LabscoConnect MCP ↗
addyosmani logo

security-and-hardening

Ready to use★ 102k on GitHub
part of addyosmani/agent-skillsby addyosmani

Has your assistant think like an attacker before writing security-sensitive code, mapping where untrusted data enters and running a quick STRIDE pass over each entry point. It then applies fixed rules split into always do, ask you first and never do, covering the OWASP Top 10 and the OWASP list for LLM apps, dependency and supply-chain checks, secrets, and personal data under GDPR or CCPA.

WHEN YOUR AGENT SHOULD USE IT

A QUICK BOUNDARY

USE FOR

  • Check that a login flow is safe before it ships.
  • Audit an input handler, file upload or webhook for injection and SSRF.
  • Triage npm audit and other package-manager findings by real reachability.
  • Vet a new dependency for typosquatting and install scripts.
  • Treat chatbot output as untrusted before it reaches SQL or HTML.
  • Design account deletion that really removes personal data, backups included.
  • Rate-limit login attempts across more than one server.