Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables
日本語の概要は準備中です。原文の説明を表示しています。
344 件 ・ 関連度順
概要と使いどころ
Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables
日本語の概要は準備中です。原文の説明を表示しています。
Comprehensive backend development guide for Langfuse's Next.js 14/tRPC/Express/TypeScript monorepo. Use when creating tRPC routers, public API endpoints, BullMQ queue processors, services, or working with tRPC procedures, Next.js API routes, Prisma database access, ClickHouse analytics queries, Redis queues, OpenTelemetry instrumentation, Zod v4 validation, env.mjs configuration, tenant isolation patterns, or async patterns. Covers layered architecture (tRPC procedures → services, queue processors → services), dual database system (PostgreSQL + ClickHouse), projectId filtering for multi-tenant isolation, traceException error handling, observability patterns, and testing strategies (Jest for web, vitest for worker).
日本語の概要は準備中です。原文の説明を表示しています。
Think and work like an expert Landscape Ecologist. Use when a task calls for Landscape Ecologist judgment. Reasons from scale-explicit pattern-process feedbacks, configuration over composition, and functional rather than graphical connectivity through FRAGSTATS, landscapemetrics, Circuitscape resistance surfaces, NLMR neutral models, and block cross-validation, while treating MAUP grain artifacts, classification error propagation, isolation-by-distance confounding isolation-by-resistance, and resistance surfaces unvalidated by movement as first-class failure modes.
日本語の概要は準備中です。原文の説明を表示しています。
Run AI agent code safely in isolated sandboxes with resource limits, audit trails, and kill switches. Use when someone asks to "sandbox my agent", "run agent code safely", "add guardrails to AI agent", "isolate agent execution", "audit agent actions", "prevent agent from deleting files", "restrict agent permissions", or "add safety controls to AI coding agent". Covers Docker isolation, filesystem restrictions, network policies, resource locking, and comprehensive audit logging.
日本語の概要は準備中です。原文の説明を表示しています。
OPTIONAL per-task isolation for autonomous parallel work. Routed to only on explicit opt-in by subagent-driven-development or dispatching-parallel-agents, so parallel units mutate files without colliding. Stands up one worktree per unit, works it in isolation, then integrates each unit back onto the caller's working branch for the caller's single commit-gate + finishing-a-development-branch exit. Never on the default path; it does not bypass a gate or finish per unit.
日本語の概要は準備中です。原文の説明を表示しています。
Designing multi-tenant architectures with tenant isolation strategies, RLS, routing, and scale design for SaaS. Use when designing multi-tenant SaaS systems or tenant isolation.
日本語の概要は準備中です。原文の説明を表示しています。
教師なし分析と EDA 前処理(欠測 / 欠損 / NaN / 補完 / imputation / 外れ値処理、クラスタリング / セグメンテーション / k-means / 階層クラスタリング / GMM / DBSCAN、次元削減 / PCA / 主成分分析 / 因子分析 / UMAP / t-SNE、異常検知 / anomaly detection / 不正検知)を実行したら必ずセットで出す図と値のルーター。fillna, dropna, fill_null, SimpleImputer, IterativeImputer, missingno, KMeans, AgglomerativeClustering, DBSCAN, GaussianMixture, silhouette_score, dendrogram, PCA, FactorAnalysis, calculate_kmo, TSNE, umap.UMAP, IsolationForest, LocalOutlierFactor, pyod がコードに現れたとき、またはユーザーが「欠損を埋めて」「クラスタリングして」「主成分で 要約して」「異常を検知して」「データをきれいにして」と言ったときに使う。安定性・k の根拠・平行分析・ベースラインに 言及がなくても適用する。SKILL.md のルーティング表で手法を特定し、対応する references/<手法>.md を読んでから実行する。 教師あり予測は predictive-modeling-diagnostics、回帰・検定は statistical-inference-diagnostics を使う。
Testing Craft CMS 5 plugins and modules with Pest — test isolation, database safety, and the markhuot/craft-pest-core harness. ALWAYS load when writing, running, fixing, or reviewing tests for a Craft plugin or module, and whenever a suite touches a real Craft install. Covers why rollback is opt-in, tests/Pest.php + tests/bootstrap.php wiring, phpunit.xml.dist <env> pins (force DB name + table prefix, default connection coordinates, pin CRAFT_ENVIRONMENT against server-scoped locks), why --configuration= defeats DB isolation, throwing fail-closed DB guards, installing the plugin under test, process-timezone pinning, per-test site fixtures, idempotent Install migrations, stale service caches when components get swapped, muting audit sinks, queue stubs, factories, HTTP/DB assertions, CI jobs.
