Discover Security
rand/cc-polymath
Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.
Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills.
$ npx skills add rampstackco/claude-skills --skill security-baseline -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rampstackco/claude-skills security-baseline --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-baseline .claude/skills/security-baseline && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-baseline" agent skill from https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline into .claude/skills/security-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-baseline", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rampstackco/claude-skills/tree/main/skills/security-baselineType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rampstackco/claude-skills --skill security-baseline -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rampstackco/claude-skills security-baseline --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-baseline .agents/skills/security-baseline && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-baseline" agent skill from https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline into .agents/skills/security-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-baseline", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rampstackco/claude-skills --skill security-baseline -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rampstackco/claude-skills security-baseline --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-baseline .cursor/skills/security-baseline && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-baseline" agent skill from https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline into .cursor/skills/security-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-baseline", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rampstackco/claude-skills.git --path skills/security-baseline--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rampstackco/claude-skills --skill security-baseline -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rampstackco/claude-skills security-baseline --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-baseline .gemini/skills/security-baseline && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-baseline" agent skill from https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline into .gemini/skills/security-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-baseline", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rampstackco/claude-skills security-baselineInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rampstackco/claude-skills --skill security-baseline -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-baseline .github/skills/security-baseline && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-baseline" agent skill from https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline into .github/skills/security-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-baseline", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rampstackco/claude-skills --skill security-baseline -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rampstackco/claude-skills security-baseline --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-baseline .opencode/skills/security-baseline && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-baseline" agent skill from https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline into .opencode/skills/security-baseline/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-baseline", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-baselineEstablish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills.
Security Baseline is an agent skill from rampstackco/claude-skills. Establish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/headers-checklist.md`).
It sits in Security, covering Security review, Secrets management and Secure coding. The repository describes itself as: Stack-agnostic Claude Skills covering the full website lifecycle: brand, design, content, SEO, dev, ops, growth, and research. Build, ship, audit, optimize. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 482c9bf. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Baseline loads about 3k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 130 tokens; SKILL.md has 1,425 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rampstackco/claude-skills at commit 482c9bf, republished under its MIT licence (© rampstackco). 1,425 words, ~2,994 tokens.
.claude/skills/security-baseline/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Establish the security floor for any production website or web app. Stack-agnostic. Covers the things that should be in place before public launch and verified periodically after.
incident-response)code-review-web)email-deliverability)domain-strategy)performance-optimization)Security is layered. Each layer addresses a different attack surface.
How data moves from server to client.
includeSubDomains and preload for high-confidence sites.What the browser is told about your site.
| Header | Purpose | Default value |
|---|---|---|
Strict-Transport-Security | Force HTTPS | max-age=31536000; includeSubDomains |
Content-Security-Policy | Restrict resource loading | Site-specific |
X-Content-Type-Options | Prevent MIME sniffing | nosniff |
X-Frame-Options | Clickjacking protection | DENY or SAMEORIGIN |
Referrer-Policy | Control referrer info | strict-origin-when-cross-origin |
Permissions-Policy | Control browser features | Site-specific (camera, mic, etc.) |
Cross-Origin-Opener-Policy | Process isolation | same-origin (where compatible) |
Cross-Origin-Embedder-Policy | Cross-origin restrictions | require-corp (where applicable) |
CSP deserves its own attention. See the framework section below.
How users prove who they are and what they can do.
How untrusted input is processed.
Where credentials and keys live.
How the team operates.
incident-response)backup-and-disaster-recovery)CSP is the most powerful response header and the most often misconfigured. Worth its own treatment.
CSP tells the browser which sources are allowed for various resource types: scripts, styles, images, frames, connections, etc. A strict CSP prevents most XSS attacks even when input handling has bugs.
Strict CSP (recommended): uses nonce- or hash- based source allowlists. Inline scripts must be explicitly allowed via nonce.
Content-Security-Policy: script-src 'self' 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'self';Allowlist CSP (legacy): lists allowed domains. Easier to set up, much weaker.
Content-Security-Policy: script-src 'self' https://trusted.com; ...Strict CSP requires application changes (every inline script needs a nonce). The investment pays off.
Content-Security-Policy-Report-Only to log violations without blocking.unsafe-inline in script-src. Defeats most of CSP's value.unsafe-eval in script-src. Often required by older libraries; refactor or replace.*). Defeats the policy.frame-ancestors. Use this for clickjacking defense (more flexible than X-Frame-Options).Use a free scanner: securityheaders.com, or the MDN HTTP Observatory at developer.mozilla.org/en-US/observatory. Get a current grade. This is the floor. If no scan result can be obtained, state the gap per the data-availability rule.
Walk the 6 layers. For each, document:
High risk, easy fixes go first:
Medium risk, medium fixes next:
Low risk, nice-to-haves last:
For each fix:
Write a security baseline document. It says what's expected on every site:
New sites get audited against this. Existing sites get re-audited periodically.
