Security And Hardening
Security And Hardening is an agent skill (a SKILL.md file) from addyosmani/agent-skills. Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external… It works with Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and OpenCode and has 102,166 GitHub stars across a repository of 13 listed skills.
github.com/addyosmani/agent-skills/skills/security-and-hardening (opens in a new tab)
- Multi-skill repo
- Plugin marketplace
- Security
- Actively maintained
Add this skill
Claude
This repository is a Claude Code plugin marketplace. In Claude Code:
/plugin marketplace add addyosmani/agent-skills
/plugin install agent-skills@addy-agent-skillsIn the Claude apps, zip the security-and-hardening folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).
ChatGPT / Codex
Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:
git clone --depth 1 https://github.com/addyosmani/agent-skills.git
cp -r agent-skills/skills/security-and-hardening .agents/skills/security-and-hardening # repo; ~/.agents/skills for all projectsStandalone skills also load in the ChatGPT desktop app.
Cursor
Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:
git clone --depth 1 https://github.com/addyosmani/agent-skills.git
cp -r agent-skills/skills/security-and-hardening .cursor/skills/security-and-hardening # project; ~/.cursor/skills for all projectsSource (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)
What this skill does
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
When it triggers
- Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten.
- Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
- Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package.
More skills in addyosmani/agent-skills
13 skills are listed from this repository.
Code Review And Qualityaddyosmani/agent-skills
API And Interface Designaddyosmani/agent-skills
Performance Optimizationaddyosmani/agent-skills
Frontend UI Engineeringaddyosmani/agent-skills
Documentation And Adrsaddyosmani/agent-skills
Code Simplificationaddyosmani/agent-skills
Observability And Instrumentationaddyosmani/agent-skills
Debugging And Error Recoveryaddyosmani/agent-skills
Doubt Driven Developmentaddyosmani/agent-skills
Context Engineeringaddyosmani/agent-skills
Interview Meaddyosmani/agent-skills
Shipping And Launchaddyosmani/agent-skills
Similar skills
More security skills
Wizard
mattpocock/skills
Generate an interactive bash wizard that walks a human through steps only they can perform.
SecurityShellPostgres Patterns
affaan-m/ECC
PostgreSQL database patterns for query optimization, schema design, indexing, and security.
SecurityJavaScriptPonytail Audit
DietrichGebert/ponytail
Whole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents.
SecurityJavaScriptNext Bundle Optimizer
vercel/next.js
Audit and reduce Next.js browser initial-load work.
OfficialSecurityJavaScriptCloud
browser-use/browser-use
Documentation reference for using Browser Use Cloud — the hosted API and SDK for browser automation.
OfficialSecurityPythonBrowser Auth Flow
ruvnet/ruflo
Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md.
SecurityTypeScript
What is the Security And Hardening skill?
Security And Hardening is an agent skill (a SKILL.md file) from addyosmani/agent-skills. Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external… It works with Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and OpenCode and has 102,166 GitHub stars across a repository of 13 listed skills. Its SKILL.md lives at github.com/addyosmani/agent-skills/skills/security-and-hardening.
How do I install the Security And Hardening skill?
In Claude Code, run /plugin marketplace add addyosmani/agent-skills and then /plugin install agent-skills@addy-agent-skills. For Codex or Cursor, copy the security-and-hardening folder into .agents/skills/ or .cursor/skills/.
Is the Security And Hardening skill free?
Yes. The repository is open source under the MIT license.
Is Security And Hardening maintained?
The repository's most recent commit was on Oct 3, 2026. Its latest release is 0.6.12. appsgit only lists skills from repositories with a commit in the last six months.