harden
Applies NIST/CWE security hardening to Python and Rust code Skill: harden Owner: athola Summary: Applies NIST/CWE security hardening to Python and Rust code Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:46.218Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:00.969Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:43.255Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:05.262Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:07.173Z | user Release v1.9
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-harden- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
144,443 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: harden
description: Applies NIST/CWE security hardening to Python and Rust code
version: 1.9.8
triggers:
- security
- hardening
- nist
- supply-chain
- python
- rust
- cwe
- auditing code for vulnerabilities or proposing concrete security remediations
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83d\udd12", "requires": {"config": ["night-market.pensive:safety-critical-patterns", "night-market.pensive:rust-review", "night-market.pensive:bug-review", "night-market.pensive:tiered-audit", "night-market.pensive:blast-radius", "night-market.leyline:supply-chain-advisory", "night-market.leyline:authentication-patterns", "night-market.leyline:content-sanitization", "night-market.abstract:hook-authoring", "night-market.imbue:proof-of-work"]}}}
source: claude-night-market
source_plugin: pensive
---
> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
# Harden Codebase Skill
Active security hardening — scan the existing repository for
vulnerabilities and forward-facing threats, then propose concrete
remediations the user can approve, defer, or file.
This skill is the engine behind `/harden`. It complements the
Claude Code built-in `/security-review` (which scans the pending
diff) by sweeping the whole repository against citation-backed
checks rather than line-level review of in-flight code.
## When To Use
- Quarterly security-posture audits.
- Before tagging a release that touches sensitive code paths.
- After a published advisory affects the language ecosystem.
- When onboarding a new repository and want a baseline.
- After integrating a new dependency or upstream service.
## When NOT To Use
- Pending-diff review on a single PR. Use `/security-review`.
- Architecture-level threat modeling. Use `attune:war-room`
with a security-focused panel.
- Cryptographic protocol review. The skill flags suspect crypto
but does not propose protocol fixes (specialist work).
- One-off bug hunting. Use `pensive:bug-review`.
## Required TodoWrite Items
1. `harden:discovery` — inventory languages, build files, hooks,
CI workflows
2. `harden:scan-python` — run python-checks.md detectors when
Python is present
3. `harden:scan-rust` — run rust-checks.md detectors when Rust
is present
4. `harden:scan-cross-cutting` — run cross-cutting.md detectors
(deps, secrets, SBOM, CI)
5. `harden:scan-frontier` — run frontier-checks.md (PQC, LLM
supply chain, sandboxing)
6. `harden:nist-mapping` — map findings to NIST SSDF practices
7. `harden:proposals` — for each finding above the threshold,
draft a concrete remediation per `modules/proposal-shape.md`
8. `harden:approval-gate` — present proposals to the user for
apply / file / defer / reject
9. `harden:apply-and-validate`_meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-pensive-harden",
"version": "1.9.19",
"publishedAt": 1787750326218
}modules/cross-cutting.md
# Cross-Cutting Hardening Checks Checks that apply regardless of the source language: dependency posture, secret hygiene, CI/CD chain, container shape, and the SBOM. ## Dependency posture (composes leyline:supply-chain-advisory) | ID | Check | CWE / NIST | Detection | |----|-------|------------|-----------| | DEP01 | Lockfile committed | PW.4 | absence of `uv.lock` / `Cargo.lock` / `package-lock.json` | | DEP02 | Dependency scanner runs in CI | RV.1 | no `pip-audit`/`cargo audit`/`npm audit` step in workflows | | DEP03 | Known-bad versions blocked | CWE-829 | `leyline:supply-chain-advisory` blocklist not consulted | | DEP04 | Auto-update bot configured | RV.1 | no `dependabot.yml` / `renovate.json` | | DEP05 | Direct deps pinned to exact versions | CWE-494 | `^1.2` / `~1.2` / `1.2.