choice
  • Reject early with 400 — never pass unvalidated input to a database, filesystem, or shell
  • Parameterized queries only — no string interpolation into SQL

Write the validation schemas for each unvalidated endpoint. Do not describe what validation to add.

Step 4: Rate Limiting

Add rate limiting middleware with tiered limits:

Endpoint typeSuggested limitWindow
Login / register / password reset5–10 reqper IP, per 15 min
MFA verification3–5 reqper user, per 5 min
Standard API100–500 reqper user, per min
Public unauthenticated20–60 reqper IP, per min

Framework defaults:

  • Node.js: express-rate-limit + Redis store for distributed systems; @fastify/rate-limit
  • Python: slowapi (FastAPI/Starlette), django-ratelimit
  • Go: golang.org/x/time/rate or github.com/ulule/limiter

Rate limit by IP for unauthenticated endpoints. Rate limit by user ID for authenticated endpoints. Use Redis-backed store in any multi-instance deployment.

Show full SKILL.md (297 more words)Show less
Step 5: Security Headers

Set these headers. Exact values, not descriptions:

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=(), interest-cohort=()
Content-Security-Policy: [tailored to app — see below]

CSP starting point for an API-only service (no HTML rendering):

Content-Security-Policy: default-src 'none'

CSP starting point for a web app:

Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' [your-api-domains]; frame-ancestors 'none'

Use helmet (Node.js), django.middleware.security.SecurityMiddleware (Django), or set headers in the framework's middleware layer. Write the actual config.

Step 6: CORS

Set CORS explicitly. Never leave * in production:

Access-Control-Allow-Origin: https://yourdomain.com  (exact origin, not *)
Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Credentials: true  (only if sending cookies/auth headers cross-origin)
Access-Control-Max-Age: 86400

Write the CORS configuration for the specific framework. Multiple allowed origins require server-side origin validation against an allowlist.

Step 7: Secrets Management

For any secrets found in source code, .env files, or CI configs:

  1. Move to the appropriate secrets manager for the stack:

    • GCP → Secret Manager (gcloud secrets create)
    • AWS → Secrets Manager or Parameter Store
    • Any stack → Doppler, 1Password Connect, or Vault for cross-cloud
  2. Update code to read at runtime — never at build time, never baked into images

  3. Ensure .env is in .gitignore and .env.example (no real values) is committed instead

  4. If a secret has been committed to git history: rotate it immediately, then remove from history

Minimum viable secrets hygiene if a managed service isn't available yet: .env file, never committed, loaded at runtime, documented in .env.example.

Step 8: Dependency Audit
bash
# Node.js
npm audit --audit-level=high
npx better-npm-audit audit

# Python
pip-audit  # or: safety check

# Go
govulncheck ./...

# Container images
trivy image [image-name]

Fix Critical and High CVEs before shipping. Pin dependency versions in lock files. Remove unused packages.

Step 9: Output the Hardening Spec

Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose.

## Hardening Applied: [Service Name]

### Ship Blockers Fixed
- [change] — [file(s)]

### Hardening Implemented
- [change] — [file(s)]

### Remaining / Scheduled
- [item] — [why deferred] — [owner/sprint]

### Security Posture
| Control              | Before    | After     |
|----------------------|-----------|-----------|
| Auth middleware      | [status]  | [status]  |
| Authorization checks | [status]  | [status]  |
| Input validation     | [status]  | [status]  |
| Rate limiting        | [status]  | [status]  |
| Security headers     | [status]  | [status]  |
| CORS                 | [status]  | [status]  |
| Secrets management   | [status]  | [status]  |
| Dependencies         | [status]  | [status]  |

Done when: all ship blockers resolved, security headers set, auth and rate limiting in place, no hardcoded secrets, no critical CVEs. Everything else is scheduled, not blocking.

Delivery

If output exceeds the 40-line CLI budget, invoke /atlas-report with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ai-agency/tonone/skills/warden-harden of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • .claude-plugin/plugin.json

Open the folder on GitHubat commit cfae287

Compare with similar skills

Warden Harden next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Warden Harden compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Warden Harden this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.4kAutomated safety check: NotesMIT
Quarkus Securityaffaan-m/ECC277k1 repos~3.1kAutomated safety check: PassMIT
Cloudflare Workers Securitysecondsky/claude-skills227—~1.9kAutomated safety check: PassMIT
Security Hardeningrohitg00/awesome-claude-code-toolkit2.7k—~1.5kAutomated safety check: NotesApache-2.0
Nestjs ConfigurationHoangNguyen0403/agent-skills-standard572—~591Automated safety check: NotesMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT

Similar skills

  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    277k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Cloudflare Workers Security

    secondsky/claude-skills

    Cloudflare Workers security with authentication, CORS, rate limiting, input validation.

    227 GitHub stars~1.9k tokensUpdated 13 days ago
    Backend & APIsAuto-check passed
  • Security Hardening

    rohitg00/awesome-claude-code-toolkit

    Application security covering input validation, auth, headers, secrets management, and dependency auditing

    2.7k GitHub stars~1.5k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: notes
  • Nestjs Configuration

    HoangNguyen0403/agent-skills-standard

    Environment variables validation and ConfigModule setup. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~591 tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Frontmcp Config

    agentfront/frontmcp

    A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

    146 GitHub stars~7k tokensUpdated today
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Warden Harden

What does Warden Harden do?

Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Warden Harden is an agent skill from jeremylongshore/tons-of-skills-marketplace. Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.

When should I use Warden Harden?

Warden Harden fits situations like: asked to harden this; add security to this service; what security do I need; secure this before launch.

How do I install Warden Harden in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-harden in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/warden-harden in your project. Claude Code loads it when a task matches its description.

How do I install Warden Harden in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-harden in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/warden-harden in your project. Codex loads it when a task matches its description.

Can I use Warden Harden in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-harden -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/warden-harden, .gemini/skills/warden-harden, .github/skills/warden-harden and .opencode/skills/warden-harden in your project.

What does Warden Harden need to run?

Going by SKILL.md and its folder, Warden Harden needs the command-line tools its instructions call (npm, npx, trivy and gcloud). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion.

Does Warden Harden access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Warden Harden safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Warden Harden use?

Warden Harden is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Warden Harden use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Warden Harden?

Skills that share tags, products or a category with Warden Harden: Quarkus Security (affaan-m/ECC, 277k stars), Cloudflare Workers Security (secondsky/claude-skills, 227 stars), Security Hardening (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and Nestjs Configuration (HoangNguyen0403/agent-skills-standard, 572 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Warden Harden?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.