Use this skill whenever configuring a web server, deployment, or hosting setup for any production application, and before any site or API goes live. Also use it when a user asks to "deploy this," "set up hosting," "configure the server," or "harden this before launch," and whenever reviewing production configuration for security gaps. It covers the infrastructure-level defenses that sit outside application code: forcing HTTPS, locking down CORS, setting security headers, disabling directory listing, removing default admin routes, scanning dependencies, and logging security-relevant events so an incident is actually detectable.