agentCLAWHUBUnverified

harden

Applies NIST/CWE security hardening to Python and Rust code Skill: harden Owner: athola Summary: Applies NIST/CWE security hardening to Python and Rust code Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:18:46.218Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:00.969Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:55:43.255Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:05.262Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:07.173Z | user Release v1.9

OpenClaw

Rank

62

Safety

84

Downloads

1.0k

Updated

Oct 11, 2026

Version

1.9.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1K downloadsadoption · observed Oct 11, 2026
Latest release
1.9.19release · observed Aug 26, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-harden
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/snapshot"

Run-check

$0.02 USD

1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.

Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.

Documentation

CLAWHUB

144,443 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: harden
description: Applies NIST/CWE security hardening to Python and Rust code
version: 1.9.8
triggers:
  - security
  - hardening
  - nist
  - supply-chain
  - python
  - rust
  - cwe
  - auditing code for vulnerabilities or proposing concrete security remediations
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83d\udd12", "requires": {"config": ["night-market.pensive:safety-critical-patterns", "night-market.pensive:rust-review", "night-market.pensive:bug-review", "night-market.pensive:tiered-audit", "night-market.pensive:blast-radius", "night-market.leyline:supply-chain-advisory", "night-market.leyline:authentication-patterns", "night-market.leyline:content-sanitization", "night-market.abstract:hook-authoring", "night-market.imbue:proof-of-work"]}}}
source: claude-night-market
source_plugin: pensive
---

> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.


# Harden Codebase Skill

Active security hardening — scan the existing repository for
vulnerabilities and forward-facing threats, then propose concrete
remediations the user can approve, defer, or file.

This skill is the engine behind `/harden`. It complements the
Claude Code built-in `/security-review` (which scans the pending
diff) by sweeping the whole repository against citation-backed
checks rather than line-level review of in-flight code.

## When To Use

- Quarterly security-posture audits.
- Before tagging a release that touches sensitive code paths.
- After a published advisory affects the language ecosystem.
- When onboarding a new repository and want a baseline.
- After integrating a new dependency or upstream service.

## When NOT To Use

- Pending-diff review on a single PR. Use `/security-review`.
- Architecture-level threat modeling. Use `attune:war-room`
  with a security-focused panel.
- Cryptographic protocol review. The skill flags suspect crypto
  but does not propose protocol fixes (specialist work).
- One-off bug hunting. Use `pensive:bug-review`.

## Required TodoWrite Items

1. `harden:discovery` — inventory languages, build files, hooks,
   CI workflows
2. `harden:scan-python` — run python-checks.md detectors when
   Python is present
3. `harden:scan-rust` — run rust-checks.md detectors when Rust
   is present
4. `harden:scan-cross-cutting` — run cross-cutting.md detectors
   (deps, secrets, SBOM, CI)
5. `harden:scan-frontier` — run frontier-checks.md (PQC, LLM
   supply chain, sandboxing)
6. `harden:nist-mapping` — map findings to NIST SSDF practices
7. `harden:proposals` — for each finding above the threshold,
   draft a concrete remediation per `modules/proposal-shape.md`
8. `harden:approval-gate` — present proposals to the user for
   apply / file / defer / reject
9. `harden:apply-and-validate`

_meta.json

{
  "ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
  "slug": "nm-pensive-harden",
  "version": "1.9.19",
  "publishedAt": 1787750326218
}

modules/cross-cutting.md

# Cross-Cutting Hardening Checks

Checks that apply regardless of the source language: dependency
posture, secret hygiene, CI/CD chain, container shape, and the
SBOM.

## Dependency posture (composes leyline:supply-chain-advisory)

| ID | Check | CWE / NIST | Detection |
|----|-------|------------|-----------|
| DEP01 | Lockfile committed | PW.4 | absence of `uv.lock` / `Cargo.lock` / `package-lock.json` |
| DEP02 | Dependency scanner runs in CI | RV.1 | no `pip-audit`/`cargo audit`/`npm audit` step in workflows |
| DEP03 | Known-bad versions blocked | CWE-829 | `leyline:supply-chain-advisory` blocklist not consulted |
| DEP04 | Auto-update bot configured | RV.1 | no `dependabot.yml` / `renovate.json` |
| DEP05 | Direct deps pinned to exact versions | CWE-494 | `^1.2` / `~1.2` / `1.2.*` for security-critical deps |
| DEP06 | Hash-pinned for top-tier supply-chain trust | CWE-494 | `--require-hashes` not used in `pip` / `requirements.txt` |
| DEP07 | License policy enforced | none | no `cargo deny` license rules / no `pip-licenses` check |

