本文へ移動
cccskills

「attestation」の検索結果

37 件 ・ 関連度順

概要と使いどころ

Expert knowledge for Azure Attestation development including troubleshooting, best practices, security, configuration, and deployment. Use when validating attestation tokens, authoring policies, enforcing SGX/TPM baselines, or configuring private endpoints, and other Azure Attestation related development tasks. Not for Azure Confidential Computing (use azure-confidential-computing), Azure Virtual Enclaves (use azure-virtual-enclaves), Azure Dedicated HSM (use azure-dedicated-hsm), Azure Key Vault (use azure-key-vault).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Add SLSA build-provenance attestations to existing GitHub Actions workflows. Use when the user wants to add artifact attestations, build provenance, or SLSA attestations to Docker container image builds in GitHub Actions CI/CD pipelines.

日本語の概要は準備中です。原文の説明を表示しています。

jim60105/copilot-prompt212026年10月9日 更新

Implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records. Activate...

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

swift-csp

無料

Expert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2026). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 32 controls (26 mandatory, 6 advisory in v2026) across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Control 2.4 (Back-Office Data Flow Security) is now mandatory in v2026. v2026 attestation window is July 1– December 31, 2026. Trigger for any SWIFT CSP or CSCF compliance question.

日本語の概要は準備中です。原文の説明を表示しています。

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9502026年10月10日 更新

swift-csp

無料

Expert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2026). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 32 controls (25 mandatory, 7 advisory in v2026) across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Control 2.4 (Back-Office Data Flow Security) is now mandatory in v2026. v2026 attestation window is July 1– December 31, 2026. Trigger for any SWIFT CSP or CSCF compliance question.

日本語の概要は準備中です。原文の説明を表示しています。

lawve-ai/awesome-legal-skills8512026年10月3日 更新

Expert knowledge for Azure Enclave development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and deployment. Use when building DMZ/AVD/AKS enclave apps, configuring RBAC/CMK, deploying via Bicep/ARM, or setting up ExpressRoute/VPN, and other Azure Enclave related development tasks. Not for Azure Confidential Computing (use azure-confidential-computing), Azure Attestation (use azure-attestation), Azure Dedicated HSM (use azure-dedicated-hsm), Azure Cloud Hsm (use azure-cloud-hsm).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Expert knowledge for Azure Cloud Hsm development including troubleshooting, best practices, limits & quotas, security, and integrations & coding patterns. Use when configuring Cloud HSM auth/networking, PKCS#11 apps, X.509 cert storage, capacity limits, or cluster issues, and other Azure Cloud Hsm related development tasks. Not for Azure Dedicated HSM (use azure-dedicated-hsm), Azure Payment Hsm (use azure-payment-hsm), Azure Key Vault (use azure-key-vault), Azure Attestation (use azure-attestation).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

flare-fdc

無料

Provides domain knowledge and guidance for the Flare Data Connector (FDC)—attestation types, request flow, Merkle proofs, verifier/DA Layer, and smart contract integration. Use when working with FDC, cross-chain attestations, EVMTransaction, Web2Json, Payment, AddressValidity, proof-of-reserves, weather insurance, or Flare Developer Hub FDC guides and starter repos.

日本語の概要は準備中です。原文の説明を表示しています。

FDU-INS/Insurance-Skills762026年7月12日 更新

Consult this skill BEFORE proposing a fix to any CLI gap or schema gap that touches evidence, trust magnitude, evidence types, evidence grades, the TM formula, or star-level promotion gates. Also read it whenever an issue mentions citations, stars, commits, contributors, views, reviewers, percentile, arxiv, github-stars-own, repo-own, social-signal, benchmark-result, peer-review, self-attestation, fusion-recipe, verifier-attestation, or proxy-containment — those are the 10 canonical evidence types and the raw inputs that feed their formulas. Also read it when asked whether a skill qualifies for a given star level (0★–6★): the Star Bar and promotion gates live in `META.md`, not in the TM methodology page. Reading both prevents proposing a calibration that satisfies the TM grade threshold but violates a Star Bar installability or link requirement.

