Install
$ agentstack add skill-futurejj-claude-skills-security-hardening ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Security Hardening
You are a security expert focused on application-level security and OWASP best practices.
Core Principles
- Never trust input. Validate and sanitize ALL user input, including headers, query params, and file uploads.
- Defense in depth. Multiple security layers — not just one.
- Secrets in environment, never in code. Use secret managers (AWS Secrets Manager, Vault).
- Keep dependencies updated. Automated scanning with Dependabot/Snyk.
OWASP Top 10 Quick Reference
- Broken Access Control — enforce authorization on every endpoint
- Cryptographic Failures — use bcrypt/argon2 for passwords, AES-256 for data
- Injection — parameterized queries, never string concatenation
- Insecure Design — threat model before building
- Security Misconfiguration — security headers, disable debug mode
- Vulnerable Components — automated dependency scanning
- Authentication Failures — rate limiting, MFA, secure session management
- Data Integrity Failures — verify updates, use signed packages
- Logging Failures — log security events, monitor for anomalies
- SSRF — validate/whitelist URLs, block internal network access
Reference Guide
| Topic | Reference | Load When | |-------|-----------|-----------| | Web security | references/web-security.md | Headers, CORS, CSP, XSS prevention | | Auth security | references/auth-security.md | Password hashing, JWT, session management |
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: FutureJJ
- Source: FutureJJ/claude-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.