Agent skill

Security Baseline

by rampstackco in rampstackco/claude-skills

Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills.

MITAuto-check passedSecurity

Install Security Baseline

skills CLI
$ npx skills add rampstackco/claude-skills --skill security-baseline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rampstackco/claude-skills security-baseline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-baseline .claude/skills/security-baseline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-baseline
GitHub stars
935
Token cost
~3k tokens
SKILL.md length
1,425 words
Files
3 (incl. references)
Skills in repo
103
Repo updated
First seen
Licence
MIT

At a glance

Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills.

  • Works in 8 steps: Run a baseline scan → Inventory the surface → Audit each layer → …
  • Configuring HTTPS and TLS
  • SKILL.md covers When to use, When NOT to use, Required inputs and The framework: 6 layers, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Baseline is an agent skill from rampstackco/claude-skills. Establish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/headers-checklist.md`).

It sits in Security, covering Security review, Secrets management and Secure coding. The repository describes itself as: Stack-agnostic Claude Skills covering the full website lifecycle: brand, design, content, SEO, dev, ops, growth, and research. Build, ship, audit, optimize. The licence is MIT.

When your agent uses it

  • Configuring HTTPS and TLS
  • Setting security headers
  • Planning secrets management
  • Evaluating CSP policies

Example prompts

  • “/security-baseline”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Run a baseline scan
  2. Inventory the surface
  3. Audit each layer
  4. Prioritize
  5. Implement and verify
  6. Set up monitoring
  7. Document the baseline
  8. Schedule review

What it can do on your machine

Read from SKILL.md and the folder at commit 482c9bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Baseline loads about 3k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 130 tokens; SKILL.md has 1,425 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~130
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rampstackco/claude-skills at commit 482c9bf, republished under its MIT licence (© rampstackco). 1,425 words, ~2,994 tokens.

Download SKILL.mdSave it as .claude/skills/security-baseline/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security-baseline
description
Establish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.
category
operations
catalog_summary
HTTPS, security headers, CSP, secrets management, vulnerability scans
display_order
7

Security Baseline

Establish the security floor for any production website or web app. Stack-agnostic. Covers the things that should be in place before public launch and verified periodically after.


When to use

  • Pre-launch security review
  • Setting up a new site or environment
  • Periodic security audit (quarterly recommended)
  • Onboarding a new vendor or third-party integration
  • Responding to a security finding or report
  • Hardening after an incident

When NOT to use

  • Active incident response (use incident-response)
  • Code-level security review (use code-review-web)
  • Email-specific authentication (SPF/DKIM/DMARC) (use email-deliverability)
  • DNS-level security (CAA, DNSSEC) (use domain-strategy)
  • Performance-related security (DDoS protection sizing) (use performance-optimization)

Required inputs

  • The site or app in scope (URLs, environments)
  • The hosting platform and CDN
  • Authentication method (if any)
  • Third-party scripts and integrations
  • Compliance context (PCI, SOC2, GDPR, etc., if applicable)
  • Existing security tooling

The framework: 6 layers

Security is layered. Each layer addresses a different attack surface.

Layer 1: Transport security

How data moves from server to client.

  • HTTPS everywhere. No HTTP variants serving content.
  • TLS 1.2 minimum, TLS 1.3 preferred. Disable TLS 1.0 and 1.1.
  • HSTS (Strict-Transport-Security) header set, with includeSubDomains and preload for high-confidence sites.
  • Strong cipher suites only. Modern browsers handle this if you pick a modern config from your provider.
  • Certificates from a trusted CA, monitored for expiration.
Layer 2: Response headers

What the browser is told about your site.

HeaderPurposeDefault value
Strict-Transport-SecurityForce HTTPSmax-age=31536000; includeSubDomains
Content-Security-PolicyRestrict resource loadingSite-specific
X-Content-Type-OptionsPrevent MIME sniffingnosniff
X-Frame-OptionsClickjacking protectionDENY or SAMEORIGIN
Referrer-PolicyControl referrer infostrict-origin-when-cross-origin
Permissions-PolicyControl browser featuresSite-specific (camera, mic, etc.)
Cross-Origin-Opener-PolicyProcess isolationsame-origin (where compatible)
Cross-Origin-Embedder-PolicyCross-origin restrictionsrequire-corp (where applicable)

CSP deserves its own attention. See the framework section below.

