
Security and Hardening
Securityby addyosmani
3/3 audits passMIT
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…
Security and Hardening is from Addy Osmani's agent-skills collection (publisher addyosmani, MIT licence). It teaches the agent to threat-model before adding controls: map trust boundaries (including LLM output and values handed over by the OS), name the assets, run STRIDE over each boundary and write abuse cases next to use cases. It then applies a three-tier boundary system of things to always do (validate input, parameterize queries, encode output, hash passwords, set security headers), things that need human approval, and things never to do. Hardening controls cover injection and XSS, authentication and sessions, headers and CORS, uploads, SSRF, destructive operations on derived paths, rate limiting, secrets, dependencies and supply chain, personal data and privacy, and AI/LLM features, followed by a review checklist, red flags and verification steps, with a reference file of hardening patterns.
Use it when building features that accept untrusted input, handle auth, store sensitive data or call external services, or when triaging dependency audit findings and GDPR or CCPA concerns. It is development guidance, not a scanner.
This skill is mainly for coding agents such as Claude Code working in your codebase; BusinessMCP can import it as a playbook, but it adds little to business-data questions.
What you can do with it
- Threat-model a new webhook or file upload endpoint
- Review a login flow against the OWASP Top Ten
- Harden a server-side fetch against SSRF
- Check an LLM feature for prompt-injection trust boundaries
Run it on your business data
Imported into BusinessMCP, Security and Hardening becomes a playbook your AI business analyst applies to your connected GitHub repositories.
Use Security and Hardening in BusinessMCPInstall it in a coding agent
One command adds Security and Hardening to your project.
npx skills add https://github.com/addyosmani/agent-skills --skill security-and-hardeningHow we vetted it
- Source
- addyosmani/agent-skills at bcab6a1
- Licence
- MIT
- Security audits (skills.sh)
- Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
- Bundled scripts
- None, instructions only
Checked 2026-09-25 against its skills.sh listing. How we vet skills
Related skills
All skillsSecrets Management
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
Differential Review
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and…
Semgrep
Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep…
Frequently asked questions
What does Security and Hardening ask the agent to do first?
Threat-model: map trust boundaries, name the assets worth protecting, run STRIDE over each boundary and write abuse cases alongside use cases.
Does it cover AI and LLM features?
Yes. It treats LLM output as untrusted input at a trust boundary and has a dedicated hardening section for AI/LLM features.
How do I install Security and Hardening?
Run `npx skills add addyosmani/agent-skills --skill security-and-hardening`, or import it from the BusinessMCP dashboard as a playbook.
Run Security and Hardening against your whole business
Free plan, no credit card.
Use Security and Hardening in BusinessMCP