agentsclimarketplace

Techtide ai generated code security hardener

Skill TechTideOhio/techtide-harness-kit/skills/techtide/techtide-ai-generated-code-security-hardener

Trust contracts for AI agent skills: JSON Schema risk tiers, tool permissions, deny-by-default egress, approval gates, prompt-injection fixtures, ~28 CI validation gates. Apache-2.0.

Install
npx -y skills add TechTideOhio/techtide-harness-kit --skill techtide-ai-generated-code-security-hardener

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Harden untrusted code by reviewing authentication, authorization, injection surfaces, dependency risk, secret exposure, unsafe defaults, and data handling. Use when an agent needs Alex Cinovoj / TechTide live-coding patterns, tool routing, guarded prototype-to-production workflows, or cross-harness prompt/skill adapters.

SKILL.md

2.8 KB, 456 tokens by cl100k_base, as published. Nobody here has run it

TechTide Code Security Hardener

Harden untrusted code by reviewing authentication, authorization, injection surfaces, dependency risk, secret exposure, unsafe defaults, and data handling.

Source Pattern

This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load references/source-patterns.md when you need the source anchors and extraction rationale. Load references/adapter-map.md when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.

Workflow

  1. Identify changed files, external dependencies, runtime permissions, and data flows.
  2. Review auth boundaries, access checks, input validation, output encoding, CORS, storage, and logging.
  3. Search for secret patterns, broad tokens, hardcoded URLs, admin defaults, and mock bypasses.
  4. Require tests or manual proofs for each security claim.
  5. Return a prioritized fix list with exact files, risk, and verification method.

Output Contract

Return a concise brief with these fields:

  • security findings
  • fix list
  • verification checklist
  • residual risk
  • verification performed or still required
  • security and privacy notes

Guardrails

  • Extract reusable methods, not private local content.
  • Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.
  • Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.
  • Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.
  • Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.

Harness Policy

  • Use this as a native SKILL.md for Claude Code, Codex, Gemini, and Copilot-compatible exports.
  • For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.
  • For Kiro, create steering only when the workflow can be made short and inclusion-scoped.
  • For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.