本文へ移動
cccskills

「security-review」の検索結果

88 件 ・ 関連度順

概要と使いどころ

Security-focused code review identifying high-confidence exploitable vulnerabilities with two-axis severity/confidence scoring, OWASP 2025 alignment, per-finding Haiku verification, and false positive filtering. Optional GitHub PR posting. Use when user runs /security-review, /review:security-review, requests a "security review", "security audit", "vulnerability scan", or mentions "find vulnerabilities", "check for exploits".

日本語の概要は準備中です。原文の説明を表示しています。

joaquimscosta/arkhe-claude-plugins212026年8月14日 更新

code-review-team

無料日本語概要

5つの専門エージェント(backend-reviewer, frontend-reviewer, test-reviewer, security-reviewer, ux-reviewer)がチームでコードレビューするスキル。 git diff ベースで変更ファイルを検出し、各専門家が並列でレビューして 統合レポート(Markdown)を docs/reviews/ に出力する。 Use when: コードレビューしたい、変更をレビュー、レビューチーム、 チームレビュー、実装をチェック、品質チェック。 Triggers: "レビュー", "review", "コードレビュー", "code review", "チームレビュー", "team review", "変更をチェック", "品質チェック"

sean-sunagaku/claude-code-plugin382026年7月30日 更新

Use when legacy prompts or older framework flows reference `security-reviewer` and you need the modern runtime to resolve that capability cleanly.

日本語の概要は準備中です。原文の説明を表示しています。

galyarderlabs/galyarder-framework252026年10月11日 更新

Use when performing security audits, vulnerability assessments, penetration testing, or when asked to find security issues. Use when encountering code that handles user input, executes commands, reads files, or makes network requests.

日本語の概要は準備中です。原文の説明を表示しています。

Dilaz/security-review-skill72026年2月3日 更新

quality-gate

無料日本語概要

コード品質の最終確認。Skill: code-review (built-in) で correctness bug を検出 → main agent が findings を修正 → lint/ty 静的解析 → 条件付きで security-reviewer / critic を spawn (security 関連変更 or plan/requirements.md がある時のみ)。「品質チェックして」「品質ゲート通して」「レビューして」「コードを確認して」「PR 出す前にチェック」「セキュリティ大丈夫?」「コード見て」で発動。

kok1eee/o-m-cc62026年6月9日 更新

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

it-security-review

無料日本語概要

社員が申請したソフトウェア・SaaS・クラウドサービスの社内利用可否を、企業のIT/セキュリティ統制の観点から調査・評価するスキル。「〇〇のセキュリティ評価をして」「〇〇は社内で使っても大丈夫?」「このSaaSのセキュリティチェックをして」「新しいツールの導入審査をして」「〇〇と△△どちらが安全?」のような依頼で必ず使うこと。「セキュリティ」という言葉がなくても、特定のツール・サービスの社内導入可否・利用申請・リスク判断が話題になったら使う。Web検索で一次情報(プライバシーポリシー、利用規約、セキュリティホワイトペーパー、第三者認証)を収集し、6分野18項目のチェックリストに基づく3段階リスク評価付きの日本語レポート(Markdownファイル)と、ワークフロー(稟議)システムの承認コメント欄に貼れる短文サマリーを生成する。

asaponi-corpeng/it-security-review42026年8月21日 更新

evaluate

無料日本語概要

Uncorrelated Evaluator — 4軸ルーブリック専門エージェント(functionality-reviewer・code-reviewer・design-reviewer・originality-reviewer)と security-reviewer を5並列実行し、成果物を多面的に独立評価します。PASS / NEEDS WORK / BLOCKED 判定を返します。Self-leniency 防止のため、実装エージェントのコンテキストを引き継がない新規エージェントとして起動します。「レビューして」「評価して」「実装を確認して」などのリクエストで起動します。

ac2393921/long-running-harness32026年5月13日 更新

security-review

無料日本語概要

認証や決済、APIの実装時に、入力検証・アクセス権限・秘密情報の管理などを点検し、実装例と公開前のチェックリストで脆弱性対策を支えるスキル。

  • ログインとアクセス権限の確認
  • API入力とファイル投稿の点検
  • 秘密情報や機密ログの見直し
affaan-m/ECC27.7万2026年10月12日 更新

orch-build-mvp

無料日本語概要

設計書や要件書から、最初から最後まで動く小さな機能単位を計画し、ひな形作成、生成と評価の反復、レビューと承認を経て動く最小限の製品を組み立てるスキル。

  • 設計書から動くMVPを作りたいとき
  • 一連の処理が動く小さな機能単位の計画
  • 最初に動く機能のひな形作成
affaan-m/ECC27.7万2026年10月12日 更新

orch-add-feature

無料日本語概要

まだ存在しない機能の追加を、調査・計画からテスト先行の実装、レビュー、コミットまで進めるスキル。工程を担当エージェントに分担し、計画とコミット前に承認を挟みます。

