本文へ移動
cccskills

テスト・セキュリティのスキル

テスト設計、脆弱性診断、品質保証(1.2万 件)

価格や並び順で絞り込む

概要と使いどころ

Runtime enforcement of file system boundaries and tool access restrictions. Blocks unauthorized operations and logs violations. Activate on 'enforce scope', 'access control', 'boundary enforcement', 'tool restrictions', 'runtime security'. NOT for validation (use dag-permission-validator) or isolation management (use dag-isolation-manager).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Validates versioned permission requests against a grant scope and records comparison evidence. Activate on 'validate permissions', 'permission check', 'inheritance validation', 'permission matrix', 'security validation'. NOT for runtime enforcement (use dag-scope-enforcer) or isolation management (use dag-isolation-manager).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Threat-models protocols where authority, scarce resources, bonds, bounties, escrow, reputation, ordering, adjudication, or settlement create strategic incentives. Use to test attack utility, conservation, collusion, Sybil resistance, oracle capture, griefing, custody, liquidity, and residual risk. NOT for choosing payment or bond amounts without evidence, smart-contract code audit, legal or employment classification, DeFi trading, admitting workers, or settling claims.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Interprets GitHub Actions run status and logs, diagnoses CI failure patterns, and suggests targeted fixes. Handles dependency install failures, test timeouts, build OOM, flaky tests, and workflow misconfigurations. Activate on: 'CI failing', 'build broken', 'workflow error', 'GitHub Actions debug', 'flaky CI', 'pipeline timeout', 'CI red'. NOT for: writing new workflows from scratch (use github-actions-pipeline-builder), CI caching strategy (use ci-cache-optimizer), deployment orchestration (use devops-automator).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Diagnose when intuitive judgment, agent confidence, or expert routing can be trusted by classifying environment validity, feedback quality, and task-boundary fit. Use for confidence calibration, agent routing, expertise audits, and escalation design. NOT for deterministic implementation tasks, pure syntax debugging, or domains with explicit verifiable answers.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Diagnose when intuitive judgment, agent confidence, or expert routing can be trusted by classifying environment validity, feedback quality, and task-boundary fit. Use for confidence calibration, agent routing, expertise audits, and escalation design. NOT for deterministic implementation tasks, pure syntax debugging, or domains with explicit verifiable answers.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Designs and audits native-unit capacity reservation, serial admission, ambiguity holds, stop reserves, effect closure, and control-disjoint settlement handoff for consequential agent attempts. Use when scarce capacity must be conserved across retry, rework, resurrection, or compensation. NOT for scheduling work, choosing models, pricing unlike resources into one scalar, authorizing effects, grading work, paying workers, or asserting runtime containment.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Use when designing or fixing a Content Security Policy on a real site, choosing between nonce-based and hash-based CSP, adding strict-dynamic, debugging "Refused to execute inline script" errors, deploying CSP in report-only mode first, configuring report-to / report-uri, or auditing an existing policy for unsafe-inline / unsafe-eval / wildcards. Triggers: "CSP blocks legitimate inline script", strict-dynamic, nonce-{RANDOM}, sha256-{HASH}, object-src none, base-uri none, frame-ancestors, Trusted Types, X-Content-Security-Policy obsolete, report-only vs enforced. NOT for general HTTP security headers (HSTS, COOP/COEP), Trusted Types deep dive, CORS configuration, or building a WAF.