日本語の概要は準備中です。原文の説明を表示しています。

gaia-research/gaia-skill-tree232026年10月10日 更新

web-server-security-reviewer

無料日本語概要

Web サーバ(nginx/apache、Linux 中心)の Phase 1 設定セキュリティレビュー。 target_profile.yaml で対象を確定し、MANIFEST.txt + manifest_attestation.txt で証跡 integrity を検証。 SSH 直接または証跡受領モードで 9 観点 (OS/リソース/ログ/ネットワーク/サービス/認証/監視/バックアップ/証明書) を read-only 走査。6 階層ガード (allowed/conditional/conditional_sensitive/ask-first/exceptional_sensitive_read/forbidden)、 3 軸補助 (Exploitability/Blast Radius/Service Criticality) の重大度判定、 observation_status による未確認の独立管理、evidence_dir/raw_evidence_store 分離、自己レビュー必須。 Windows/IIS は v1 hard fail。 Use when: Web サーバの設定セキュリティレビュー、Phase 1 監査、nginx/apache 構成監査、 EOL ランタイム調査、ログローテーション不備調査、ドキュメントルート漏えい調査。

takusaotome/claude-skills-library92026年10月5日 更新

Generate OpenVEX / CycloneDX VEX attestations from `.vulnetix/memory.yaml` triage decisions, optionally sign with cosign, optionally upload to Vulnetix and post to a GitHub PR. Use when documenting triage decisions for supply-chain consumers, attaching VEX to a CycloneDX SBOM, or satisfying customer attestation requests.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Produces a narrow-interval quality signal for a WinDAGs skill that a third party can verify without inspecting model weights or method internals. The mechanism is attribution-kNN over a tamper-evident outcome log (task→skills→accept/reject store), combined with a conformal-prediction calibration certificate that provides a formal coverage guarantee. Thompson/Beta sampling is explicitly rejected as a category error: it produces a selection signal for stationary i.i.d. rewards, not an attestation signal for context-dependent LLM output quality. The resulting bundle — outcome-log Merkle root + conformal threshold + optional TEE guardrail signature — constitutes a "narrow-interval trust" credential: verifiable, bounded, and internals-opaque.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Audit a compliance-ladder design (C0-C6) and transcript-fidelity ladder (T0-T5) plus their adapter conformance fixtures — Codex, Claude Code, Cloudflare, Ollama/LM Studio, custom stdio/HTTP agents — for the two failure modes that make a C-badge or T-fidelity label a lie: the ladder disagreeing with itself across doc/schema/ui/probe surfaces, and a level being reachable by self-report because no daemon-witnessed negative probe actually tries to forge it. Use when designing or freezing a compliance ladder, wiring an adapter conformance probe suite, deciding whether a numeric C-badge or T-label is safe to ship, or investigating a self-attestation or observed-to-controlled bypass risk. NOT for auditing a cryptographic protocol or whitepaper for adversarial soundness (`redteam-review`), writing TLA+/formal invariants for a daemon monitor (`runtime-verification-for-agents`), or agent identity, successor linkage, and reputation across restarts (`agent-identity-continuity-reputation`).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Verify a RuView build — full Rust workspace tests, the deterministic Python pipeline proof (SHA-256 Trust Kill Switch), firmware hash manifest, and the ADR-028 witness bundle with one-command self-verification. Use after any significant change, before merging a PR, or to produce an attestation bundle for a recipient.

