Harden Deps
Description
--- description: Deployment hardening step 3 — run ecosystem-native vulnerability audit (full tree AND production-only, so shipped CVEs are separated from dev-only ones), flag unpinned versions, abandoned packages, dev-deps leaking into runtime. Read-only; --fix runs `npm audit fix` (non-breaking only) and offers to pin floating versions one-by-one. Fire on `/harden-deps`. argument-hint: "[--fix] [--no-install] [scope path]" allowed-tools: Bash(npm:*), Bash(pnpm:*), Bash(yarn:*), Bash(pip:*), Ba
Installation
Installs to ~/.claude/skills/jchigg2000-git-claude-code-dev-harden-deps/SKILL.md
mkdir -p ~/.claude/skills/jchigg2000-git-claude-code-dev-harden-deps && curl -fsSL https://raw.githubusercontent.com/jchigg2000-git/claude-code-dev/HEAD/commands/harden-deps.md -o ~/.claude/skills/jchigg2000-git-claude-code-dev-harden-deps/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
Full documentation available on GitHub
View Source RepositoryRelated Skills
Fastapi Review
Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu
Security Defense in Depth
Implement multi-layered testing and security best practices.
Security SecLists Official Repository
[OWASP Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
Security Threat Hunting with Sigma Rules
Use Sigma detection rules to hunt for threats and analyze security events
Security Maintenance Walkthrough - 2026-03-29
- Re-triaged the full 2026-03-15 security finding set against current `main` and wrote a fresh current-head re
Security Google Workspace Model Armor
Filter user-generated content for safety
Security Related Agents
Django Reviewer
Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi
Token Auditor
Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d
Gitnexus Security Boundary Reviewer
GitNexus security and trust-boundary reviewer. Use for auth, permissions, secrets, injection, unsafe parsing,