Skip to content
Back to skills

Hardening Flags

ASecurity

Blocks added settings that weaken compiler, linker, Rust or kernel hardening, in CMake, Make, meson, configure.ac, Cargo, build.rs, Go release scripts, Dockerfiles and kernel config: no stack protector, FORTIFY_SOURCE off, non-PIE, execstack, norelro, CET off, kernel KASLR/RWX off. Asks on Rust release overflow-checks off, /dev/mem. Not MSVC, sysctl or container settings; misses environment flags, generated files. Runs: commit, agent write, turn's end, CI. Waiver: 'pragma: allowlist hardening...

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentsrustgoshelldockergit

Works with

  • cli

Security analysis

A100/100

Scanned October 3, 2026

npx -y skills add open-coder-ai/chock-catalog --skill hardening-flags --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hardening Flags?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Hardening Flags
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/open-coder-ai-hardening-flags/badge)](https://www.skillsdirectory.com/skills/open-coder-ai-hardening-flags)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: hardening-flags
description: "Blocks added settings that weaken compiler, linker, Rust or kernel hardening, in CMake, Make, meson, configure.ac, Cargo, build.rs, Go release scripts, Dockerfiles and kernel config: no stack protector, FORTIFY_SOURCE off, non-PIE, execstack, norelro, CET off, kernel KASLR/RWX off. Asks on Rust release overflow-checks off, /dev/mem. Not MSVC, sysctl or container settings; misses environment flags, generated files. Runs: commit, agent write, turn's end, CI. Waiver: 'pragma: allowlist hardening-flag'."
metadata:
  chock.artifact: hook
  chock.enforcement: block
  chock.coverage_without_chock: advisory
---

# Hardening Flags

Blocks added settings that weaken compiler, linker, Rust or kernel hardening, in CMake, Make, meson, configure.ac, Cargo, build.rs, Go release scripts, Dockerfiles and kernel config: no stack protector, FORTIFY_SOURCE off, non-PIE, execstack, norelro, CET off, kernel KASLR/RWX off. Asks on Rust release overflow-checks off, /dev/mem. Not MSVC, sysctl or container settings; misses environment flags, generated files. Runs: commit, agent write, turn's end, CI. Waiver: 'pragma: allowlist hardening-flag'.

```
on(commit|tool_use): block(script) script=hardening-flags-gate.py
A build or kernel setting that weakens a hardening default was added (stack protector, FORTIFY_SOURCE, PIE, RELRO, non-executable stack, CET, kernel KASLR or RWX). Keep the default or enable the protection. A person may waive a reviewed setting with 'pragma: allowlist hardening-flag' in a comment on the same line and commit from their own shell; in the agent a waiver counts only for a line already committed in HEAD, so an agent asks the person rather than writing the pragma itself.
```

This skill is advisory: the client reading it has no mechanism to enforce it. The same policy compiled by `chock` blocks at commit, on an agent's file writes and at turn end. See https://github.com/open-coder-ai/chock

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…