Skip to content
Back to skills

Harden Repo

ASecurity

Apply SECURITY.md, Dependabot, secrets-scan workflow, CODEOWNERS and .gitignore baseline; list GitHub settings to enable.

  • 8 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 19, 2026
ai-agentsgitsecurity

Security analysis

A100/100

Scanned September 19, 2026

npx -y skills add Adilmunawar/ZD-claude-plugin --skill harden-repo --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Harden Repo?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Harden Repo
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/adilmunawar-harden-repo/badge)](https://www.skillsdirectory.com/skills/adilmunawar-harden-repo)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: harden-repo
disable-model-invocation: true
description: Apply SECURITY.md, Dependabot, secrets-scan workflow, CODEOWNERS and .gitignore baseline; list GitHub settings to enable.
---

1. Copy from `${CLAUDE_PLUGIN_ROOT}/templates/` into the repo (show diff, ask before overwrite): `SECURITY.md`, `.github/dependabot.yml`, `.github/workflows/secrets-scan.yml`, `.github/CODEOWNERS` (fill owners), `.gitignore` additions.
2. Print the GitHub settings to enable (cannot be set from code): branch protection on `main` (require PR, 1 review, status checks `validate` + `secrets-scan`, no force push), secret scanning + push protection, Dependabot alerts, signed commits optional.
3. Run `/zd-core:secrets-audit --history`; if findings, stop and start rotation before anything else.
4. Report what was added and the remaining manual steps.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…