BusinessMCP
Security and Hardening logo

Security and Hardening

Security

by addyosmani

3/3 audits passMIT

Use Security and Hardening in BusinessMCP

Free · imported in one click after signup

View on GitHub

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…

Security and Hardening is from Addy Osmani's agent-skills collection (publisher addyosmani, MIT licence). It teaches the agent to threat-model before adding controls: map trust boundaries (including LLM output and values handed over by the OS), name the assets, run STRIDE over each boundary and write abuse cases next to use cases. It then applies a three-tier boundary system of things to always do (validate input, parameterize queries, encode output, hash passwords, set security headers), things that need human approval, and things never to do. Hardening controls cover injection and XSS, authentication and sessions, headers and CORS, uploads, SSRF, destructive operations on derived paths, rate limiting, secrets, dependencies and supply chain, personal data and privacy, and AI/LLM features, followed by a review checklist, red flags and verification steps, with a reference file of hardening patterns.

Use it when building features that accept untrusted input, handle auth, store sensitive data or call external services, or when triaging dependency audit findings and GDPR or CCPA concerns. It is development guidance, not a scanner.

This skill is mainly for coding agents such as Claude Code working in your codebase; BusinessMCP can import it as a playbook, but it adds little to business-data questions.

What you can do with it

  • Threat-model a new webhook or file upload endpoint
  • Review a login flow against the OWASP Top Ten
  • Harden a server-side fetch against SSRF
  • Check an LLM feature for prompt-injection trust boundaries

Run it on your business data

Imported into BusinessMCP, Security and Hardening becomes a playbook your AI business analyst applies to your connected GitHub repositories.

Use Security and Hardening in BusinessMCP

Install it in a coding agent

One command adds Security and Hardening to your project.

npx skills add https://github.com/addyosmani/agent-skills --skill security-and-hardening

How we vetted it

Source
addyosmani/agent-skills at bcab6a1
Licence
MIT
Security audits (skills.sh)
Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
Bundled scripts
None, instructions only

Checked 2026-09-25 against its skills.sh listing. How we vet skills

Frequently asked questions

What does Security and Hardening ask the agent to do first?

Threat-model: map trust boundaries, name the assets worth protecting, run STRIDE over each boundary and write abuse cases alongside use cases.

Does it cover AI and LLM features?

Yes. It treats LLM output as untrusted input at a trust boundary and has a dedicated hardening section for AI/LLM features.

How do I install Security and Hardening?

Run `npx skills add addyosmani/agent-skills --skill security-and-hardening`, or import it from the BusinessMCP dashboard as a playbook.

Run Security and Hardening against your whole business

Free plan, no credit card.

Use Security and Hardening in BusinessMCP