
Security Scanning Security Hardening
Run a phased defense-in-depth hardening program that turns scan findings into remediations and validated controls across app and CI/CD.
Install
npx skills add https://github.com/sickn33/antigravity-awesome-skills --skill security-scanning-security-hardeningWhat is this skill?
- Three-phase orchestration: security baseline, high-risk remediation, control implementation and validation
- Defense-in-depth across application, infrastructure, and compliance layers
- Shift-left and automated scanning aligned with modern DevSecOps workflows
- Explicit gates: skip when unauthorized for invasive testing or environment cannot tolerate hardening
- Prioritizes remediation from scans and threat modeling inputs
Adoption & trust: 466 installs on skills.sh; 40.1k GitHub stars; 1/3 security scanners passed (skills.sh audits).
Recommended Skills
Azure Compliancemicrosoft/azure-skills
Openclaw Secure Linux Cloudxixu-me/skills
Entra Agent Idmicrosoft/azure-skills
Firebase Security Rules Auditorfirebase/agent-skills
Firestore Security Rules Auditorfirebase/agent-skills
Skill Vetteruseai-pro/openclaw-skills-security
Journey fit
Common Questions / FAQ
Is Security Scanning Security Hardening safe to install?
skills.sh reports 1 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.
SKILL.md
READMESKILL.md - Security Scanning Security Hardening
Implement comprehensive security hardening with defense-in-depth strategy through coordinated multi-agent orchestration: [Extended thinking: This workflow implements a defense-in-depth security strategy across all application layers. It coordinates specialized security agents to perform comprehensive assessments, implement layered security controls, and establish continuous security monitoring. The approach follows modern DevSecOps principles with shift-left security, automated scanning, and compliance validation. Each phase builds upon previous findings to create a resilient security posture that addresses both current vulnerabilities and future threats.] ## Use this skill when - Running a coordinated security hardening program - Establishing defense-in-depth controls across app, infra, and CI/CD - Prioritizing remediation from scans and threat modeling ## Do not use this skill when - You only need a quick scan without remediation work - You lack authorization for security testing or changes - The environment cannot tolerate invasive security controls ## Instructions 1. Execute Phase 1 to establish a security baseline. 2. Apply Phase 2 remediations for high-risk issues. 3. Implement Phase 3 controls and validate defenses. 4. Complete Phase 4 validation and compliance checks. ## Safety - Avoid intrusive testing in production without approval. - Ensure rollback plans exist before hardening changes. ## Phase 1: Comprehensive Security Assessment ### 1. Initial Vulnerability Scanning - Use Task tool with subagent_type="security-auditor" - Prompt: "Perform comprehensive security assessment on: $ARGUMENTS. Execute SAST analysis with Semgrep/SonarQube, DAST scanning with OWASP ZAP, dependency audit with Snyk/Trivy, secrets detection with GitLeaks/TruffleHog. Generate SBOM for supply chain analysis. Identify OWASP Top 10 vulnerabilities, CWE weaknesses, and CVE exposures." - Output: Detailed vulnerability report with CVSS scores, exploitability analysis, attack surface mapping, secrets exposure report, SBOM inventory - Context: Initial baseline for all remediation efforts ### 2. Threat Modeling and Risk Analysis - Use Task tool with subagent_type="security-auditor" - Prompt: "Conduct threat modeling using STRIDE methodology for: $ARGUMENTS. Analyze attack vectors, create attack trees, assess business impact of identified vulnerabilities. Map threats to MITRE ATT&CK framework. Prioritize risks based on likelihood and impact." - Output: Threat model diagrams, risk matrix with prioritized vulnerabilities, attack scenario documentation, business impact analysis - Context: Uses vulnerability scan results to inform threat priorities ### 3. Architecture Security Review - Use Task tool with subagent_type="backend-api-security::backend-architect" - Prompt: "Review architecture for security weaknesses in: $ARGUMENTS. Evaluate service boundaries, data flow security, authentication/authorization architecture, encryption implementation, network segmentation. Design zero-trust architecture patterns. Reference threat model and vulnerability findings." - Output: Security architecture assessment, zero-trust design recommendations, service mesh security requirements, data classification matrix - Context: Incorporates threat model to address architectural vulnerabilities ## Phase 2: Vulnerability Remediation ### 4. Critical Vulnerability Fixes - Use Task tool with subagent_type="security-auditor" - Prompt: "Coordinate immediate remediation of critical vulnerabilities (CVSS 7+) in: $ARGUMENTS. Fix SQL injections with parameterized queries, XSS with output encoding, authentication bypasses with secure session management, insecure deserialization with input validation. Apply security patches for CVEs." - O