name: 安全AndHardening slug: security-and-hardening version: 1.0.0 displayName: 安全AndHardening description: > 安全AndHardening專用技能,幫助AI Agent高效完成相關任務。 summary: "安全AndHardening專用技能,幫助AI Agent高效完成相關任務。" license: MIT category: 開發者工具 framework: - Claude Code - Codex - Hermes Agent - OpenClaw - QClaw - WorkBuddy platform: multi-platform homepage: "https://github.com/1991513ccie-png" repository: "https://github.com/1991513ccie-png"
Security-first development practices for web applications. Treat every external input as hostile, every secret as sacred, and every authorization check as mandatory. Security isn't a phase — it's a constraint on every line of code that touches user data, authentication, or external systems.
小蔥技能7w4.net持續更新中。
Controls bolted on without a threat model are guesses. Before hardening, spend five minutes thinking like an attacker:
| Threat | Ask | Typical mitigation | |
這是一款面向專業開發者的安全開發輔助Skill,質量中等偏上。它整理了系統的安全開發方法論,對提升程式碼安全性有一定幫助。優點是內容專業、覆蓋面廣;不足是內容不夠豐富,缺乏實際程式碼示例,實用性有待加強。對於想加強應用安全的開發者有一定參考價值。