security-baseline

Establish a security baseline for websites and web apps.

523|69|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/rampstackco/claude-skills --skill security-baseline-rampstackco
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-baseline
Source: https://github.com/rampstackco/claude-skills/tree/main/skills/security-baseline
Command: npx skills add https://github.com/rampstackco/claude-skills --skill security-baseline-rampstackco

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Establish a security baseline for websites and web apps to reduce risk and ensure consistent protection across environments.

Core Features & Use Cases

  • TLS & HTTPS hardening and certificate lifecycle management across environments.
  • Header governance and CSP policy evaluation to meet compliance and reduce attack surface.
  • Secrets management planning, rotation policies, and regular vulnerability scanning integration.
  • Use Case: Run a baseline before launch to verify HSTS, CSP, and secure credentials practices.

Quick Start

Run a baseline assessment on your site to verify TLS, headers, and CSP configurations against the standard security baseline.

Frequently Asked Questions about security-baseline

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I establish a security baseline for my website before launch?

To establish a security baseline for your website, assess TLS configurations, security headers, and CSP policies against standard compliance checks. The skill generates a documented baseline and remediation plan using your hosting platform, domains, and third-party integrations.

What should be included in a web application security baseline for compliance?

A web application security baseline should include TLS and HTTPS hardening, header governance, CSP policy evaluation, and secrets management planning. This skill produces a documented baseline and remediation plan to ensure consistent protection and meet compliance requirements.

How do I configure Content Security Policy headers and HSTS for compliance?

Configuring Content Security Policy headers and HSTS requires evaluating your header governance and CSP policies against a standard security baseline. This skill takes your hosting platform and third-party integrations as input to produce a compliant configuration plan.

Does this security baseline skill work with specific hosting platforms and third-party integrations?

Yes, this security baseline skill processes inputs such as your specific hosting platform, domains, authentication methods, and third-party integrations. It uses these details to produce a documented baseline and targeted remediation plan for your environment.

What is the best way to manage TLS certificate lifecycle and secrets rotation for web apps?

The best way to manage TLS certificate lifecycle and secrets rotation is to integrate them into a continuous security baseline. This skill plans your secrets management, rotation policies, and regular vulnerability scanning to reduce risk across environments.

Can I use this for ongoing maintenance and vulnerability scanning integration?

Yes, you can use this for ongoing maintenance and vulnerability scanning integration. The skill applies continuous baseline assessments to verify TLS, headers, and CSP configurations, ensuring your web apps maintain consistent protection over time.