007
無料Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Follow these patterns when implementing activity emission and audit logging in OptAIC. Use for emitting ActivityEnvelopes on mutations (create, update, delete, execute), designing payloads, and ensuring audit compliance.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Guide for implementing audit-compliant activity emission in OptAIC services.
Apply when:
If it changes state, it MUST emit an activity.
All mutations must emit activities in the service layer (not API handlers or models).
ActivityEnvelope(
tenant_id=UUID,
actor_principal_id=UUID,
resource_id=UUID,
resource_type=str, # "signal", "dataset", "portfolio"
action=str, # "signal.created", "run.completed"
visibility=str, # "private"|"resource"|"scope"|"tenant"
payload=dict, # Action-specific data
delivery_channels=list, # Where to publish
correlation_id=UUID # Links related activities
)
Use pattern: <resource>.<verb>
signal.registered signal.validated signal.promoted
dataset.created dataset.previewed dataset.refresh_started
dataset.refresh_completed dataset.refresh_failed
pipeline_def.submitted pipeline_def.deployed
pipeline_instance.created pipeline.run_started pipeline.run_completed
experiment.created experiment.updated
experiment.run_completed experiment.run_failed
expression.evaluated macro.saved
run.started run.completed run.failed run.cancelled
backtest.started backtest.completed backtest.failed
training.started training.completed training.failed
inference.started inference.completed inference.failed
optimization.started optimization.completed optimization.failed
monitoring.started monitoring.completed monitoring.alert
portfolio.rebalanced portfolio.constraints_updated
portfolio.weights_computed portfolio.optimization_started
promotion.requested promotion.approved promotion.merged promotion.rejected
guardrails.validated guardrails.blocked guardrails.warned
monitoring.drift_detected monitoring.performance_alert
monitoring.data_quality_alert monitoring.threshold_breach
await record_activity_with_outbox(
session=self.session,
envelope=ActivityEnvelope(
action="signal.created",
actor_principal_id=self.actor_id,
tenant_id=self.tenant_id,
resource_id=resource.id,
resource_type="signal",
payload={"signal_type": dto.signal_type}
)
)
from libs.core.activity import tx_activity
result, activity = await tx_activity(db, envelope, domain_fn)
Include: Changed fields, related IDs, computed metrics, status transitions Exclude: Passwords, API keys, large blobs, PII beyond necessity
See references/payload-examples.md.
Link related activities in workflows:
correlation_id = uuid4()
# Use same correlation_id throughout workflow
await emit("promotion.requested", correlation_id=correlation_id)
await emit("guardrails.validated", correlation_id=correlation_id)
await emit("promotion.merged", correlation_id=correlation_id)
Activities are processed by the outbox worker which publishes to Centrifugo for real-time WebSocket delivery.
| Type | Who | Mechanism | Opt-in? |
|---|---|---|---|
| Implicit | Owner + Delegators | Query Resource + RoleBinding | Automatic |
| Explicit | Subscribers | Query Subscription table | User opts in |
# Outbox worker builds watchers set:
watchers: set[UUID] = set()
# 1. Explicit subscribers (user opt-in)
watchers |= await _subscription_watchers(session, tenant_id, resource_id)
# 2. Resource owner (implicit - auto-notified)
owner_id = await _resource_owner(session, tenant_id, resource_id)
if owner_id:
watchers.add(owner_id)
# 3. Delegators (owner/delegator roles on resource or ancestors)
watchers |= await _resource_delegators(session, tenant_id, resource_id)
# 4. CRITICAL: Exclude actor (don't notify yourself)
watchers.discard(actor_principal_id)
# 5. Filter by user notification preferences
watchers = await _filter_watchers_by_preference(session, tenant_id, watchers, action)
Users configure via PUT /notifications/preferences:
| Filter Mode | Actions Notified |
|---|---|
all | All activity types |
mutations (default) | resource.created/updated/deleted, transfer.*, promotion.* |
custom | User-defined patterns (e.g., ["resource.*", "chat.*"]) |
# Custom pattern matching uses fnmatch
await client.notifications.update_preferences(
filter_mode="custom",
custom_actions=["resource.*", "promotion.*"],
)
| Anti-Pattern | Why It's Wrong | Correct Approach |
|---|---|---|
| Notify actor about own action | Noisy, redundant | Always watchers.discard(actor_id) |
| Hardcode notification targets | Inflexible | Build watchers dynamically |
| Skip preference filtering | Users can't control noise | Always filter by preferences |
| Notify without checking roles | Security issue | Use _resource_delegators() |
# Subscribe to a resource
await client.subscriptions.create(
resource_id=folder_id,
scope="descendants", # or "resource" for single resource
)
# List subscriptions
subs = await client.subscriptions.list()
# Unsubscribe
await client.subscriptions.revoke(subscription_id)
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).
日本語の概要は準備中です。原文の説明を表示しています。
You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。