Security And Hardening
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install receptron/mulmoterminal blueprint-local-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/blueprints/local/skills/security .claude/skills/blueprint-local-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "blueprint-local-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/security into .claude/skills/blueprint-local-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-local-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install receptron/mulmoterminal blueprint-local-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/blueprints/local/skills/security .agents/skills/blueprint-local-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "blueprint-local-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/security into .agents/skills/blueprint-local-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-local-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install receptron/mulmoterminal blueprint-local-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/blueprints/local/skills/security .cursor/skills/blueprint-local-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "blueprint-local-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/security into .cursor/skills/blueprint-local-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-local-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/receptron/mulmoterminal.git --path blueprints/local/skills/security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install receptron/mulmoterminal blueprint-local-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/blueprints/local/skills/security .gemini/skills/blueprint-local-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "blueprint-local-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/security into .gemini/skills/blueprint-local-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-local-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install receptron/mulmoterminal blueprint-local-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .github/skills && cp -r skills-src/blueprints/local/skills/security .github/skills/blueprint-local-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "blueprint-local-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/security into .github/skills/blueprint-local-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-local-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install receptron/mulmoterminal blueprint-local-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/blueprints/local/skills/security .opencode/skills/blueprint-local-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "blueprint-local-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/local/skills/security into .opencode/skills/blueprint-local-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-local-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
blueprint-local-securityReview the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.
Blueprint Local Security is an agent skill from receptron/mulmoterminal. Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities. The repository describes itself as: Run multiple Claude Code and Codex sessions in parallel — a browser terminal grid that shows which agent needs you. Local, tmux-backed, MIT. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b3f6ff0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
yarngitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use yarn and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Blueprint Local Security loads about 1.5k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 901 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
secret random and in `.env`, with `.env` listed in `.gitignore` (add it if it is not; the check fails on an `.env` thain `ALLOWED_HOSTS` (comma-separated, in `.env`) → **421**, on every path, `/` included.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from receptron/mulmoterminal at commit b3f6ff0, republished under its MIT licence (© receptron). 901 words, ~1,507 tokens.
.claude/skills/blueprint-local-security/SKILL.md (or your agent's skills folder).The app is built and runs. Before it is handed over, review it the way an attacker would read it, fix what is exploitable, and leave a report the person can read. The check does not take your word for it: it starts the built server and sends it the requests an attack would send.
.blueprint/spec.md (above all "必ず詰める点"), then all of server/, client/src/ and
package.json. Note who may do what, where input enters, and what is stored.test/security.test.ts that fails without the fix..blueprint/security-review.md (format below).Severity: HIGH is directly exploitable (read or change someone's data, bypass sign-in, run code). MEDIUM needs a specific condition but the impact is real. LOW is defence in depth. Report a finding only when you can state how it is exploited and you are at least 70% sure; a guess is not a finding. Do not report denial of service, rate limits, memory or CPU exhaustion, or missing validation on a field that cannot cause harm.
/api route enforces the spec's sign-in and roles on the server; with
accounts, a row is read or changed only by whoever may (no id-guessing into another person's data). DNS
rebinding: listening on 127.0.0.1 is not enough, because a web page can point its own name at 127.0.0.1 and
then call this API as a same-origin page. Refuse any request whose Host is not on the allow-list.x-powered-by off; no permissive
CORS; the default host stays 127.0.0.1.yarn audit --groups dependencies has no high or critical; the
lockfile is kept; no dependency the app does not use.scrypt, compared with timingSafeEqual; the session
secret random and in .env, with .env listed in .gitignore (add it if it is not; the check fails on an .env that is not ignored); cookies HttpOnly and SameSite=Lax.eval built from input; the
screen never renders input as HTML (v-html only on text the app itself wrote).Put these in front of everything, in server/ (one small module, applied in the function that builds the app):
Host name (port ignored) is not localhost, 127.0.0.1, [::1], the HOST setting, or one
listed in ALLOWED_HOSTS (comma-separated, in .env) → 421, on every path, / included./api whose Origin (or, without one, Referer) is not this server's own
origin → 403, before routing and before sign-in. A request with neither header is a script, not a page:
let it through to sign-in.Content-Security-Policy with frame-ancestors 'none' (start from default-src 'self';
object-src 'none'), X-Content-Type-Options: nosniff, Referrer-Policy. No X-Powered-By.SyntaxError text.test/security.test.ts proves each of these against the app built on a temporary database, plus one test per
finding you fixed. Keep the existing tests passing: a test that talks to the app sends an allowed Host.
