Agent skill

Security Hardening

by rohitg00 in rohitg00/awesome-claude-code-toolkit

Application security covering input validation, auth, headers, secrets management, and dependency auditing

Apache-2.0Auto-check: notesDevOps & Cloud

Install Security Hardening

skills CLI
$ npx skills add rohitg00/awesome-claude-code-toolkit --skill security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rohitg00/awesome-claude-code-toolkit security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rohitg00/awesome-claude-code-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-hardening .claude/skills/security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-hardening
GitHub stars
2.7k
Token cost
~1.5k tokens
SKILL.md length
373 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Application security covering input validation, auth, headers, secrets management, and dependency auditing

  • Works in 10 steps: All inputs validated with schema… → SQL queries parameterized → Security headers configured → …
  • Tasks that involve Secrets management
  • SKILL.md covers Input Validation, Output Encoding, SQL Injection Prevention and CSRF Protection, plus 7 more sections
  • Calls gitleaks, npm and npx

What it does

Security Hardening is an agent skill from rohitg00/awesome-claude-code-toolkit. Application security covering input validation, auth, headers, secrets management, and dependency auditing

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management, Security review and Web application vulnerabilities. The repository describes itself as: The most comprehensive toolkit for Claude Code -- 135 agents, 35 curated skills, 42 commands, 176+ plugins, 20 hooks, 15 rules, 7 templates, 14 MCP configs, 26 companion apps, 52… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secrets management
  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/security-hardening”

Requirements

  • Python 3
  • Node.js

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. All inputs validated with schema validation
  2. SQL queries parameterized
  3. Security headers configured
  4. HTTPS enforced with HSTS
  5. Secrets externalized, not in code
  6. Dependencies audited, no critical vulnerabilities
  7. Rate limiting on all public endpoints
  8. Authentication tokens expire and rotate
  9. Error messages do not leak internal details
  10. Logging captures security events without sensitive data

What it can do on your machine

Read from SKILL.md and the folder at commit ebdf1d5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gitleaks
    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Hardening loads about 1.5k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:160
    o version control (use `.gitignore` for `.env`)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rohitg00/awesome-claude-code-toolkit at commit ebdf1d5, republished under its Apache-2.0 licence (© rohitg00). 373 words, ~1,511 tokens.

Download SKILL.mdSave it as .claude/skills/security-hardening/SKILL.md (or your agent's skills folder).
name
security-hardening
description
Application security covering input validation, auth, headers, secrets management, and dependency auditing

Security Hardening

Input Validation

Validate all input at the boundary. Never trust client-side validation alone.

typescript
import { z } from 'zod';

const CreateUserSchema = z.object({
  email: z.string().email().max(255),
  name: z.string().min(1).max(100).regex(/^[a-zA-Z\s'-]+$/),
  age: z.number().int().min(13).max(150),
});

function createUser(req: Request) {
  const result = CreateUserSchema.safeParse(req.body);
  if (!result.success) {
    return { status: 400, errors: result.error.flatten().fieldErrors };
  }
  // result.data is typed and validated
}

Rules:

  • Validate type, length, format, and range on every input
  • Use allowlists over denylists (accept known good, reject everything else)
  • Validate file uploads: check MIME type, file extension, and magic bytes
  • Limit request body size at the server/proxy level (e.g., 1MB max)

Output Encoding

typescript
// Prevent XSS: encode output based on context
// HTML context: use framework auto-escaping (React does this by default)
// Never use dangerouslySetInnerHTML with user input

// URL context: encode parameters
const safeUrl = `/search?q=${encodeURIComponent(userInput)}`;

// JSON context: use JSON.stringify (handles escaping)
const safeJson = JSON.stringify({ query: userInput });

Never construct HTML strings with user input. Use templating engines with auto-escaping enabled.

SQL Injection Prevention

python
# NEVER do this
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")

# Always use parameterized queries
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))
typescript
// NEVER do this
db.query(`SELECT * FROM users WHERE email = '${email}'`);

// Always use parameterized queries
db.query("SELECT * FROM users WHERE email = $1", [email]);

Use an ORM or query builder. If writing raw SQL, always parameterize.