*` for security-critical deps | | DEP06 | Hash-pinned for top-tier supply-chain trust | CWE-494 | `--require-hashes` not used in `pip` / `requirements.txt` | | DEP07 | License policy enforced | none | no `cargo deny` license rules / no `pip-licenses` check | ## Secret hygiene | ID | Check | CWE | Detection | |----|-------|-----|-----------| | SEC01 | Pre-commit secret scanner installed | CWE-798 | no `gitleaks` / `trufflehog` / `talisman` in `.pre-commit-config.yaml` | | SEC02 | `.env` files git-ignored | CWE-200 | `.env` tracked or unmatched in `.gitignore` | | SEC03 | Long-lived secrets in CI | CWE-798 | `secrets.SOME_KEY` used without `if: github.event_name != 'pull_request'` | | SEC04 | OIDC publishing configured | CWE-798 | PyPI/Cargo publish step uses `password:` rather than OIDC `id-token: write` | | SEC05 | Audit trail for secret access | PW.7 | repo settings: secret-access logs not retained | | SEC06 | Sealed-secrets / secret manager | CWE-798 | secrets baked into config files instead of fetched from a manager | ## CI/CD chain (GitHub Actions example) | ID | Check | NIST SSDF | Detection | |----|-------|-----------|-----------| | CI01 | Third-party actions pinned by SHA, not tag | PW.4 | `uses: foo/bar@v1` instead of `@<full SHA>` | | CI02 | `permissions:` block per workflow | PW.4 | top-level `permissions:` missing or `permissions: write-all` | | CI03 | `GITHUB_TOKEN` minimum scope | PW.4 | default permissions used when `contents: read` would suffice | | CI04 | Concurrency cancel for stale runs | RV.2 | no `concurrency.cancel-in-progress: true` | | CI05 | Workflow dispatch requires approval for protected branches | PW.4 | branch protection allows direct dispatch | | CI06 | SLSA provenance generated for releases | RV.2 | release workflow does not invoke `slsa-framework/slsa-github-generator` | | CI07 | SBOM generated and attached to releases | RV.2 | release workflow lacks `cyclonedx`/`syft`/`spdx-sbom-generator` step | ## Container hardening (when Dockerfiles exist) | ID | Check | CWE | Detection | |----|-------|-----|-----------| | CO01 | Non-root `USER` set | CWE-269 | `USER root` or `USER` directive missing | | CO02 | `FROM` is digest-pinned | CWE-
modules/frontier-checks.md
# Frontier Hardening Checks (2025-2026) Forward-facing checks that defend against threats just emerging in production. Findings here are usually MEDIUM by default because exploitation is non-trivial; promote to HIGH when the codebase has a high-value attack surface (auth provider, signing service, data plane). ## Post-quantum migration readiness The NSA CNSA 2.0 timeline targets quantum-resistant crypto for NSS by 2030; PCI DSS 4.0.1 expects an inventory by 2026. Most application code is not the right place to swap algorithms, but the *crypto-agility* posture is. | ID | Check | Citation | Detection | |----|-------|----------|-----------| | PQ01 | Signing/verification has a single hard-coded algorithm | NIST IR 8547 | `algorithms = ["RS256"]` or `algorithms = ["EdDSA"]` literal in JWT/JWS code | | PQ02 | Algorithm selection driven by config, not code | NIST IR 8547 | move the algorithm list behind a `signing_algorithms` config field | | PQ03 | Inventory of crypto APIs in the repo | NIST CNSA 2.0 | no `docs/crypto-inventory.md` or equivalent | | PQ04 | TLS clients accept algorithm downgrade silently | CWE-757 | `requests` / `reqwest` defaults without minimum-TLS pin | The proposal for PQ02 is usually a small refactor: move `algorithms = ["EdDSA"]` into a config table the operator can override. The skill does not propose ML-DSA / Falcon migration in application code (still specialist work). ## LLM and agentic supply chain A new failure mode in 2025: AI assistants suggest dependencies that look plausible but do not exist (or are typosquats). The checks below defend the development pipeline itself. | ID | Check | Citation | Detection | |----|-------|----------|-----------| | LLM01 | Index pinning to defeat dependency confusion | OWASP LLM Top 10 #08 | `pyproject.toml` lacks `[[tool.uv.index]]` priority order | | LLM02 | New deps require human review | OWASP LLM Top 10 #08 | no CI rule blocking auto-merge on dep PRs | | LLM03 | LLM SDK calls validate role/instruction boundaries | OWASP LLM Top 10 #01 | system prompt concatenated with user input without separator/role | | LLM04 | Tool-use response sanitization | OWASP LLM Top 10 #02 | tool output rendered to UI/terminal without escape | | LLM05 | MCP server allowlist of tools | OWASP LLM Top 10 #02 | MCP config mounts every tool from a server (no allowlist) | | LLM06 | Agent action audit trail | OWASP LLM Top 10 #06 | no log of tool invocations with inputs | ## Sandbox / isolation posture For codebases that execute user-supplied or AI-supplied code: | ID | Check | Why | Today's option | |----|-------|-----|----------------| | SB01 | User code runs in same process as host | host privilege escalation | Pyodide WASM (Python), wasmtime (Rust) | | SB02 | Network egress unrestricted from sandbox | data exfiltration | gVisor egress policy, NetworkPolicy in K8s | | SB03 | Filesystem capabilities ambient | path-based attacks | `cap-std` (Rust), bind-mount only required dirs | | SB04 | Resource limits
modules/nist-controls.md
