interview-me
78Clarify User Intent Before You Build
Underspecified requests cause teams to build the wrong outcome and discover misalignment late. This skill runs a focused, one-question interview that turns ambiguity into confirmed intent.
Harden Applications Against Security Risks
Security reviews can miss trust boundaries and unsafe data flows. This skill supplies threat-modeling prompts, OWASP patterns, and practical review checklists.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "security-and-hardening" from https://skillstore.io/skills/addyosmani-security-and-hardening.md and its manifest at https://skillstore.io/api/skills/addyosmani-security-and-hardening/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "security-and-hardening". Review an endpoint that accepts a webhook URL and fetches it on behalf of a user.
Expected outcome:
Using "security-and-hardening". Assess an LLM feature that renders model replies in a web page.
Expected outcome:
Using "security-and-hardening". Triage a high-severity package advisory from a native package-manager audit.
Expected outcome:
All 96 findings are false positives from examples and Markdown in SKILL.md. No executable behavior or prompt injection was found.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/addyosmani-security-and-hardening?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/addyosmani-security-and-hardening?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/addyosmani-security-and-hardening/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/addyosmani-security-and-hardening.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>addyosmani. (2026). security-and-hardening security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2@techreport{addyosmani-addyosmani-security-and-hardening-2026,
author = {addyosmani},
title = {security-and-hardening security audit report (audit version 2)},
institution = {Skillstore},
year = {2026},
number = {2},
url = {https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "security-and-hardening security audit report (audit version 2)"
version: "unspecified"
type: report
authors:
- name: "addyosmani"
date-released: "2026-09-19"
url: "https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2"
identifiers:
- type: other
value: "skillstore:addyosmani-security-and-hardening:audit:2"
description: "Skillstore immutable audit report identifier"
Map trust boundaries, validate request data, check authorization, and identify abuse cases before shipping an endpoint.
Triage audit results by reachability, review install scripts and provenance, and define a documented remediation decision.
Evaluate prompt injection, unsafe model output, excessive tool permissions, data exposure, and unbounded consumption risks.
Review this feature for trust boundaries, untrusted inputs, authentication, authorization, and sensitive data exposure. List the three most important fixes.
Audit this API endpoint against relevant OWASP risks. Check validation, queries, output encoding, access control, rate limits, errors, and logging. Cite issues and propose fixes.
Triage these package audit results. Check reachability, available fixes, install scripts, provenance, and lockfile impact. Recommend an action and review date.
Threat-model this LLM feature. Analyze prompt injection, unsafe output, data exposure, tool permissions, retrieval isolation, SSRF, limits, and irreversible actions. Prioritize controls and tests.
Author
addyosmaniLicense
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
5d5054f8a23586f9b500fece1cb613a9dffc787b
Maintenance freshness
9/19/2026
Usage
1 downloads ยท 0 views
File structure
๐ SKILL.md
Clarify User Intent Before You Build
Underspecified requests cause teams to build the wrong outcome and discover misalignment late. This skill runs a focused, one-question interview that turns ambiguity into confirmed intent.
Review Code Across Five Quality Axes
Code reviews often miss risks when they focus only on tests or style. This skill guides a consistent review of correctness, readability, architecture, security, and performance.
Plan Work Into Verifiable Tasks
Large or vague software work can hide dependencies, missing acceptance criteria, and verification gaps. This skill converts a specification into ordered task slices with checkpoints, scope guidance, and clear completion conditions.
Document Decisions and Architecture Clearly
Teams lose context when important technical decisions remain in chat, code comments, or individual memory. This skill turns architectural reasoning, API guidance, project instructions, and release changes into structured documentation.
Build Accessible, Production-Ready Frontends
Frontend work can become inconsistent, inaccessible, or difficult to maintain. This skill guides component architecture, responsive layouts, state handling, and polished user experiences.
Debug Errors with a Root-Cause Workflow
Debugging failures by guesswork wastes time and can hide the real cause. This skill provides a repeatable process for reproducing, isolating, fixing, and verifying problems.
Strengthen Application Security Reviews
by alirezarezvani
Security reviews often lack consistent checklists and reusable workflows. This skill provides security review scaffolds, reference guidance, and simple reporting scripts for Claude, Codex, and Claude Code.
Audit Code for Security Risks
by Barnhardt-Enterprises-Inc
Security-sensitive code is easy to ship with hidden flaws in authentication, input handling, and secrets. This skill gives Claude, Codex, and Claude Code structured security references and scanner guidance for safer reviews.
Build Secure Backend Services
by sickn33
Backend flaws can expose data, accounts, and infrastructure. This skill guides secure implementation and review using established defensive patterns.
Review Code for Security Fundamentals
by DanielPodolsky
Security mistakes often appear in common areas like authentication, authorization, input handling, and data exposure. This skill gives Claude, Codex, and Claude Code a focused checklist for finding those risks during review.
Audit Python Web Apps Before Release
by glenskii
Python teams need repeatable checks for common application security controls. This skill provides configurable pytest coverage with clear evidence, boundaries, and release decisions.
Strengthen Security Engineering Decisions
by 89jobrien
Security work often spans architecture, identity, compliance, testing, and response planning. This skill gives Claude, Codex, and Claude Code structured security engineering guidance.