日本語の概要は準備中です。原文の説明を表示しています。
Agent Context Isolation
日本語の概要は準備中です。原文の説明を表示しています。
Implement AI-powered anomaly detection for operational metrics using time series analysis (Isolation Forest, Prophet, LSTM), alert correlation, and root cause analysis. Reduce alert fatigue by intelligently identifying true anomalies in system metrics, logs, and traces. Use when operations teams are overwhelmed by alert volume, when detecting complex multi-metric anomalies beyond static thresholds, when seasonal patterns make thresholds ineffective, or when needing to predict issues proactively before they impact users.
日本語の概要は準備中です。原文の説明を表示しています。
Agent Context Isolation
日本語の概要は準備中です。原文の説明を表示しています。
Plans and configures multi-tenancy on GKE. Covers namespace isolation, RBAC planning for teams, resource quotas, LimitRanges, network isolation, and cost allocation. Use when designing GKE multi-tenancy, configuring GKE namespaces, setting up resource quotas, or isolating GKE teams. Don't use for single-tenant cluster configuration or general deployment instructions (use gke-basics or gke-app-onboarding instead).
日本語の概要は準備中です。原文の説明を表示しています。
Checks isolation (APIs/DB/FS/Time/Random/Network), determinism (flaky, order-dependent), and 7 anti-patterns.
日本語の概要は準備中です。原文の説明を表示しています。
Drive Chromium from standard Playwright APIs with a real-device fingerprint applied in the kernel, one persistent isolated profile per identity, and a per-profile proxy whose exit IP sets timezone and WebRTC - JavaScript (npm 'anti-detect-browser') or Python (PyPI 'antibrow'). Use when sessions must stay logged in across runs and stay separate, when a scraper or agent is blocked by an incoherent headless fingerprint, when checking ads or pricing from another region, when a page must be reached as a phone rather than a desktop, when automation mints a profile per task, when running several of your own accounts from one machine, or when testing how your own bot detection scores a real device. Also for 'antibrow', 'fingerprint browser', 'multi-account browser', '防关联', '多账号', '安卓模拟', 'Android profile', 'mobile fingerprint', 'temporary profile', 'CreepJS', 'residential proxy', 'browser-use', 'crawl4ai'. MCP control is browser-mcp-agent; isolation is multi-account-isolation.
日本語の概要は準備中です。原文の説明を表示しています。
Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so the session stays logged in between runs and pages see one coherent device instead of a headless build. No Playwright or SDK code to write. Use when an agent should operate a site itself, when a computer-use / browser-use setup needs a captured real fingerprint rather than a synthetic one, when agent sessions keep losing their login, or when comparing hosted agent-browser services. Also for 'MCP browser', 'browser MCP server', 'let my agent browse the web', 'agent browser control', 'browser-use MCP', 'computer use browser', 'Browserbase alternative', 'Steel browser alternative', 'headless browser detected'. Node (npx) or Python; Windows x64, macOS Intel + Apple Silicon, Linux x64 / arm64. SDK and REST reference is anti-detect-browser; account isolation is multi-account-isolation.
日本語の概要は準備中です。原文の説明を表示しています。
Manages git worktrees for parallel agent isolation. Creates isolated worktrees for parallel agents on parallel/{name}-{timestamp} branches, merges results with conflict detection, prunes stale metadata, and reports health status. NOT for user-initiated feature branches — use git worktree directly for that.