## Secret hygiene

| ID | Check | CWE | Detection |
|----|-------|-----|-----------|
| SEC01 | Pre-commit secret scanner installed | CWE-798 | no `gitleaks` / `trufflehog` / `talisman` in `.pre-commit-config.yaml` |
| SEC02 | `.env` files git-ignored | CWE-200 | `.env` tracked or unmatched in `.gitignore` |
| SEC03 | Long-lived secrets in CI | CWE-798 | `secrets.SOME_KEY` used without `if: github.event_name != 'pull_request'` |
| SEC04 | OIDC publishing configured | CWE-798 | PyPI/Cargo publish step uses `password:` rather than OIDC `id-token: write` |
| SEC05 | Audit trail for secret access | PW.7 | repo settings: secret-access logs not retained |
| SEC06 | Sealed-secrets / secret manager | CWE-798 | secrets baked into config files instead of fetched from a manager |

## CI/CD chain (GitHub Actions example)

| ID | Check | NIST SSDF | Detection |
|----|-------|-----------|-----------|
| CI01 | Third-party actions pinned by SHA, not tag | PW.4 | `uses: foo/bar@v1` instead of `@<full SHA>` |
| CI02 | `permissions:` block per workflow | PW.4 | top-level `permissions:` missing or `permissions: write-all` |
| CI03 | `GITHUB_TOKEN` minimum scope | PW.4 | default permissions used when `contents: read` would suffice |
| CI04 | Concurrency cancel for stale runs | RV.2 | no `concurrency.cancel-in-progress: true` |
| CI05 | Workflow dispatch requires approval for protected branches | PW.4 | branch protection allows direct dispatch |
| CI06 | SLSA provenance generated for releases | RV.2 | release workflow does not invoke `slsa-framework/slsa-github-generator` |
| CI07 | SBOM generated and attached to releases | RV.2 | release workflow lacks `cyclonedx`/`syft`/`spdx-sbom-generator` step |

## Container hardening (when Dockerfiles exist)

| ID | Check | CWE | Detection |
|----|-------|-----|-----------|
| CO01 | Non-root `USER` set | CWE-269 | `USER root` or `USER` directive missing |
| CO02 | `FROM` is digest-pinned | CWE-

modules/frontier-checks.md

# Frontier Hardening Checks (2025-2026)

Forward-facing checks that defend against threats just emerging
in production. Findings here are usually MEDIUM by default
because exploitation is non-trivial; promote to HIGH when the
codebase has a high-value attack surface (auth provider, signing
service, data plane).

## Post-quantum migration readiness

The NSA CNSA 2.0 timeline targets quantum-resistant crypto for
NSS by 2030; PCI DSS 4.0.1 expects an inventory by 2026. Most
application code is not the right place to swap algorithms, but
the *crypto-agility* posture is.

| ID | Check | Citation | Detection |
|----|-------|----------|-----------|
| PQ01 | Signing/verification has a single hard-coded algorithm | NIST IR 8547 | `algorithms = ["RS256"]` or `algorithms = ["EdDSA"]` literal in JWT/JWS code |
| PQ02 | Algorithm selection driven by config, not code | NIST IR 8547 | move the algorithm list behind a `signing_algorithms` config field |
| PQ03 | Inventory of crypto APIs in the repo | NIST CNSA 2.0 | no `docs/crypto-inventory.md` or equivalent |
| PQ04 | TLS clients accept algorithm downgrade silently | CWE-757 | `requests` / `reqwest` defaults without minimum-TLS pin |

The proposal for PQ02 is usually a small refactor: move
`algorithms = ["EdDSA"]` into a config table the operator can
override. The skill does not propose ML-DSA / Falcon migration
in application code (still specialist work).

## LLM and agentic supply chain

A new failure mode in 2025: AI assistants suggest dependencies
that look plausible but do not exist (or are typosquats). The
checks below defend the development pipeline itself.

| ID | Check | Citation | Detection |
|----|-------|----------|-----------|
| LLM01 | Index pinning to defeat dependency confusion | OWASP LLM Top 10 #08 | `pyproject.toml` lacks `[[tool.uv.index]]` priority order |
| LLM02 | New deps require human review | OWASP LLM Top 10 #08 | no CI rule blocking auto-merge on dep PRs |
| LLM03 | LLM SDK calls validate role/instruction boundaries | OWASP LLM Top 10 #01 | system prompt concatenated with user input without separator/role |
| LLM04 | Tool-use response sanitization | OWASP LLM Top 10 #02 | tool output rendered to UI/terminal without escape |
| LLM05 | MCP server allowlist of tools | OWASP LLM Top 10 #02 | MCP config mounts every tool from a server (no allowlist) |
| LLM06 | Agent action audit trail | OWASP LLM Top 10 #06 | no log of tool invocations with inputs |

