security-and-hardening - Harden web applications against common security threats
Applies threat modeling and secure development practices to protect web applications handling untrusted input, authentication, sensitive data, and external services.
Tags
Updated: 2026-10-04Capabilities
What this skill does
- Model threats with STRIDE
- Validate external input
- Parameterize database queries
- Encode output against XSS
- Secure passwords and sessions
- Configure security headers
- Check authorization boundaries
- Restrict SSRF targets
- Review dependency audit findings
- Assess security-sensitive changes
Inputs
- Application code
- Untrusted user input
- Authentication and session flows
- Sensitive data
- External service integrations
- File uploads and webhooks
- Dependency audit results
Outputs
- Hardened application code
- Threat models
- Security configuration changes
- Security audit findings