Layer 3: Authentication and authorization

How users prove who they are and what they can do.

  • Strong password requirements (length over complexity rules; allow long passphrases)
  • Account lockout or rate limiting on login
  • 2FA available, required for admin accounts
  • Session tokens: short-lived, secure, HttpOnly cookies
  • Logout invalidates tokens server-side, not just client-side
  • Password reset flows that don't reveal account existence
  • Authorization checked on every request (don't rely on UI hiding)
Layer 4: Input handling

How untrusted input is processed.

  • Validate on the server (client validation is UX, not security)
  • Parameterized queries for any database access (no string concatenation into SQL)
  • Output encoding by context (HTML, JS, URL, CSS)
  • File upload restrictions (type, size, location, scanning)
  • Rate limiting on endpoints that could be abused
  • CSRF tokens on state-changing requests
Layer 5: Secrets management

Where credentials and keys live.

  • No secrets in code, config files in repos, or environment variables baked into images
  • Secrets in a dedicated secrets manager
  • Different secrets per environment (no shared dev/prod secrets)
  • Rotation schedule documented and followed
  • Audit log of secret access
  • Limited blast radius (each service has its own credentials, scoped narrowly)
Layer 6: Operational security

How the team operates.

  • Access controls reviewed quarterly (offboard immediately on departure)
  • 2FA enforced on every admin account (hosting, DNS, registrar, code host, deploy tools)
  • Audit logs enabled and reviewed
  • Vulnerability scanning (dependencies, containers, infrastructure)
  • Patch cadence defined
  • Incident response runbook exists (see incident-response)
  • Backups exist and are tested (see backup-and-disaster-recovery)
  • Security contact published (security.txt at /.well-known/security.txt)

Content Security Policy

CSP is the most powerful response header and the most often misconfigured. Worth its own treatment.

What CSP does

CSP tells the browser which sources are allowed for various resource types: scripts, styles, images, frames, connections, etc. A strict CSP prevents most XSS attacks even when input handling has bugs.

Two flavors

Strict CSP (recommended): uses nonce- or hash- based source allowlists. Inline scripts must be explicitly allowed via nonce.

Content-Security-Policy: script-src 'self' 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'self';

Allowlist CSP (legacy): lists allowed domains. Easier to set up, much weaker.

Content-Security-Policy: script-src 'self' https://trusted.com; ...

Strict CSP requires application changes (every inline script needs a nonce). The investment pays off.

Roll out CSP gradually
  1. Start with Content-Security-Policy-Report-Only to log violations without blocking.
  2. Set up a violation report endpoint.
  3. Watch for legitimate violations (third-party scripts, inline handlers).
  4. Tune the policy.
  5. Switch to enforcing mode once violations are mostly false positives.
  6. Continue monitoring violation reports for new issues.
Common CSP mistakes
  • unsafe-inline in script-src. Defeats most of CSP's value.
  • unsafe-eval in script-src. Often required by older libraries; refactor or replace.
  • Wildcard sources (*). Defeats the policy.
  • Allowing CDNs that host arbitrary user content. Attackers can upload scripts to the CDN.
  • Not restricting frame-ancestors. Use this for clickjacking defense (more flexible than X-Frame-Options).

Workflow

Step 1: Run a baseline scan

Use a free scanner: securityheaders.com, or the MDN HTTP Observatory at developer.mozilla.org/en-US/observatory. Get a current grade. This is the floor. If no scan result can be obtained, state the gap per the data-availability rule.

