security-and-hardening

security-and-hardening is a skill for Claude Code from vinvcn/addyosmani-agent-skills-zh. It costs 53 tokens per session (2,842 once invoked), scanned A, original, MIT.

A security guide for software that accepts user input, handles accounts or sensitive data, or connects to outside services. It describes practices for protecting applications against common attacks.

In plain words
What is it for?
Use it when building or reviewing authentication, authorization, data storage, APIs, file uploads, webhooks, payments, or other features involving untrusted input or sensitive information.
Why use it?
It reduces the risk of problems such as injection, cross-site scripting, exposed secrets, unsafe sessions, and insecure external communication.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: positional $N argument.

Part of the agent-skills plugin — 23 skills, 8 commands, 3 agents, 1 hook shipped together

Good fit Use it when building or reviewing authentication, authorization, data storage, APIs, file uploads, webhooks, payments, or other features involving untrusted input or sensitive information.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add vinvcn/addyosmani-agent-skills-zh --skill security-and-hardening
Clone the repo
git clone --depth 1 https://github.com/vinvcn/addyosmani-agent-skills-zh

Made for: Claude Code.

Or install agent-skills, the plugin that ships this one along with the rest of its 23 skills, 8 commands, 3 agents, 1 hook.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-and-hardening

README.md
[![agentmods](https://agentmods.dev/badge/skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening/github.svg)](https://agentmods.dev/skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening)
Your own site
<a href="https://agentmods.dev/skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening"><img src="https://agentmods.dev/badge/skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for security-and-hardening

Your own site · 80×15
<a href="https://agentmods.dev/skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening"><img src="https://agentmods.dev/badge/skills/vinvcn/addyosmani-agent-skills-zh/security-and-hardening.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 53 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,842 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00053 $0.02842
Opus 5 $0.00026 $0.01421
Sonnet 5 $0.00011 $0.00568
Haiku 4.5 $0.00005 $0.00284

Measured 12d ago against content hash 6006690ea968, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

security-and-hardening scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/security-and-hardening/SKILL.md · 350 lines

How it starts

The opening of the file, as written. The whole thing — 350 lines — stays where its author put it; the contents beside it link to each section on GitHub.

安全和加固

概览

面向 Web 应用的安全优先开发实践。把每个外部输入都视为敌意输入,把每个 secret 都视为不可泄露,把每次授权检查都视为必需。安全不是一个阶段,而是触及用户数据、认证或外部系统的每一行代码都必须满足的约束。

何时使用

  • 构建任何接受用户输入的东西
  • 实现认证或授权
  • 存储或传输敏感数据
  • 集成外部 API 或服务
  • 添加文件上传、webhooks 或 callbacks
  • 处理支付或 PII 数据

三层边界系统

必须始终执行(无例外)

  • 在系统边界验证所有外部输入(API routes、form handlers)
  • 参数化所有数据库查询,绝不要把用户输入拼接进 SQL
  • 编码输出 以防止 XSS(使用框架自动转义,不要绕过它)
  • 所有外部通信使用 HTTPS
  • 使用 bcrypt/scrypt/argon2 哈希密码(绝不存储明文)
  • 设置安全 header(CSP、HSTS、X-Frame-Options、X-Content-Type-Options)
  • 会话使用 httpOnly、secure、sameSite cookies
  • 每次发布前运行 npm audit(或等价工具)

先询问(需要人工批准)

  • 添加新的认证流程或修改 auth 逻辑
  • 存储新的敏感数据类别(PII、支付信息)
  • 添加新的外部服务集成
  • 修改 CORS 配置
  • 添加文件上传 handler
  • 修改 rate limiting 或 throttling
  • 授予提升后的权限或角色

绝不执行

  • 绝不要将 secrets commit 到版本控制(API keys、passwords、tokens)
  • 绝不要记录敏感数据到日志(passwords、tokens、完整信用卡号)
  • 绝不要把客户端校验当作安全边界
  • 绝不要为了方便禁用安全 header
  • 绝不要对用户提供的数据使用 eval()innerHTML
  • 绝不要把会话存储在客户端可访问的存储中(auth tokens 放在 localStorage)
  • 绝不要向用户暴露 stack traces 或内部错误细节

OWASP Top 10 防护

1. Injection(SQL、NoSQL、OS Command)

// BAD: SQL injection via string concatenation
const query = `SELECT * FROM users WHERE id = '${userId}'`;

// GOOD: Parameterized query
const user = await db.query('SELECT * FROM users WHERE id = $1', [userId]);

// GOOD: ORM with parameterized input
const user = await prisma.user.findUnique({ where: { id: userId } });

2. Broken Authentication

// Password hashing
import { hash, compare } from 'bcrypt';

const SALT_ROUNDS = 12;
const hashedPassword = await hash(plaintext, SALT_ROUNDS);
const isValid = await compare(plaintext, hashedPassword);

// Session management
app.use(session({
  secret: process.env.SESSION_SECRET,  // From environment, not code
  resave: false,
  saveUninitialized: false,
  cookie: {
    httpOnly: true,     // Not accessible via JavaScript
    secure: true,       // HTTPS only
    sameSite: 'lax',    // CSRF protection
    maxAge: 24 * 60 * 60 * 1000,  // 24 hours
  },
}));

Read the full file on GitHub · 350 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 350 lines · 53 tokens per session scan A 6006690ea968

Subscribe to this mod's changes

security-and-hardening is a skill published in the GitHub repository vinvcn/addyosmani-agent-skills-zh (31 stars, last pushed 4mo ago), licensed MIT. It adds 53 tokens to every session and 2,842 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

test-driven-development

Drives development with tests via Red-Green-Refactor and the Prove-It pattern, with hard rules against weakening assertions or faking green suites. Use when implementing any logic, fixing any bug, or changing any behavior. Triggers on "add a feature", "fix this bug", "write tests", or any task where done must be…

borhen68/SkillEngine · 79 tokens

ai-ops

Guides operational excellence for AI/ML systems in production. Use when deploying models, managing inference infrastructure, monitoring model drift, or maintaining AI-powered features. Use when you need reliable, observable, and governable machine learning systems.

borhen68/SkillEngine · 50 tokens

ci-cd-and-automation

Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.

borhen68/SkillEngine · 45 tokens

context-engineering

Optimizes agent context setup. Use when starting a new session, when agent output quality degrades, when switching between tasks, or when you need to configure rules files and context for a project.

borhen68/SkillEngine · 43 tokens

data-engineering

Guides data pipeline design, ETL/ELT workflows, schema evolution, and data quality assurance. Use when building data pipelines, designing data warehouses, migrating schemas, or ensuring data integrity across systems. Use when you need reliable, testable, and observable data flows.

borhen68/SkillEngine · 59 tokens

debugging-and-error-recovery

Guides systematic root-cause debugging with hard rules against guess-fixes and symptom suppression. Use when tests fail, builds break, behavior doesn't match expectations, or you encounter any unexpected error. Triggers on "this is broken", "tests are failing", "why doesn't this work", or any error output.

borhen68/SkillEngine · 69 tokens