日本語の概要は準備中です。原文の説明を表示しています。
Comprehensive backend development guide for Langfuse's Next.js 14/tRPC/Express/TypeScript monorepo. Use when creating tRPC routers, public API endpoints, BullMQ queue processors, services, or working with tRPC procedures, Next.js API routes, Prisma database access, ClickHouse analytics queries, Redis queues, OpenTelemetry instrumentation, Zod v4 validation, env.mjs configuration, tenant isolation patterns, or async patterns. Covers layered architecture (tRPC procedures → services, queue processors → services), dual database system (PostgreSQL + ClickHouse), projectId filtering for multi-tenant isolation, traceException error handling, observability patterns, and testing strategies (Jest for web, vitest for worker).
日本語の概要は準備中です。原文の説明を表示しています。
Runtime enforcement of file system boundaries and tool access restrictions. Blocks unauthorized operations and logs violations. Activate on 'enforce scope', 'access control', 'boundary enforcement', 'tool restrictions', 'runtime security'. NOT for validation (use dag-permission-validator) or isolation management (use dag-isolation-manager).
日本語の概要は準備中です。原文の説明を表示しています。
Validates permission inheritance between parent and child agents. Ensures child permissions are equal to or more restrictive than parent. Activate on 'validate permissions', 'permission check', 'inheritance validation', 'permission matrix', 'security validation'. NOT for runtime enforcement (use dag-scope-enforcer) or isolation management (use dag-isolation-manager).
日本語の概要は準備中です。原文の説明を表示しています。
Expert-level mechanical vibrations covering free and forced vibration, damping, resonance, modal analysis, vibration isolation, and rotating machinery.
日本語の概要は準備中です。原文の説明を表示しています。
Flags where a P&ID draft raises a process safety question and points to the candidate evidence an engineer would review (HAZOP register, relief study, SIL assessment, isolation philosophy), as questions and quoted passages with UNKNOWN for missing documents, plus safety functions, relief devices and isolation requirements carried over as stated. Never rates, sizes, classifies, resolves or declares protection adequate. Use when the user asks to "write the process safety flags", "produce the process safety section of the P&ID enrichment", "list which protection questions this P&ID raises" or "map the HAZOP and relief study evidence to the draft" after gate G2, once the piping and instrumentation sections exist. Do not use for proposing loops, alarms or trips from the control philosophy, use instrumentation-and-control-enrichment instead; do not use for checking identifiers, use tagging-and-numbering. Drafts for human review; never approves, authorises or signs off.
日本語の概要は準備中です。原文の説明を表示しています。
Resolve Swift concurrency compiler errors, adopt approachable concurrency (SE-0466), and write data-race-safe async code. Use when fixing Sendable conformance errors, actor isolation warnings, or strict concurrency diagnostics; when adopting default MainActor isolation, @concurrent, nonisolated(nonsending), or Task.immediate; when designing actor-based architectures, structured concurrency with TaskGroup, or background work offloading; or when migrating from @preconcurrency to full Swift 6 strict concurrency.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to write or improve integration tests for Quarkus — including @QuarkusTest, Dev Services for automatic container provisioning, Testcontainers via QuarkusTestResourceLifecycleManager, WireMock for external HTTP stubs, @QuarkusIntegrationTest for black-box testing against packaged artifacts, REST Assured, data isolation strategies (@TestTransaction vs @BeforeEach cleanup), and Maven Surefire/Failsafe three-tier split (*Test, *IT, *AT). This should trigger for requests such as Add or improve integration tests in a Quarkus project; Configure Testcontainers or Dev Services for Quarkus tests; Add WireMock stubs for external HTTP dependencies in Quarkus integration tests; Set up @QuarkusIntegrationTest for packaged artifact or native binary testing; Fix test data isolation or configure Maven Surefire/Failsafe split. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
mssql (node-mssql, Node.js 向け Microsoft SQL Server クライアント) の API リファレンス。 tedious / msnodesqlv8 ドライバー、SQL Server / T-SQL / TDS 接続、ConnectionPool、 `sql.query` タグ付きテンプレート、bulk insert、Table-Valued Parameter (TVP)、 prepared statement、isolation level、Diagnostics Channel、Azure AD 認証、CLI。 Drizzle ORM 経由の SQL Server 利用 (drizzle-orm/mssql-core) は別スキル drizzle が対象。