Quarterly is the floor. Add reviews after major changes or incidents.
Not legal advice. Surfaces where security baseline meets compliance requirements:
When compliance applies, the baseline is necessary but not the full answer.
HSTS without includeSubDomains. Attacker tricks browser into HTTP on a subdomain you haven't HTTPS'd yet.
HSTS preload without commitment. Once preloaded, removing it takes months to reach users through a Chrome update, with no guarantee for other browsers. Don't preload until HTTPS is solid across all subdomains forever.
CSP with unsafe-inline. Defeats most of CSP. Either go strict (nonce-based) or accept that CSP is providing limited protection.
Default headers missing. X-Content-Type-Options, X-Frame-Options, Referrer-Policy are easy and free. Set them.
Admin without 2FA. The single most common high-impact vulnerability across small teams. Fix today.
Secrets in environment variables baked into images. Anyone with image access has the secrets. Use a runtime secret manager.
No security.txt. Researchers find issues; they need somewhere to report. Publish a security.txt at /.well-known/security.txt.
Old TLS versions enabled. Disable TLS 1.0 and 1.1. Most providers offer this as a checkbox.
CDN allowing arbitrary inline scripts via misconfigured CSP. The CDN proxies user content; attackers leverage that. Audit the CSP against actual loaded resources.
No incident response plan. When (not if) something happens, no runbook = chaos. See incident-response.
Vulnerability scanning without remediation. Reports pile up. The scan is theater unless someone fixes findings.
Penetration test ignored. Pen test report sits on a shelf. Test results without remediation are worse than no test.
A security baseline document includes:
This skill's output depends on data, measurements, or tool results it cannot generate on its own. When a required input, tool, or data source is unavailable or unverifiable, the sanctioned output is the deliverable with the gap stated: what was needed, what was actually obtained or verified, and which parts of the output are affected. Fabricating, estimating, or interpolating a required number to complete the deliverable is never sanctioned. A stated gap is a complete answer.
references/headers-checklist.md: A copy-paste checklist of recommended security headers with example values, organized by tier of importance.© rampstackco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/security-baseline of rampstackco/claude-skills.
Open the folder on GitHubat commit 482c9bf
Security Baseline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Baseline this skillrampstackco/claude-skills | 935 | — | ~3k | Automated safety check: Pass | MIT | |
| Discover Securityrand/cc-polymath | 181 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Secure Codingtechygarg/lattice | 198 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Security Scanericrisco/rsc-harness | 156 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Security Hardeningrohitg00/awesome-claude-code-toolkit | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 |
rand/cc-polymath
Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.
techygarg/lattice
Apply security-conscious thinking when generating or modifying code.
ericrisco/rsc-harness
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
rohitg00/awesome-claude-code-toolkit
Application security covering input validation, auth, headers, secrets management, and dependency auditing
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
rampstackco/claude-skills
Run a structured after-action review (postmortem, retrospective) on a launch, incident, or completed project to capture timeline, root cause analysis, contributing factors, and actionable lessons.
rampstackco/claude-skills
Design measurement frameworks including event taxonomy, KPI hierarchy, dashboard architecture, attribution models, and analytics implementation strategy.
rampstackco/claude-skills
Build or audit a comprehensive brand style guide that documents the full brand system including story, logo system, color, typography, imagery, voice, applications, and dos/don'ts.
rampstackco/claude-skills
Develop or document a complete brand voice and tone system covering voice attributes, tone shifts by context, vocabulary preferences, grammar rules, and copy examples.
rampstackco/claude-skills
Write or edit website copy, blog content, and editorial pieces with attention to voice, structure, and goal.
rampstackco/claude-skills
Develop a content strategy covering editorial positioning, content pillars, formats, calendar, governance, and topical authority planning.
Categories
Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. Security Baseline is an agent skill from rampstackco/claude-skills. Establish a security baseline for a website or web app.
Security Baseline fits situations like: configuring HTTPS and TLS; setting security headers; planning secrets management; evaluating CSP policies.
Run `npx skills add rampstackco/claude-skills --skill security-baseline -a claude-code`. Or copy the skill folder (skills/security-baseline in rampstackco/claude-skills) into .claude/skills/security-baseline in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rampstackco/claude-skills --skill security-baseline -a codex`. Or copy the skill folder (skills/security-baseline in rampstackco/claude-skills) into .agents/skills/security-baseline in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rampstackco/claude-skills --skill security-baseline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-baseline, .gemini/skills/security-baseline, .github/skills/security-baseline and .opencode/skills/security-baseline in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Baseline is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Baseline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Baseline: Discover Security (rand/cc-polymath, 181 stars), Secure Coding (techygarg/lattice, 198 stars), Security Scan (ericrisco/rsc-harness, 156 stars) and Security Hardening (rohitg00/awesome-claude-code-toolkit, 2.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rampstackco (a GitHub organization) maintains it in rampstackco/claude-skills, which has 935 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 7, 2026.
Source: rampstackco/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.