Agent skill

Security Hardening

by swyxio in swyxio/skills

Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass.

MITAuto-check passedSecurity

Install Security Hardening

skills CLI
$ npx skills add swyxio/skills --skill security-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install swyxio/skills security-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/swyxio/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security-hardening .claude/skills/security-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-hardening
GitHub stars
176
Token cost
~962 tokens
SKILL.md length
440 words
Files
3 (incl. references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass.

  • Works in 5 steps: Map the attack surface → Build a risk-ranked plan → Harden the highest-risk paths → …
  • Explicitly requests a security audit
  • SKILL.md covers Counterweight: threat before…, Workflow and Quality Bar
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Hardening is an agent skill from swyxio/skills. Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass. Do not trigger for routine authentication changes, role design, scoped permissions, ordinary authorization bugs, dependency updates, generic production readiness, or feature implementation with incidental security implications.

Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/checklist.md`).

It sits in Security, covering Security review and Threat modeling. The repository describes itself as: Agent skills for Claude Code and other AI agents. The licence is MIT.

When your agent uses it

  • Explicitly requests a security audit
  • Vulnerability investigation
  • Scoped security-hardening pass
  • Routine authentication changes

Example prompts

  • “/security-hardening”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Map the attack surface
  2. Build a risk-ranked plan
  3. Harden the highest-risk paths
  4. Prove the fixes
  5. Report residual risk

What it can do on your machine

Read from SKILL.md and the folder at commit 038ef34. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Hardening loads about 962 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 440 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~962
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from swyxio/skills at commit 038ef34, republished under its MIT licence (© swyxio). 440 words, ~962 tokens.

Download SKILL.mdSave it as .claude/skills/security-hardening/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security-hardening
description
Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass. Do not trigger for routine authentication changes, role design, scoped permissions, ordinary authorization bugs, dependency updates, generic production readiness, or feature implementation with incidental security implications.

Security Hardening

Use this skill for pragmatic appsec work that produces prioritized fixes and residual-risk notes. Do not turn it into a compliance theater exercise.

Counterweight: threat before control

  • Start with assets, trust boundaries, attacker capability, exposure, and plausible abuse paths. Do not apply the checklist uniformly.
  • Add or change a control only for a concrete reachable risk. Record when framework or provider defaults already cover it.
  • Prefer removing exposure, privilege, data, or code over adding middleware, policy layers, scanners, and monitoring.
  • Do not add rate limits, CORS/CSRF machinery, headers, runtime schemas, encryption, secret rotation, or dependency upgrades where the threat model does not require them.
  • Preserve one authorization source of truth; do not duplicate permission checks across artificial layers.
  • Avoid speculative findings based only on pattern matches. Confirm actual callers, deployment topology, and runtime behavior.
  • Keep fixes focused. Do not turn one vulnerability into a repo-wide security program, compliance project, dependency refresh, or release ceremony.
  • A scoped review may correctly conclude that no code change is needed. Report accepted and out-of-scope risk plainly.
  • Do not mutate production, rotate credentials, contact users, or change provider policy unless the active request explicitly authorizes it.

Workflow

  1. Map the attack surface

    • Identify only the assets, entrypoints, trust boundaries, privileges, storage, and egress relevant to the defined review.
    • Trace plausible attacker paths through actual callers and deployment topology.
  2. Build a risk-ranked plan

    • Prioritize exploitable paths over theoretical issues.
    • Separate must-fix before release, should-fix soon, and accepted/deferred risks.
    • Preserve product behavior unless the vulnerability requires a behavior change.
  3. Harden the highest-risk paths

    • Add or tighten authorization checks at server/action boundaries.
    • Validate untrusted input at external/API/provider boundaries.
    • Protect secrets and redact sensitive logs.
    • Add rate limits, origin controls, CSRF/CORS policy, SSRF protections, upload constraints, or security headers only where the mapped threat requires them.
    • Audit dependencies and package scripts only within the reviewed attack surface.
  4. Prove the fixes

    • Add focused tests for permission bypasses, input rejection, dangerous URL/file cases, auth/session edge cases, and safe error/log payloads.
    • Run focused dependency or security tools when their signal applies to the reviewed surface.
    • Document what could not be verified.
  5. Report residual risk

    • List fixed issues with evidence.
    • List remaining risks with severity, exploit sketch, and recommended next action.
    • Avoid claiming the app is "secure"; state the reviewed scope.
Show full SKILL.md (56 more words)Show less

Quality Bar

  • Every reviewed server mutation has an authorization story.
  • Reviewed secrets are not exposed through reachable logs, clients, fixtures, or outputs.
  • Reviewed external inputs have threat-appropriate validation before side effects.
  • Reviewed dangerous network or file operations have threat-appropriate restrictions.
  • Focused tests prove the highest-risk changed bypass or failure cases.