# NIST and CWE Citation Backbone Every finding in a hardening report carries a citation. This module is the lookup table. ## NIST SSDF (SP 800-218) practice mapping The Secure Software Development Framework defines four practice groups: Prepare the Organization (PO), Protect Software (PS), Produce Well-Secured Software (PW), Respond to Vulnerabilities (RV). Findings map to PW and RV most often. | Practice | What it requires | Detector signal | |----------|------------------|-----------------| | PW.4 | Reuse existing well-secured software | dependencies pinned, scanned, attested | | PW.5 | Create source code aligned with secure practices | linter enforces auth/crypto/serialization rules | | PW.6 | Configure compilation, build processes, links | RUSTFLAGS hardening, Python `-W error`, reproducible builds | | PW.7 | Review and analyze human-readable code | SAST run in CI; findings tracked | | PW.8 | Test executable code | fuzz coverage, mutation tests, property tests | | PW.9 | Configure software with secure default settings | yaml SafeLoader, TLS verify on, autoescape on | | RV.1 | Identify, confirm vulnerabilities on a continuous basis | dependency scanner runs on every push | | RV.2 | Assess, prioritize, remediate vulnerabilities | severity policy, SLA per severity | | RV.3 | Analyze vulnerabilities to identify root causes | post-incident notes feed PW.4-9 | The skill's executive summary lists each practice and whether the codebase has at least one detector firing for it. Coverage <80% of PW.4-PW.9 is itself a finding (RV.1 unmet). ## CWE Top 25 (2024) mapping The skill prioritizes detectors that map to the CWE Top 25 most dangerous software weaknesses. Per-finding citations name the specific CWE, not just "Top 25." | CWE | Title | Languages most often hit | |-----|-------|--------------------------| | CWE-79 | Cross-site Scripting | Python, JS | | CWE-787 | Out-of-bounds Write | Rust unsafe, C/C++ FFI | | CWE-89 | SQL Injection | Python, Rust | | CWE-352 | CSRF | Python web frameworks | | CWE-22 | Path Traversal | All | | CWE-125 | Out-of-bounds Read | Rust unsafe, C/C++ FFI | | CWE-78 | OS Command Injection | Python (subprocess), shell scripts | | CWE-416 | Use After Free | Rust unsafe, C/C++ | | CWE-862 | Missing Authorization | Web layer | | CWE-434 | Unrestricted File Upload | Web layer | | CWE-94 | Code Injection | Python (eval/exec), template engines | | CWE-20 | Improper Input Validation | All | | CWE-77 | Command Injection | All shell-out paths | | CWE-287 | Improper Authentication | Auth layer | | CWE-269 | Improper Privilege Management | Container, sudo | | CWE-502 | Deserialization of Untrusted Data | Python, Java | | CWE-200 | Exposure of Sensitive Information | Logs, errors, telemetry | | CWE-863 | Incorrect Authorization | Web layer | | CWE-918 | Server-Side Request Forgery | URL fetchers | | CWE-119 | Improper Restriction of Operations within Memory Buffer | Rust unsafe, C/C++ | | CWE-476 | NULL Pointer Dereference | Rust
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-pensive-harden",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-harden",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T16:09:39.775Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T16:09:39.775Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/athola/nm-pensive-harden",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-harden",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T16:09:39.775Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-harden",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-harden",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:18:46.218Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-harden",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-harden",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:18:46.218Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
