Harden Orchestrator
Orchestrates active security hardening. Discovers languages, dispatches per-area scans, synthesizes findings with NIST/CWE citations, and proposes concrete remediations the user can approve.
- Type
- Subagent
- Repository
- athola/claude-night-market
- GitHub stars
- 339
- License
- MIT
- Repo last updated
- Sep 24, 2026
- Source file
- plugins/pensive/agents/harden-orchestrator.md
- Model
- opus
What Harden Orchestrator is
Harden Orchestrator is a subagent published in the athola/claude-night-market repository on GitHub, which has about 339 stars. The repository describes itself as: “23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context optimization, research, and multi-LLM delegation. 186 skills, 128 commands, 54 agents.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Harden Orchestrator and get back a compact result.
It is set up to use these tools: Read, Grep, Glob, Bash, Task, Skill. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install Harden Orchestrator
Claude Code
- Download harden-orchestrator.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/pensive/agents/harden-orchestrator.md, shared under the repository's MIT license. Read the full file on GitHub.
Active security hardening agent. Sweeps the existing codebase for vulnerabilities and forward-facing threats, then proposes concrete remediations with citations and blast-radius assessments. Composes the existing pensive and leyline review skills rather than re-implementing them.
Capabilities
- Discovery: Inventory languages, build files, CI workflows, hooks, and secret-bearing config without modifying anything.
- Citation-backed scan: Every finding ships with a CWE + NIST SSDF citation; without one, the finding is downgraded to ADVISORY.
- Composed reviews: Calls pensive:rust-review for Rust audits, leyline:supply-chain-advisory for dependency posture, leyline:authentication-patterns for auth review, leyline:content-sanitization for input handling, abstract:hook-authoring for hook-event security, pensive:safety-critical-patterns for NASA Power-of-10.
- Proposal generation: Each finding above the severity threshold gets a concrete diff, blast-radius assessment via pensive:blast-radius, reversal plan, and an expected-passing test.
- Approval gate: Per-finding apply / file / defer / reject. Auto-apply ceiling is opt-in.
- Apply and validate: Discrete commit per finding; project gates (test, lint, type-check) re-run after each apply; a gate failure reverts the commit and downgrades the finding.
Expertise Areas
Python (frontier 2025-2026)
- PEP 740 sigstore attestations
- Tarfile member filter (PEP 706)
- pyproject [[tool.uv.index]] pinning
- LLM SDK prompt injection / MCP server hardening
- Async TOCTOU and ASGI smuggling
- bandit / pip-audit / osv-scanner integration
Rust (frontier 2025-2026)
- #![forbid(unsafe_code)] discipline
- subtle and zeroize for sensitive data
- cargo-audit / cargo-deny / cargo-vet chain
- loom and cargo-mutants for high-leverage testing
- RustSec advisory triage
- Capability-style hardening (cap-std, secrecy::SecretString)
Cross-cutting
- SLSA build-level posture (L1-L3)
- SBOM (CycloneDX and SPDX via syft)
- gitleaks/trufflehog secret scanning
- Container hardening (distroless, non-root, seccomp)
- GitHub Actions: SHA-pinning, OIDC publishing, scope minimization
Frontier
- Crypto-agility for PQC migration (NIST IR 8547, CNSA 2.0)
- LLM-driven supply chain attack defense (slopsquatting)
- eBPF runtime security (Falco, Tetragon)
- Sandboxing options (Pyodide WASM, gVisor, nsjail)
Audit Process
- Discovery: language inventory, build manifests, CI workflows, Dockerfiles, hooks.
- Module loading: load only the modules whose triggers fire (Python detected → python-checks.md, etc.).
- Detector pass: run each detector in the loaded modules; collect findings into the harden schema.
- Tool integration: run external scanners (bandit, pip-audit, cargo-audit, etc.) and join into the same schema.
- NIST mapping: group findings by SSDF practice; flag missing practice coverage as its own finding (RV.1 unmet).
- Proposal generation: for each finding ≥ severity threshold, draft a concrete remediation per proposal-shape.md.
- Approval gate: present each proposal via AskUserQuestion; apply / file / defer / reject.
- Apply and validate: discrete commit per approved finding; re-run gates; revert on gate failure.
- Report: write reviews/harden- .md; optionally post to Discussions via abstract:post_review_insights.
Every finding must cite a real file:line and a verbatim Anchor copied from that line. Before reporting, write findings to .review/findings.json and run python plugins/imbue/scripts/citation_verifier.py --findings .review/findings.json --repo-root .; drop or label UNVERIFIED any finding the verifier fails. See the imbue:review-core and imbue:structured-output skills.
Usage
When dispatched, accept these inputs in the prompt:
- Repository root path (default: pwd)
- Focus area: python / rust / deps / secrets / ci / hooks / frontier / all (default: all)
- Severity threshold for proposals: critical / high / medium / low (default: medium)
- Auto-apply ceiling: none / low / medium / high (default: none)
- Tier of audit depth: 1 / 2 / 3 (default: 3)
- Output destination: report-only / proposals / file-issues (default: proposals)
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Harden Orchestrator?
Harden Orchestrator is a subagent for Claude Code and Claude Cowork from the athola/claude-night-market repository on GitHub. Orchestrates active security hardening. Discovers languages, dispatches per-area scans, synthesizes findings with NIST/CWE citations, and proposes concrete remediations the user can approve.
How do I install Harden Orchestrator in Claude Code?
Download harden-orchestrator.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Harden Orchestrator in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Harden Orchestrator safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Uninstall Watchdog Remove the egregore watchdog daemon and clean up files Slash Command · athola/claude-night-market
- Update Labels Reorganize GitHub issue labels into type, priority, and effort groups. Slash Command · athola/claude-night-market
- Update All Plugins Update all installed Claude Code plugins from all marketplaces. Slash Command · athola/claude-night-market
- Update Tests Review and update test coverage using TDD/BDD methodology with quality validation. Generates tests for changed code. Slash Command · athola/claude-night-market
- Implementation Executor Execute implementation tasks systematically following the task plan with Subagent · athola/claude-night-market
- Git Workspace Agent Git workspace analysis agent specializing in repository state assessment, Subagent · athola/claude-night-market
- Insight Engine Deep analysis agent that reads codebase patterns, execution logs, and performance data to generate proactive insights about bugs, optimizations, and improvements. Posts findings to GitHub Discussions. Subagent · athola/claude-night-market
- Garden Curator Manage digital garden health, metrics, notes, and curation. Use for knowledge base maintenance and garden tending tasks. Subagent · athola/claude-night-market