CSRF Protection

typescript
// Server: generate and validate CSRF tokens
import { randomBytes } from 'crypto';

function generateCsrfToken(): string {
  return randomBytes(32).toString('hex');
}

// Middleware: validate on state-changing requests
function csrfMiddleware(req, res, next) {
  if (['POST', 'PUT', 'PATCH', 'DELETE'].includes(req.method)) {
    const token = req.headers['x-csrf-token'] || req.body._csrf;
    if (!timingSafeEqual(token, req.session.csrfToken)) {
      return res.status(403).json({ error: 'Invalid CSRF token' });
    }
  }
  next();
}

For APIs with token-based auth (Bearer tokens), CSRF is not needed since the token is not auto-sent by browsers.

Content Security Policy

Content-Security-Policy:
  default-src 'self';
  script-src 'self' 'nonce-{random}';
  style-src 'self' 'unsafe-inline';
  img-src 'self' data: https:;
  font-src 'self';
  connect-src 'self' https://api.example.com;
  frame-ancestors 'none';
  base-uri 'self';
  form-action 'self';

Start strict, relax as needed. Use nonce for inline scripts instead of unsafe-inline. Report violations with report-uri directive. Test with Content-Security-Policy-Report-Only first.

Security Headers

Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()

Set these on every response. Use helmet (Node.js) or equivalent middleware.

Rate Limiting

typescript
// Per-user, per-endpoint rate limiting
const rateLimits = {
  'POST /auth/login':    { window: '15m', max: 5 },
  'POST /auth/register': { window: '1h',  max: 3 },
  'POST /api/*':         { window: '1m',  max: 60 },
  'GET /api/*':          { window: '1m',  max: 120 },
};

Use sliding window algorithm. Store counters in Redis. Return 429 with Retry-After header. Apply stricter limits to authentication endpoints.

JWT Best Practices

  • Use short expiry (15 minutes) for access tokens
  • Use refresh tokens (7-30 days) stored in httpOnly cookies
  • Sign with RS256 (asymmetric) for microservices, HS256 (symmetric) for monoliths
  • Never store sensitive data in JWT payload (it is base64 encoded, not encrypted)
  • Validate iss, aud, exp, and nbf claims on every request
  • Implement token revocation via a denylist or short expiry + rotation
typescript
// Verify JWT with all checks
const payload = jwt.verify(token, publicKey, {
  algorithms: ['RS256'],
  issuer: 'auth.example.com',
  audience: 'api.example.com',
  clockTolerance: 30,
});
Show full SKILL.md (143 more words)Show less

Secrets Management

  • Never commit secrets to version control (use .gitignore for .env)
  • Use environment variables for runtime secrets
  • Use a secrets manager in production (AWS Secrets Manager, HashiCorp Vault, Doppler)
  • Rotate secrets regularly (90-day maximum for API keys)
  • Use different secrets per environment (dev/staging/prod)
  • Scan for leaked secrets in CI: trufflehog, gitleaks, git-secrets
bash
# Check for secrets in git history
gitleaks detect --source . --verbose

# Pre-commit hook to prevent secret commits
gitleaks protect --staged

Dependency Auditing

bash
# Node.js
npm audit --production
npx better-npm-audit audit --level=high

# Python
pip-audit
safety check

# Go
govulncheck ./...

Run dependency audits in CI on every PR. Block merges on critical/high vulnerabilities. Pin dependency versions. Update dependencies weekly with automated PRs (Dependabot, Renovate).

Checklist Before Deploy

  1. All inputs validated with schema validation
  2. SQL queries parameterized
  3. Security headers configured
  4. HTTPS enforced with HSTS
  5. Secrets externalized, not in code
  6. Dependencies audited, no critical vulnerabilities
  7. Rate limiting on all public endpoints
  8. Authentication tokens expire and rotate
  9. Error messages do not leak internal details
  10. Logging captures security events without sensitive data

© rohitg00, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-hardening of rohitg00/awesome-claude-code-toolkit.