  • 未実装の機能を追加したいとき
  • テスト先行で新機能を実装
  • 認証機能のセキュリティレビュー
affaan-m/ECC27.7万2026年10月12日 更新

orch-change-feature

無料日本語概要

正常に動いている既存機能を新しい仕様へ変更するスキル。テストを先に更新し、実装の修正、レビュー、承認を挟んだコミットまで順に進めます。

  • 既存の通知しきい値を変えたいとき
  • 動作中の機能を新仕様に合わせたいとき
  • 振る舞いの変更前にテストを更新したいとき
affaan-m/ECC27.7万2026年10月12日 更新

Complete a security review of the pending changes on the current branch

日本語の概要は準備中です。原文の説明を表示しています。

asgeirtj/system_prompts_leaks6.9万2026年10月11日 更新

Find security vulnerabilities in a codebase or repository with Strix — a white-box AI security review that reads your source, reasons about the actual data flow and authorization model, then exploits what it finds in a live sandbox so every reported issue has a working proof-of-concept instead of a noisy static-analysis alert. Covers injection, XSS, SSRF, broken access control and IDOR, insecure deserialization, secrets in code, unsafe dependencies, and business-logic flaws. Use when the user asks to security-scan, security-review, or audit their code, repo, or pull request for vulnerabilities.

日本語の概要は準備中です。原文の説明を表示しています。

usestrix/strix6.8万2026年10月11日 更新

Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema validation, official-SDK usage, RCE vectors, and the OWASP MCP Top 10 — producing a report with file/line evidence. Use this skill when: - Reviewing an MCP server implementation for security before release - Checking a server against the baseline controls (MCP-01 to MCP-05) and the OWASP MCP Top 10 - Auditing tools for RCE vectors (command/code injection, unsafe deserialization, path traversal, SSTI, dependency hijacking, SSRF) - Verifying auth, session, rate-limiting, and input-validation controls on a network-exposed server - Reviewing MCP client code that handles untrusted server responses and session IDs - Requests like "review this MCP server for security" or "is my MCP server implementation secure?"

日本語の概要は準備中です。原文の説明を表示しています。

github/awesome-copilot4万2026年10月9日 更新

omp-roles

無料

Use this skill whenever you need the allowed_tools / skills preset for a sub-agent role before calling spawn_subagent. Trigger especially when user mentions: "role", "spawn_subagent", "allowed_tools", or any OMP role name (executor, architect, analyst, critic, security-reviewer, code-reviewer, qa-tester, planner, explore, debugger, verifier). Also use when a /ultrawork, /ralph, /autopilot, /ultraqa, or /team workflow step asks for role tool/skill configuration.

日本語の概要は準備中です。原文の説明を表示しています。

agentscope-ai/QwenPaw3.6万2026年10月10日 更新

Security-focused code review checklist for identifying vulnerabilities

日本語の概要は準備中です。原文の説明を表示しています。

mastra-ai/mastra2.9万2026年10月11日 更新

Flag only new security issues introduced by this diff. Reported in the Warden security summary.

日本語の概要は準備中です。原文の説明を表示しています。

different-ai/openwork2.4万2026年10月11日 更新

Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.

日本語の概要は準備中です。原文の説明を表示しています。

Jeffallan/claude-skills1.2万2026年10月4日 更新

Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

日本語の概要は準備中です。原文の説明を表示しています。

Jeffallan/claude-skills1.2万2026年10月4日 更新

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

日本語の概要は準備中です。原文の説明を表示しています。

WorldFlowAI/everything-claude-code4,4892026年1月23日 更新

Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review.

日本語の概要は準備中です。原文の説明を表示しています。

foryourhealth111-pixel/Vibe-Skills3,6532026年8月31日 更新

当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

日本語の概要は準備中です。原文の説明を表示しています。

xu-xiang/everything-claude-code-zh1,9842026年3月5日 更新

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

日本語の概要は準備中です。原文の説明を表示しています。

xu-xiang/everything-claude-code-zh1,9842026年3月5日 更新