# Environment and headers hardening (/security--env-hardening)

/security--env-hardening is a Claude Code skill in the Code section. Reviews .env files, server settings and HTTP security headers, then generates a hardened configuration with a before and after comparison.

- Web version: https://skills.sgomez.dev/en/s/security--env-hardening
- Section: [Code](https://skills.sgomez.dev/en/code.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/security/env-hardening.md
- Updated 26 Mar 2026

## How to ask for it

- `/security--env-hardening review my production server configuration`
- `/security--env-hardening is my API missing security headers?`
- `/security--env-hardening harden environment variables before we ship`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install security-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`, `.env*`, `.gitignore`
- Writes: `**/*`
- Runs: —
- Network: No
- Destructive: No

## Author's description

Review and harden environment configuration and HTTP security headers

## Pairs well with

- [Leaked secrets scan (/security--secrets-scan)](https://skills.sgomez.dev/en/s/security--secrets-scan.md): Scans your code, config files and recent git history for API keys, tokens, passwords and private keys, and explains how to remediate each.
- [Dependency vulnerability check (/security--dependency-vuln)](https://skills.sgomez.dev/en/s/security--dependency-vuln.md): Runs your package manager's audit and lists each vulnerable dependency with its CVE, severity, fixed version and a remediation plan.
- [OWASP security audit (/security--security-audit)](https://skills.sgomez.dev/en/s/security--security-audit.md): Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.
- [Login and permissions review (/security--auth-review)](https://skills.sgomez.dev/en/s/security--auth-review.md): Reviews your app's login, sessions, tokens and access rules and returns severity-rated findings, each with a specific fix.
- [Input sanitization review (/security--sanitize)](https://skills.sgomez.dev/en/s/security--sanitize.md): Traces where user input enters your code and where it ends up, flags SQL injection, XSS and similar flaws, and proposes the fix.
- [CORS configuration review (/security--cors-review)](https://skills.sgomez.dev/en/s/security--cors-review.md): Reviews your CORS setup in Express, FastAPI, Django or Nginx, tightens overly permissive origins and headers, and verifies them with curl.
- Recipe: [/pipeline--security-hardening](https://github.com/sgomez-dev/claude-skills/blob/main/pipelines/security-hardening.yaml): Security Hardening

- [How we review this](https://skills.sgomez.dev/en/methodology.md)
