TechTide Code Security Hardener
Harden untrusted code by reviewing authentication, authorization, injection surfaces, dependency risk, secret exposure, unsafe defaults, and data handling.
Source Pattern
This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load references/source-patterns.md when you need the source anchors and extraction rationale. Load references/adapter-map.md when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.
Workflow
- Identify changed files, external dependencies, runtime permissions, and data flows.
- Review auth boundaries, access checks, input validation, output encoding, CORS, storage, and logging.
- Search for secret patterns, broad tokens, hardcoded URLs, admin defaults, and mock bypasses.
- Require tests or manual proofs for each security claim.
- Return a prioritized fix list with exact files, risk, and verification method.
Output Contract
Return a concise brief with these fields:
- security findings
- fix list
- verification checklist
- residual risk
- verification performed or still required
- security and privacy notes
Guardrails
- Extract reusable methods, not private local content.
- Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.
- Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.
- Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.
- Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.
Harness Policy
- Use this as a native
SKILL.md for Claude Code, Codex, Gemini, and Copilot-compatible exports.
- For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.
- For Kiro, create steering only when the workflow can be made short and inclusion-scoped.
- For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.
1---2name: techtide-ai-generated-code-security-hardener3description: Harden untrusted code by reviewing authentication, authorization, injection surfaces, dependency risk, secret exposure, unsafe defaults, and data handling. Use when an agent needs Alex Cinovoj / TechTide live-coding patterns, tool routing, guarded prototype-to-production workflows, or cross-harness prompt/skill adapters.4---56# TechTide Code Security Hardener78Harden untrusted code by reviewing authentication, authorization, injection surfaces, dependency risk, secret exposure, unsafe defaults, and data handling.910## Source Pattern1112This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load `references/source-patterns.md` when you need the source anchors and extraction rationale. Load `references/adapter-map.md` when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.1314## Workflow15161. Identify changed files, external dependencies, runtime permissions, and data flows.172. Review auth boundaries, access checks, input validation, output encoding, CORS, storage, and logging.183. Search for secret patterns, broad tokens, hardcoded URLs, admin defaults, and mock bypasses.194. Require tests or manual proofs for each security claim.205. Return a prioritized fix list with exact files, risk, and verification method.2122## Output Contract2324Return a concise brief with these fields:2526- security findings27- fix list28- verification checklist29- residual risk30- verification performed or still required31- security and privacy notes3233## Guardrails3435- Extract reusable methods, not private local content.36- Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.37- Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.38- Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.39- Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.4041## Harness Policy4243- Use this as a native `SKILL.md` for Claude Code, Codex, Gemini, and Copilot-compatible exports.44- For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.45- For Kiro, create steering only when the workflow can be made short and inclusion-scoped.46- For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.