security-and-hardening
An agent skill by addyosmani, from addyosmani/agent-skills. Tags: api, debugging, developer-tools, web.
What it does
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add addyosmani/agent-skills --skill security-and-hardening
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/addyosmani/agent-skills
cp -r agent-skills/skills/security-and-hardening ~/.claude/skills/security-and-hardening
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- addyosmani/agent-skills (all skills from this repository)
- Path
- skills/security-and-hardening/SKILL.md
- Branch
- main
- Updated
- 2026-09-19
Related skills
- debugging-and-error-recovery — Guides systematic root-cause debugging.
- observability-and-instrumentation — Instruments code so production behavior is visible and diagnosable. Use when adding logging, metrics, tracing, or alerting.
- performance-optimization — Optimizes application performance across frontend, backend, queries, and databases.
- systematic-debugging — Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes
- browser-testing-with-devtools — Tests in real browsers via Chrome DevTools MCP. Use when building or debugging anything that runs in a browser.
- deprecation-and-migration — Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another.