ruff
無料Use when working with ruff — this skill's ruff policy and required overrides to Astral's official guidance. Pair with `astral:ruff` (if installed) for general usage.
日本語の概要は準備中です。原文の説明を表示しています。
56 件 ・ 関連度順
概要と使いどころ
Use when working with ruff — this skill's ruff policy and required overrides to Astral's official guidance. Pair with `astral:ruff` (if installed) for general usage.
日本語の概要は準備中です。原文の説明を表示しています。
Scan source code repositories, CI/CD pipelines, and configuration files for exposed AWS credentials using TruffleHog, git-secrets, and AWS-native detection. Use when integrating secrets scanning into CI/CD, auditing repositories (including git history) for historically committed AWS keys, responding to a GuardDuty alert about credential use from an unexpected location, or verifying credential rotation removed all exposed keys.
日本語の概要は準備中です。原文の説明を表示しています。
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
日本語の概要は準備中です。原文の説明を表示しています。
Tespit etme exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native Tespit mechanisms to prevent credential theft and unauthorized account access.
日本語の概要は準備中です。原文の説明を表示しています。
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
日本語の概要は準備中です。原文の説明を表示しています。
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
日本語の概要は準備中です。原文の説明を表示しています。
Djangoの公開や変更提案の前に、環境・コード品質・データベース変更・テスト・脆弱性・設定を順に検証し、段階別の合否と修正すべき問題をレポートにまとめます。
Modern Python tooling best practices using uv, ruff, ty, and pytest. Mandates the Trail of Bits Python coding standards for project setup, dependency management, linting, type checking, and testing. Based on patterns from trailofbits/cookiecutter-python.
日本語の概要は準備中です。原文の説明を表示しています。
Python project tooling: pyproject.toml as the single source of truth, package managers (pip, Poetry, uv, pipenv), virtual environments, lockfiles, ruff (lint + format), mypy (type checking), and console scripts / entry points. Stack-agnostic — referenced by every Python plugin in the marketplace. Use this skill to: - Read pyproject.toml (or requirements.txt / Pipfile) to learn which package manager and Python version the project uses. - Install, add, and remove dependencies with the project's package manager. - Run ruff for formatting and linting, mypy for type checking. - Define console scripts and entry points for CLI applications. Do NOT use this skill for: - Language idioms — see python-foundation:python-conventions. - Testing patterns — see python-foundation:pytest-testing. - Framework-specific tooling (django management commands, flask CLI) — see framework plugin skills.
日本語の概要は準備中です。原文の説明を表示しています。
Integrate gitleaks and trufflehog into CI/CD pipelines to tespit etmeleaked secrets before Dağıt:ment
日本語の概要は準備中です。原文の説明を表示しています。
Run the full static analysis suite — ruff lint, ruff format check, pyright type check, auth analysis, license headers. Use before committing or to verify code quality after changes.
日本語の概要は準備中です。原文の説明を表示しています。
機能追加やコード整理の後に、ビルド・型・lint・テスト・秘密情報の検索・差分を6段階で確認するスキル。合否と修正事項をまとめ、PRを作成できる状態か報告します。
Pythonコードの作成・レビューで、PEP 8や型ヒント、例外処理、パッケージ構成を整え、読みやすさと保守性、メモリ効率を考えた改善を支援するスキル。
Select and run Python SDK verification with nox, Makefile targets, Ruff, mypy, pytest markers, sanity tests, type inference checks, and build checks. Use when adding Python tests, diagnosing Python CI, or validating Python SDK/provider changes. Do not use for TypeScript-only checks.
日本語の概要は準備中です。原文の説明を表示しています。
Use when building Python 3.11+ applications requiring type safety, async programming, or robust error handling. Generates type-annotated Python code, configures mypy in strict mode, writes pytest test suites with fixtures and mocking, and validates code with black and ruff. Invoke for type hints, async/await patterns, dataclasses, dependency injection, logging configuration, and structured error handling.
日本語の概要は準備中です。原文の説明を表示しています。
Configures Python projects with modern tooling (uv, ruff, ty). Use when creating projects, writing standalone scripts, or migrating from pip/Poetry/mypy/black.
日本語の概要は準備中です。原文の説明を表示しています。
Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are installed on the local machine (jhaddix, SecLists, trufflehog, ffuf, dalfox, ghauri); for pure orchestration/routing use the bug-bounty skill. Workflow it covers — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use when you need the local install path of a tool / wordlist / clone for a hunt, or as the full-workflow variant when operating from this local toolkit; for general routing use the bug-bounty skill. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘、信息收集、子域名枚举、XSS测试、SQL注入、SSRF、安全审计、漏洞报告
日本語の概要は準備中です。原文の説明を表示しています。
Linting and formatting for Megatron-LM. Covers running autoformat.sh, tools (ruff, black, isort, pylint, mypy), and code style rules.
日本語の概要は準備中です。原文の説明を表示しています。
Upgrades an MWAA environment to a newer Airflow version — within 2.x, within 3.x, or across the 2.x-to-3.x boundary. Computes the version-jump path, inserting the 2.11.x stepping-stone and Python-transition step when needed. Chooses an approach by whether run history and the same environment (URL/ARN) must be kept: a new-environment upgrade (blue-green), a rehearsed in-place upgrade validated on a test copy, or a direct in-place upgrade. Runs Ruff scanning and deprecation-warning log scans for 3.x moves, plus Docker validation, batched deployment, and switchover. Saves a resumable upgrade plan for multi-session work. Triggers on: upgrade MWAA, upgrade Airflow, migrate to Airflow 3, MWAA Airflow 3, Airflow 2 to 3, preserve Airflow history, keep same MWAA environment, blue-green cutover, validation environment before cutover. Not for authoring new DAGs (authoring-mwaa-workflow), debugging unrelated DAG failures (debugging-mwaa-workflow), or MWAA Serverless YAML workflows (provisioned Python DAGs only).
日本語の概要は準備中です。原文の説明を表示しています。
Language-specific auto-lint/format/typecheck pipeline. Supports Python (ruff+pyright), TypeScript (prettier+eslint+tsc), Go (gofmt+golangci-lint). Auto-fix and convergence loops.
日本語の概要は準備中です。原文の説明を表示しています。
Master Python 3.12+ with modern features, async programming, performance optimization, and production-ready practices. Expert in the latest Python ecosystem including uv, ruff, pydantic, and FastAPI. Use PROACTIVELY for Python development, optimization, or advanced Python patterns.
日本語の概要は準備中です。原文の説明を表示しています。
Builds Python 3.11+ applications with type safety, async programming, robust error handling, mypy strict mode, pytest suites, and code validation with black and ruff.
日本語の概要は準備中です。原文の説明を表示しています。
Configure Python tooling, dependency surfaces, static analysis, and verification gates. Use when editing `pyproject.toml`, `requirements.txt`, `pytest.ini`, `ruff`, `pyright`, CI, or Python release checks.
日本語の概要は準備中です。原文の説明を表示しています。
Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Use when the user mentions 'secrets audit,' 'secret scanning,' 'leaked credentials,' 'API key in code,' 'gitleaks,' 'trufflehog,' 'git history scan,' 'secrets management,' 'vault audit,' 'rotation policy,' 'AWS Secrets Manager,' 'HashiCorp Vault,' 'Doppler,' '1Password Secrets Automation,' 'sealed-secrets,' 'External Secrets Operator,' or needs to find or prevent credential exposure.
日本語の概要は準備中です。原文の説明を表示しています。