| name | security |
| description | Application and server security — OWASP Top 10, WordPress hardening, server hardening (UFW/fail2ban), SSL/TLS, secrets management, WAF |
| version | 1.0.0 |
| author | veekunth217 |
| tags | ["security","owasp","hardening","ssl","tls","waf","fail2ban","ufw","secrets","wordpress-security","xss","sqli"] |
| platforms | ["claude-code","cursor","codex"] |
Security Skill
Application security, server hardening, and secrets management — from OWASP Top 10 mitigations to production WAF configuration.
RULE: Security changes are high-impact. Always show what will change, explain the risk being mitigated, and wait for GO.
🚧 Status: Stub — implementation pending
This reference skill has the structure but the snippet content is still being filled in
(you'll see <!-- TODO --> placeholders below). It activates and tells Claude the topic
exists, but won't yield deep snippets yet.
Want to help? Pick any TODO, write the snippet, open a PR. See CONTRIBUTING.md.
Each contribution moves the skill closer to "Ready" status.
Capabilities
OWASP Top 10
WordPress Hardening
Server Hardening (UFW / fail2ban)
SSL/TLS Configuration
Secrets Management
WAF Configuration
Quick Wins (apply to any server)
fail2ban WordPress jail
[wordpress]
enabled = true
filter = wordpress
logpath = /var/log/nginx/access.log
maxretry = 5
bantime = 3600
findtime = 600
[Definition]
failregex = ^<HOST> .* "POST /wp-login.php
ignoreregex =
Nginx security headers
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
server_tokens off;
SSH hardening (/etc/ssh/sshd_config)
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
AllowUsers [your-user]
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2