## Sandbox / isolation posture

For codebases that execute user-supplied or AI-supplied code:

| ID | Check | Why | Today's option |
|----|-------|-----|----------------|
| SB01 | User code runs in same process as host | host privilege escalation | Pyodide WASM (Python), wasmtime (Rust) |
| SB02 | Network egress unrestricted from sandbox | data exfiltration | gVisor egress policy, NetworkPolicy in K8s |
| SB03 | Filesystem capabilities ambient | path-based attacks | `cap-std` (Rust), bind-mount only required dirs |
| SB04 | Resource limits 

modules/nist-controls.md

# NIST and CWE Citation Backbone

Every finding in a hardening report carries a citation. This
module is the lookup table.

## NIST SSDF (SP 800-218) practice mapping

The Secure Software Development Framework defines four practice
groups: Prepare the Organization (PO), Protect Software (PS),
Produce Well-Secured Software (PW), Respond to Vulnerabilities
(RV). Findings map to PW and RV most often.

| Practice | What it requires | Detector signal |
|----------|------------------|-----------------|
| PW.4 | Reuse existing well-secured software | dependencies pinned, scanned, attested |
| PW.5 | Create source code aligned with secure practices | linter enforces auth/crypto/serialization rules |
| PW.6 | Configure compilation, build processes, links | RUSTFLAGS hardening, Python `-W error`, reproducible builds |
| PW.7 | Review and analyze human-readable code | SAST run in CI; findings tracked |
| PW.8 | Test executable code | fuzz coverage, mutation tests, property tests |
| PW.9 | Configure software with secure default settings | yaml SafeLoader, TLS verify on, autoescape on |
| RV.1 | Identify, confirm vulnerabilities on a continuous basis | dependency scanner runs on every push |
| RV.2 | Assess, prioritize, remediate vulnerabilities | severity policy, SLA per severity |
| RV.3 | Analyze vulnerabilities to identify root causes | post-incident notes feed PW.4-9 |

The skill's executive summary lists each practice and whether the
codebase has at least one detector firing for it. Coverage <80%
of PW.4-PW.9 is itself a finding (RV.1 unmet).

## CWE Top 25 (2024) mapping

The skill prioritizes detectors that map to the CWE Top 25 most
dangerous software weaknesses. Per-finding citations name the
specific CWE, not just "Top 25."

| CWE | Title | Languages most often hit |
|-----|-------|--------------------------|
| CWE-79 | Cross-site Scripting | Python, JS |
| CWE-787 | Out-of-bounds Write | Rust unsafe, C/C++ FFI |
| CWE-89 | SQL Injection | Python, Rust |
| CWE-352 | CSRF | Python web frameworks |
| CWE-22 | Path Traversal | All |
| CWE-125 | Out-of-bounds Read | Rust unsafe, C/C++ FFI |
| CWE-78 | OS Command Injection | Python (subprocess), shell scripts |
| CWE-416 | Use After Free | Rust unsafe, C/C++ |
| CWE-862 | Missing Authorization | Web layer |
| CWE-434 | Unrestricted File Upload | Web layer |
| CWE-94 | Code Injection | Python (eval/exec), template engines |
| CWE-20 | Improper Input Validation | All |
| CWE-77 | Command Injection | All shell-out paths |
| CWE-287 | Improper Authentication | Auth layer |
| CWE-269 | Improper Privilege Management | Container, sudo |
| CWE-502 | Deserialization of Untrusted Data | Python, Java |
| CWE-200 | Exposure of Sensitive Information | Logs, errors, telemetry |
| CWE-863 | Incorrect Authorization | Web layer |
| CWE-918 | Server-Side Request Forgery | URL fetchers |
| CWE-119 | Improper Restriction of Operations within Memory Buffer | Rust unsafe, C/C++ |
| CWE-476 | NULL Pointer Dereference | Rust 
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/athola/skills/nm-pensive-harden",
      "sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-harden",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T16:09:39.775Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T16:09:39.775Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1K downloads",
      "href": "https://clawhub.ai/athola/nm-pensive-harden",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-harden",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T16:09:39.775Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-harden",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-harden",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:18:46.218Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-harden/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.9.19",
      "description": "Release v1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-harden",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-harden",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:18:46.218Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to harden and adjacent AI workflows.