# Security And Hardening (agent skill)

> Security And Hardening is an agent skill (a SKILL.md file) from addyosmani/agent-skills. Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external… It works with Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot and OpenCode and has 102,166 GitHub stars across a repository of 13 listed skills.

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/addyosmani/agent-skills |
| Skill path | skills/security-and-hardening/SKILL.md |
| Skill name | security-and-hardening |
| GitHub stars | 102,166 |
| Installs on skills.sh | 52,721 |
| License | MIT |
| Skills in repo | 13 |
| Plugin marketplace | addy-agent-skills |
| Official | no |
| Works with | Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode |
| Category | Security |
| Last commit | Oct 3, 2026 |

## When it triggers

- Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten.
- Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
- Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package.

## Add this skill

### Claude Code

```sh
/plugin marketplace add addyosmani/agent-skills
/plugin install agent-skills@addy-agent-skills
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/addyosmani/agent-skills.git
cp -r agent-skills/skills/security-and-hardening .agents/skills/security-and-hardening   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/addyosmani/agent-skills.git
cp -r agent-skills/skills/security-and-hardening .cursor/skills/security-and-hardening   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

skills.sh listing: https://www.skills.sh/addyosmani/agent-skills/security-and-hardening

---

Canonical page: https://appsgit.com/skills/addyosmani-security-and-hardening
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