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Treat tokens as a coding swarm's cost-of-goods-sold and legibility engine while accounting for finite subscription allowance when per-call price is unknown. Covers provider windows, remaining-usage evidence, burn forecasts, preemptive checkpoint/model switching, per-agent budgets, compaction, shared digests, context degradation, and spend metering. Activate on: "token budget", "context budget", "compaction strategy", "briefing as compression", "context rot", "summarization collapse", "COGS for agents", "subscription usage remaining", "five-hour or weekly limit", "burn forecast", "model switch before limit", or "/context-economics-for-agent-swarms". NOT for: memory architecture (use always-on-agent-architecture), single-prompt wording (use prompt-engineer), mechanism-design proofs (use nisan-et-al-2007-algorithmic-game-theory), physical containment (use sandboxed-adversarial-test-harness), or production rebodiment and fencing (use agent-resurrection-and-body-continuity).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Audit LLM token cost estimates against actual API usage. Activate on 'cost verification', 'token estimate accuracy', 'API cost audit', 'estimation variance'. NOT for pricing lookups, budget planning, or cost optimization strategies.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Build production computer vision pipelines for object detection, tracking, and video analysis. Handles drone footage, wildlife monitoring, and real-time detection. Supports YOLO, Detectron2, TensorFlow, PyTorch. Use for archaeological surveys, conservation, security. Activate on "object detection", "video analysis", "YOLO", "tracking", "drone footage". NOT for simple image filters, photo editing, or face recognition APIs.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Build, debug, optimize, and deploy ComfyUI workflows for diffusion image, video, and audio generation. Activate on: ComfyUI workflow, ComfyUI custom node, ComfyUI API, ComfyUI Manager, KSampler, FLUX in ComfyUI, Wan 2.2 ComfyUI, Hunyuan video ComfyUI, LTX video ComfyUI, IPAdapter, ControlNet ComfyUI, Kijai wrapper, ComfyDeploy, RunComfy, ComfyUI security, GGUF quantization, TeaCache, Nunchaku, ACE-Step ComfyUI, F5-TTS ComfyUI, subgraphs ComfyUI. NOT for: A1111/Forge/Invoke (different UIs), training pipelines from scratch, non-diffusion ML models, or general image-API integrations (use generative-video-2026 / generative-music-audio / media-gen-deployment).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Detects and fixes color contrast violations using WCAG 2.1 guidelines and perceptual analysis. Expert in contrast ratio calculation, color blindness simulation, and providing accessible alternatives. Activate on "check contrast", "color accessibility", "WCAG audit", "readability check", "contrast ratio", "hard to read", "can't see text". NOT for general color theory (use color-theory-palette-harmony-expert), brand color selection (use web-design-expert), or non-visual accessibility (use ux-friction-analyzer).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Plan or audit the cross-layer Harbor cooperative editor: Loro replicas for humans and agents, governed edit claims, salvage authority, and transport across shared, LAN, and remote harbors. Use when a change spans editor collaboration, identity, recovery, or transport contracts. For a single GPUI pane use gpui-rust-console; for motion use rust-gpui-motion; for a shader use gpui-shaders. NOT for non-collaborative screens, web editors, or generic Rust development.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