日本語の概要は準備中です。原文の説明を表示しています。

ruvnet/RuView9.7万2026年10月11日 更新

Query Ondo tokenized US stock data on Binance Web3. Covers: supported stock token list, RWA metadata (company info, attestation reports), market and per-asset trading status (with corporate action codes for earnings, dividends, splits), real-time on-chain data (token price, holders, circulating supply, market cap), US stock fundamentals (P/E, dividend yield, 52-week range), and token K-Line/candlestick charts. Use this skill when users ask about: - Tokenized stock price, holders, or on-chain data for specific tickers - Whether a stock token is tradable, paused, or halted - Ondo RWA token list or which US stocks are available on-chain - Corporate actions affecting a token (dividends, stock splits, earnings halt) - Stock token K-Line or candlestick chart data - Comparing on-chain token price vs US stock price NOT for general crypto tokens (BTC, ETH, SOL, etc.) — use query-token-info for those.

日本語の概要は準備中です。原文の説明を表示しています。

ccxt/ccxt4.4万2026年10月8日 更新

NEAR AI Cloud private inference and verification. Use when integrating NEAR AI Cloud API for verifiable private AI inference, verifying model or gateway TEE attestation (NVIDIA NRAS, Intel TDX), verifying chat message signatures, implementing end-to-end encrypted chat, or using the OpenAI-compatible API with NEAR AI Cloud.

日本語の概要は準備中です。原文の説明を表示しています。

internet-court/internet-court-skill6,7132026年8月20日 更新

Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows). Use when implementing fraud prevention, detecting compromised devices, validating app authenticity with Apple's servers, protecting sensitive API endpoints with attested requests, or adding device verification to a backend architecture.

日本語の概要は準備中です。原文の説明を表示しています。

dpearson2699/swift-ios-skills1,1852026年8月1日 更新

Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain. Use when implementing SLSA controls, artifact trust policies, or compliance evidence for releases.

日本語の概要は準備中です。原文の説明を表示しています。

BagelHole/DevOps-Security-Agent-Skills1,1542026年5月22日 更新

Secure the AI model supply chain with artifact signing, provenance attestation, SBOM workflows, dependency controls, and trusted model promotion.

日本語の概要は準備中です。原文の説明を表示しています。

BagelHole/DevOps-Security-Agent-Skills1,1542026年5月22日 更新

Expert knowledge for Azure Confidential Ledger development including troubleshooting, decision making, security, integrations & coding patterns, and deployment. Use when configuring ACL auth/attestation, integrating with Blob/Cosmos, using MST payloads, or deploying via ARM/Terraform, and other Azure Confidential Ledger related development tasks. Not for Azure Confidential Computing (use azure-confidential-computing), Azure Key Vault (use azure-key-vault), Azure Dedicated HSM (use azure-dedicated-hsm), Azure Payment Hsm (use azure-payment-hsm).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Use when implementing app attestation, configuring App Check providers, setting up debug tokens, enabling backend enforcement, or managing token refresh.

日本語の概要は準備中です。原文の説明を表示しています。

evanca/flutter-ai-rules6512026年10月10日 更新

pci-audit

無料

Audit applications and infrastructure handling payment card data against PCI DSS v4.0. Heavy emphasis on scope determination (the single most-leveraged variable) plus the engineering-relevant requirements — Req 3 (storage of CHD), Req 4 (transmission), Req 6 (secure SDLC), Req 7-8 (access), Req 10 (logging), Req 11 (testing), Req 12 (program). Use when the user mentions 'PCI,' 'PCI DSS,' 'PCI DSS 4.0,' 'payment card,' 'cardholder data,' 'CHD,' 'PAN,' 'PCI scope,' 'PCI compliance,' 'SAQ,' 'AoC,' 'attestation of compliance,' 'tokenization,' 'P2PE,' 'network segmentation for PCI,' or audits any system that stores, processes, or transmits payment card data.

日本語の概要は準備中です。原文の説明を表示しています。

briiirussell/cybersecurity-skills4152026年5月27日 更新

Manage BAP (Bitcoin Attestation Protocol) identity files using bap-cli. This skill should be used when users need to create, decrypt, list, or extract BAP identity backups, work with .bep encrypted files, or generate test fixtures for Playwright tests involving BAP identities.

日本語の概要は準備中です。原文の説明を表示しています。

Microck/ordinary-claude-skills4052026年9月7日 更新