Step 2: Inventory the surface
  • Domains and subdomains in scope
  • Public endpoints (forms, APIs)
  • Authentication entry points
  • Admin interfaces
  • Third-party integrations and their permissions
Step 3: Audit each layer

Walk the 6 layers. For each, document:

  • What's in place
  • What's missing
  • Risk level (high, medium, low)
Step 4: Prioritize

High risk, easy fixes go first:

  • HSTS not set
  • Default headers missing
  • Admin without 2FA
  • Old TLS versions enabled

Medium risk, medium fixes next:

  • CSP rollout
  • Input validation gaps
  • Secret management improvements

Low risk, nice-to-haves last:

  • Permissions-Policy refinements
  • Optional headers (Cross-Origin-* family)
Show full SKILL.md (559 more words)Show less
Step 5: Implement and verify

For each fix:

  • Make the change
  • Test in a non-production environment
  • Verify with a scanner
  • Roll out
  • Re-verify in production
Step 6: Set up monitoring
  • Certificate expiration alerts
  • CSP violation reporting
  • Failed login monitoring
  • Unusual admin activity alerts
  • Dependency vulnerability alerts (Dependabot, Snyk, or equivalent)
Step 7: Document the baseline

Write a security baseline document. It says what's expected on every site:

  • Required headers
  • Required configurations
  • Required practices

New sites get audited against this. Existing sites get re-audited periodically.

Step 8: Schedule review

Quarterly is the floor. Add reviews after major changes or incidents.


Common compliance touchpoints

Not legal advice. Surfaces where security baseline meets compliance requirements:

  • PCI DSS (if handling payment cards): much more involved than baseline. The baseline is a starting point, not sufficient.
  • SOC 2: baseline aligns with most CC controls (CC6 series). Documented baseline plus evidence of execution is the audit ask.
  • GDPR / privacy regs: baseline supports security obligations (Article 32). Privacy is broader than security.
  • HIPAA, HITRUST, FedRAMP: baseline is necessary, far from sufficient. Get specialized help.

When compliance applies, the baseline is necessary but not the full answer.


Failure patterns

HSTS without includeSubDomains. Attacker tricks browser into HTTP on a subdomain you haven't HTTPS'd yet.

HSTS preload without commitment. Once preloaded, removing it takes months to reach users through a Chrome update, with no guarantee for other browsers. Don't preload until HTTPS is solid across all subdomains forever.

CSP with unsafe-inline. Defeats most of CSP. Either go strict (nonce-based) or accept that CSP is providing limited protection.

Default headers missing. X-Content-Type-Options, X-Frame-Options, Referrer-Policy are easy and free. Set them.

Admin without 2FA. The single most common high-impact vulnerability across small teams. Fix today.

Secrets in environment variables baked into images. Anyone with image access has the secrets. Use a runtime secret manager.

No security.txt. Researchers find issues; they need somewhere to report. Publish a security.txt at /.well-known/security.txt.

Old TLS versions enabled. Disable TLS 1.0 and 1.1. Most providers offer this as a checkbox.

CDN allowing arbitrary inline scripts via misconfigured CSP. The CDN proxies user content; attackers leverage that. Audit the CSP against actual loaded resources.

No incident response plan. When (not if) something happens, no runbook = chaos. See incident-response.

Vulnerability scanning without remediation. Reports pile up. The scan is theater unless someone fixes findings.

Penetration test ignored. Pen test report sits on a shelf. Test results without remediation are worse than no test.


Output format

A security baseline document includes:

  • Inventory: what's in scope
  • Layer-by-layer status: what's in place, what's missing
  • Required headers: with values, applied per environment
  • Required configurations: TLS, secrets, auth
  • Required operational practices: access reviews, patch cadence, audit logging
  • Findings: prioritized list of gaps
  • Remediation plan: owners, dates
  • Re-audit cadence: when this is reviewed next

If required data is unavailable

This skill's output depends on data, measurements, or tool results it cannot generate on its own. When a required input, tool, or data source is unavailable or unverifiable, the sanctioned output is the deliverable with the gap stated: what was needed, what was actually obtained or verified, and which parts of the output are affected. Fabricating, estimating, or interpolating a required number to complete the deliverable is never sanctioned. A stated gap is a complete answer.