.blueprint/security-review.md, in the spec's language. One section per category, its heading naming the id
(## A01 … through ## A10 …), each with what you checked and every finding on a line of its own:
- HIGH fixed: <what was wrong, how it could be exploited> — <what changed, which test proves it>
- LOW accepted: <what, and why it is acceptable for this app>The state is fixed, open or accepted. A HIGH or MEDIUM may not be open or accepted: fix it, or ask
through the blueprint question tool if fixing it would change what the spec asks for. A category with nothing
to report says what was checked and "指摘なし".
Done when the check passes: the report covers A01–A10 with nothing HIGH or MEDIUM left open, the tests pass,
the audit is clean, and the running server refuses the rebound Host, the cross-origin change and the
malformed body, and sends the headers.
.blueprint/spec.md first. It is the agreed specification; do not widen it.git init: a new repository loses the folder's trust and the next unattended step stops at Claude
Code's trust prompt. The user adds git themselves after the build if they want it.© receptron, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in blueprints/local/skills/security of receptron/mulmoterminal.
Open the folder on GitHubat commit b3f6ff0
Blueprint Local Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Blueprint Local Security this skillreceptron/mulmoterminal | 237 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 68k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None |
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
usestrix/strix
Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.
receptron/mulmoterminal
Help desk for "MulmoTerminal is broken". An agent skill from receptron/mulmoterminal.
receptron/mulmoterminal
Check what this project's humans have already been asked, and how they answered, before asking them something similar.
receptron/mulmoterminal
Help desk for questions about MulmoTerminal itself — what it can do, how a feature or a part of the screen works, how to set something up, what is new in this version or in the latest one.
receptron/mulmoterminal
Decide which moments MulmoTerminal beeps or pushes for, and what each one plays — soundKinds, sounds and pushKinds in ~/.mulmoterminal/config.json, plus a per-project sound / sounds in…
receptron/mulmoterminal
Build a colour scheme of your own for MulmoTerminal — one that joins Midnight, Nord, Daylight and Solarized in Settings' theme picker and can then be pinned per project.
receptron/mulmoterminal
Answer each question from the named documents only, quoting where the answer is written, or saying plainly that the documents do not say — changing nothing yet.
Categories
Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report. Blueprint Local Security is an agent skill from receptron/mulmoterminal. Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.
Blueprint Local Security fits situations like: tasks that involve Web application vulnerabilities.
Run `npx skills add receptron/mulmoterminal --skill blueprint-local-security -a claude-code`. Or copy the skill folder (blueprints/local/skills/security in receptron/mulmoterminal) into .claude/skills/blueprint-local-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add receptron/mulmoterminal --skill blueprint-local-security -a codex`. Or copy the skill folder (blueprints/local/skills/security in receptron/mulmoterminal) into .agents/skills/blueprint-local-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add receptron/mulmoterminal --skill blueprint-local-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blueprint-local-security, .gemini/skills/blueprint-local-security, .github/skills/blueprint-local-security and .opencode/skills/blueprint-local-security in your project.
Going by SKILL.md and its folder, Blueprint Local Security needs the command-line tools its instructions call (yarn and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Blueprint Local Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Blueprint Local Security: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
receptron (a GitHub organization) maintains it in receptron/mulmoterminal, which has 237 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 10, 2026.
Source: receptron/mulmoterminal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.