App Store and Google Play submission automator with Fastlane, screenshot automation, metadata management, and TestFlight/internal testing. Activate on: app store submission, Fastlane, TestFlight, Google Play Console, screenshot automation, metadata management, app review, code signing, provisioning profiles. NOT for: CI/CD pipeline setup (use github-actions-pipeline-builder), app architecture (use react-native-architect), analytics (use mobile-analytics-crash-reporting-expert).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Own whether a multi-document product-architecture binder is internally consistent, complete against its stated customer/contingency/architecture coverage, and honest about which older product ambitions it has absorbed, superseded, deferred, contradicted, orphaned, or rejected. Use when running a binder Architect of Record pass, before an implementation chain cites a binder chapter as ready, when a proof-gate owner is missing, or when reconciling the binder against the older ambition corpus (website, plans, examples, ADRs). NOT for auditing a single Claude Skill bundle's structure or frontmatter (use skill-hygiene), rendering a single-PM accept/reject verdict on one finished deliverable (use port-daddy-user-surrogate-pm-review), or sequencing/stewarding a roadmap's sidequests once a gap or operator decision has been surfaced (use legible-roadmap-with-sidequests).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Audits an Articles of Agreement contract — the daemon-witnessed agreement every official Port Daddy agent signs covering registration, transcript reporting, tool-use gating, file claims, parley conduct, budget limits, and operator control — against the enforcement-beats-hope bar: a clause counts as safe only when it resolves to a concrete, daemon-observable mechanism with a defined denial shape, never a promise the agent might honor. Use when drafting a new agent's Articles, reviewing a compliance-level (C0-C6) claim, deciding whether a clause is genuinely enforced or merely documented, or auditing whether an agent's claimed identity can be trusted. NOT for securing the inbound event-to-spawn path (fleet-event-spawn-trust), designing the relay's transport PKI and signing keys (pd-relay-zero-trust), or tracking an agent's identity and reputation across its whole lifetime after it signs (agent-identity-continuity-reputation).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Declare an agentic application's interaction disclosure, state, context, capabilities, and effect-control boundaries. Use for a reviewable design specification and static consistency audit before implementation. NOT for proving that controls are deployed or enforced, exposing private chain-of-thought, selecting a model/router, or designing a multi-agent protocol.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Safety-case design for always-on agents with episodic memory. Covers data hygiene, privacy and security risk surfaces, cost controls, scope, user dependency concerns, retention, incident containment, and responsible deployment evidence. It identifies hazards and asks for named controls, tests, owners, and residual uncertainty; it does not provide legal, clinical, youth-safety, or jurisdictional determinations. Activate on: "agent safety", "always-on agent privacy", "agent cost control", "persistent agent risks", "AI companion safety", "agent data hygiene", "runaway agent costs", "parasocial AI risk", "/always-on-agent-safety". NOT for: architecture design (use always-on-agent-architecture), input design (use always-on-agent-inputs), application brainstorming (use always-on-agent-applications), healthcare compliance specifically (use hipaa-compliance).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Author a pull request an AI coding agent can actually get merged: a scoped, coherent diff; a Summary and Test Plan backed by real evidence; correct triage of required-and-blocking CI gates versus external/advisory checks (e.g. a Cloudflare Pages preview build); draft-while-WIP discipline; named fixup commits for real review findings; and a clean landing through a merge queue without force-pushing or bypassing branch protection. Use when opening, updating, triaging red CI on, or landing an agent-authored GitHub PR. NOT for this repo's internal release ceremony, actor embodiments, or contributor mirror-sync mechanics (use port-daddy-internal-dev), tracking backlog/issue lifecycle across a board (use agent-issue-tracker-workflow), or deciding what to build next / sequencing a roadmap (use legible-roadmap-with-sidequests).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Design and audit a pricing function for variable-cost agent labor. Choose among per-seat, metered, credits, hybrid, and outcome pricing; name buyer value and cost metrics separately; calculate a reproducible cost floor; require pre-commitment guardrails; and stress-test declared personas. Use for offline pricing-design evidence, not billing implementation or runtime control. NOT for production billing, payment collection, or runtime spend enforcement.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Designs and audits closed, ordered, replay-safe message protocols between already admitted agent bodies. Use when a multi-agent exchange needs explicit epochs, audiences, per-sender sequencing, gathers, terminal fences, acknowledgements, and deterministic replay. NOT for selecting or spawning agents, granting identity or authority, choosing a runtime topology, general human facilitation, wire transport implementation, or deciding whether evidence is true.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Verify every visual-evidence artifact (screenshot/GIF/recording) attached to a PR carries a provenance manifest binding it to real daemon-backed truth — daemon port, run id, transcript head hash, agent node id, commit, and an honest real/fixture/mock source label — and that operator-control-panel PRs cover the required set of proof states. Use when gating a PR's proof artifacts before merge, auditing whether a "LIVE" visual claim is backed by a real daemon run versus a reused or fixture-backed mock, or defining the required state-coverage set for a control-panel change. NOT for the capture technique itself — headless Playwright, `screencapture -x -l`, non-interruptive capture (use port-daddy-agent-skill's visual-evidence doctrine), designing the receipt body schema an artifact attaches to (use agent-work-receipt-designer), or the broader dogfood/Potemkin product-quality bar (use multi-agent-authoring-product-bar).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Designs and audits deterministic, authority-filtered partitions of trust-typed context for already admitted bodies or abstract continuation slots. Use when causal context, obligations, disclosure boundaries, vector-space identity, capacity, and omission proofs must survive partitioning. NOT for spawning or admitting agents, choosing worker count, retrieving arbitrary knowledge, writing successor prompts, or granting tools, leases, identity, or effect authority.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新