Reference files

© rampstackco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/security-baseline of rampstackco/claude-skills.

  • SKILL.md
  • README.md
  • references/headers-checklist.md

Open the folder on GitHubat commit 482c9bf

Compare with similar skills

Security Baseline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Baseline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Baseline this skillrampstackco/claude-skills935—~3kAutomated safety check: PassMIT
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Secure Codingtechygarg/lattice198—~1.5kAutomated safety check: PassMIT
Security Scanericrisco/rsc-harness156—~2.8kAutomated safety check: NotesMIT
Security Hardeningrohitg00/awesome-claude-code-toolkit2.7k—~1.5kAutomated safety check: NotesApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Secure Coding

    techygarg/lattice

    Apply security-conscious thinking when generating or modifying code.

    198 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    156 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Hardening

    rohitg00/awesome-claude-code-toolkit

    Application security covering input validation, auth, headers, secrets management, and dependency auditing

    2.7k GitHub stars~1.5k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from rampstackco/claude-skills

All 103 skills in this repo
  • After Action Report

    rampstackco/claude-skills

    Run a structured after-action review (postmortem, retrospective) on a launch, incident, or completed project to capture timeline, root cause analysis, contributing factors, and actionable lessons.

    935 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Analytics Strategy

    rampstackco/claude-skills

    Design measurement frameworks including event taxonomy, KPI hierarchy, dashboard architecture, attribution models, and analytics implementation strategy.

    935 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Brand Style Guide

    rampstackco/claude-skills

    Build or audit a comprehensive brand style guide that documents the full brand system including story, logo system, color, typography, imagery, voice, applications, and dos/don'ts.

    935 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Brand Voice

    rampstackco/claude-skills

    Develop or document a complete brand voice and tone system covering voice attributes, tone shifts by context, vocabulary preferences, grammar rules, and copy examples.

    935 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Content And Copy

    rampstackco/claude-skills

    Write or edit website copy, blog content, and editorial pieces with attention to voice, structure, and goal.

    935 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Content Strategy

    rampstackco/claude-skills

    Develop a content strategy covering editorial positioning, content pillars, formats, calendar, governance, and topical authority planning.

    935 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Security Baseline

What does Security Baseline do?

Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. Security Baseline is an agent skill from rampstackco/claude-skills. Establish a security baseline for a website or web app.

When should I use Security Baseline?

Security Baseline fits situations like: configuring HTTPS and TLS; setting security headers; planning secrets management; evaluating CSP policies.

How do I install Security Baseline in Claude Code?

Run `npx skills add rampstackco/claude-skills --skill security-baseline -a claude-code`. Or copy the skill folder (skills/security-baseline in rampstackco/claude-skills) into .claude/skills/security-baseline in your project. Claude Code loads it when a task matches its description.

How do I install Security Baseline in Codex?

Run `npx skills add rampstackco/claude-skills --skill security-baseline -a codex`. Or copy the skill folder (skills/security-baseline in rampstackco/claude-skills) into .agents/skills/security-baseline in your project. Codex loads it when a task matches its description.

Can I use Security Baseline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rampstackco/claude-skills --skill security-baseline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-baseline, .gemini/skills/security-baseline, .github/skills/security-baseline and .opencode/skills/security-baseline in your project.

What does Security Baseline need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Baseline is instructions for the agent only.

Does Security Baseline access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Baseline safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Baseline use?

Security Baseline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Baseline use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Security Baseline?

Skills that share tags, products or a category with Security Baseline: Discover Security (rand/cc-polymath, 181 stars), Secure Coding (techygarg/lattice, 198 stars), Security Scan (ericrisco/rsc-harness, 156 stars) and Security Hardening (rohitg00/awesome-claude-code-toolkit, 2.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Baseline?

rampstackco (a GitHub organization) maintains it in rampstackco/claude-skills, which has 935 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 7, 2026.

Source: rampstackco/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.