For the audit checklist, read checklist.md.

© swyxio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in security-hardening of swyxio/skills.

  • SKILL.md
  • agents/openai.yaml
  • references/checklist.md

Open the folder on GitHubat commit 038ef34

Compare with similar skills

Security Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Hardening this skillswyxio/skills176—~962Automated safety check: PassMIT
Commit Security Scancodexstar69/bug-hunter520—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills157—~3.2kAutomated safety check: PassMIT
Threat Mitigation Mappingwshobson/agents40k8 repos~742Automated safety check: PassMIT
Audit Browser Security Boundariesnordstjernen-web/northstar-browser127—~920Automated safety check: PassGPL-3.0
Security Auditblueberrycongee/termcanvas405—~966Automated safety check: NotesMIT

Similar skills

  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    520 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed
  • Audit Browser Security Boundaries

    nordstjernen-web/northstar-browser

    Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

    127 GitHub stars~920 tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Audit

    blueberrycongee/termcanvas

    Security audit skill. An agent skill from blueberrycongee/termcanvas.

    405 GitHub stars~966 tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Security Review

    codexstar69/bug-hunter

    Run a focused STRIDE-based security review using Bug Hunter-native artifacts.

    520 GitHub stars~567 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from swyxio/skills

All 89 skills in this repo
  • Programmatic Agents

    swyxio/skills

    Run a selected coding-agent CLI programmatically, with latency, error, usage, cost, and trace logging.

    176 GitHub stars~2.2k tokensUpdated 6 days ago
    Auto-check passed
  • Design, implement, audit, or refresh protected username and handle namespaces for public products.

    176 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    176 GitHub stars~4.3k tokensUpdated 6 days ago
    Auto-check passed
  • Youtube API

    swyxio/skills

    Manage YouTube videos programmatically via the YouTube Data API v3 — upload video files, upload custom thumbnails, update video metadata (titles, descriptions, tags), and query video/channel info…

    176 GitHub stars~2.2k tokensUpdated 6 days ago
    Auto-check passed
  • Batch YouTube Studio upload workflow for videos sourced from Airtable, Google Drive, Loom, YouTube, or local files.

    176 GitHub stars~1.5k tokensUpdated 6 days ago
    Auto-check: warnings
  • Reconstruct and visually analyze paired agent, game, or policy trajectories to determine whether changed actions produced their intended effects.

    176 GitHub stars~1.8k tokensUpdated 6 days ago
    Auto-check passed

Categories

Questions about Security Hardening

What does Security Hardening do?

Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass. Security Hardening is an agent skill from swyxio/skills. Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass.

When should I use Security Hardening?

Security Hardening fits situations like: explicitly requests a security audit; vulnerability investigation; scoped security-hardening pass; routine authentication changes.

How do I install Security Hardening in Claude Code?

Run `npx skills add swyxio/skills --skill security-hardening -a claude-code`. Or copy the skill folder (security-hardening in swyxio/skills) into .claude/skills/security-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Security Hardening in Codex?

Run `npx skills add swyxio/skills --skill security-hardening -a codex`. Or copy the skill folder (security-hardening in swyxio/skills) into .agents/skills/security-hardening in your project. Codex loads it when a task matches its description.

Can I use Security Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add swyxio/skills --skill security-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-hardening, .gemini/skills/security-hardening, .github/skills/security-hardening and .opencode/skills/security-hardening in your project.

What does Security Hardening need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Hardening is instructions for the agent only.

Does Security Hardening access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Hardening use?

Security Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Hardening use?

About 962 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 444 tokens, read only when the agent opens those files.

What are the alternatives to Security Hardening?

Skills that share tags, products or a category with Security Hardening: Commit Security Scan (codexstar69/bug-hunter, 520 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars) and Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Hardening?

swyxio (a GitHub user) maintains it in swyxio/skills, which has 176 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 5, 2026.

Source: swyxio/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.