Open the folder on GitHubat commit ebdf1d5

Compare with similar skills

Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Hardening this skillrohitg00/awesome-claude-code-toolkit2.7k—~1.5kAutomated safety check: NotesApache-2.0
Secure Codingtechygarg/lattice199—~1.5kAutomated safety check: PassMIT
Security Scanericrisco/rsc-harness180—~2.8kAutomated safety check: NotesMIT
Security Baselinerampstackco/claude-skills945—~3kAutomated safety check: PassMIT
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Vercel Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT

Similar skills

  • Secure Coding

    techygarg/lattice

    Apply security-conscious thinking when generating or modifying code.

    199 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    180 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Baseline

    rampstackco/claude-skills

    Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills.

    945 GitHub stars~3k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from rohitg00/awesome-claude-code-toolkit

All 38 skills in this repo
  • Accessibility Wcag

    rohitg00/awesome-claude-code-toolkit

    Web accessibility patterns for WCAG 2.2 compliance including ARIA, keyboard navigation, screen readers, and testing

    2.7k GitHub stars~1.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Agentkit SEO

    rohitg00/awesome-claude-code-toolkit

    Route broad or ambiguous AgentKit SEO work to the right module while keeping context scoped.

    2.7k GitHub stars~879 tokensUpdated 5 mo ago
    Auto-check passed
  • API Design Patterns

    rohitg00/awesome-claude-code-toolkit

    REST API design with resource naming, pagination, versioning, and OpenAPI spec generation

    2.7k GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check passed
  • Authentication Patterns

    rohitg00/awesome-claude-code-toolkit

    Authentication and authorization patterns including OAuth2, JWT, RBAC, session management, and PKCE flows

    2.7k GitHub stars~1.4k tokensUpdated 5 mo ago
    Auto-check passed
  • AWS Cloud Patterns

    rohitg00/awesome-claude-code-toolkit

    AWS cloud patterns for Lambda, ECS, S3, DynamoDB, and Infrastructure as Code with CDK/Terraform

    2.7k GitHub stars~1.1k tokensUpdated 5 mo ago
    Auto-check passed
  • CI CD Pipelines

    rohitg00/awesome-claude-code-toolkit

    CI/CD pipeline patterns for GitHub Actions, GitLab CI, testing strategies, and deployment automation

    2.7k GitHub stars~1.1k tokensUpdated 5 mo ago
    Auto-check passed

Questions about Security Hardening

What does Security Hardening do?

Application security covering input validation, auth, headers, secrets management, and dependency auditing. Security Hardening is an agent skill from rohitg00/awesome-claude-code-toolkit.

When should I use Security Hardening?

Security Hardening fits situations like: tasks that involve Secrets management; tasks that involve Security review; tasks that involve Web application vulnerabilities.

How do I install Security Hardening in Claude Code?

Run `npx skills add rohitg00/awesome-claude-code-toolkit --skill security-hardening -a claude-code`. Or copy the skill folder (skills/security-hardening in rohitg00/awesome-claude-code-toolkit) into .claude/skills/security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Security Hardening in Codex?

Run `npx skills add rohitg00/awesome-claude-code-toolkit --skill security-hardening -a codex`. Or copy the skill folder (skills/security-hardening in rohitg00/awesome-claude-code-toolkit) into .agents/skills/security-hardening in your project. Codex loads it when a task matches its description.

Can I use Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rohitg00/awesome-claude-code-toolkit --skill security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-hardening, .gemini/skills/security-hardening, .github/skills/security-hardening and .opencode/skills/security-hardening in your project.

What does Security Hardening need to run?

Going by SKILL.md and its folder, Security Hardening needs the command-line tools its instructions call (gitleaks, npm and npx). Our summary lists: Python 3; Node.js.

Does Security Hardening access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Hardening safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Hardening use?

Security Hardening is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Hardening use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Hardening?

Skills that share tags, products or a category with Security Hardening: Secure Coding (techygarg/lattice, 199 stars), Security Scan (ericrisco/rsc-harness, 180 stars), Security Baseline (rampstackco/claude-skills, 945 stars) and Discover Security (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Hardening?

rohitg00 (a GitHub user) maintains it in rohitg00/awesome-claude-code-toolkit, which has 2,686 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on May 12, 2026.

Source: rohitg00/awesome-claude-code-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.