007
無料Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Library of realistic adversarial attack vectors and anti-patterns to avoid. Contains examples of valid attacks and subtle gaming patterns to reject.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
We seek Semantic Failures (logic errors in valid code paths), NOT:
| Pattern | Example | Why It's Realistic |
|---|---|---|
| Unicode normalization | "Å" vs "A\u030a" (same visual, different bytes) | Users copy-paste from various sources |
| Control characters | "John\x00Doe" (null byte in name) | Data from legacy systems |
| RTL override | "hello\u202eworld" | Malicious input, but valid UTF-8 |
| Whitespace variants | " " (only zero-width spaces) | Copy-paste errors |
| SQL fragments | "O'Brien" or "Robert'); DROP TABLE" | Real names, security testing |
| CSV injection | "=CMD('calc')" as a cell value | Export to spreadsheet attack |
| Newlines in fields | "Line1\nLine2" in single-line field | Form paste errors |
| Pattern | Example | Why It Breaks Code |
|---|---|---|
| Floating precision | 0.1 + 0.2 (≠ 0.3) | Currency, percentages |
| Negative zero | -0.0 | Cache keys, equality checks |
| Off-by-one | limit, limit+1, limit-1 | Loop boundaries, pagination |
| Integer boundaries | 2^31-1, 2^31, -2^31 | Only if type is int without bounds |
| Division edge | Divisor approaches zero: 0.0001 | Rate calculations |
| Large but valid | 999999 for quantity (if no limit specified) | Overflow in multiplication |
| Pattern | Example | Why It's Realistic |
|---|---|---|
| Race condition | Two updates within 5ms | Concurrent users |
| Timeout boundary | 29.9s on 30s timeout | Network latency |
| Leap year | Feb 29, 2024 | Date calculations |
| DST transition | 2:30 AM during spring-forward | Scheduling systems |
| Epoch boundaries | Dec 31, 1969; Jan 1, 1970 | Legacy timestamp handling |
| Far future | Year 2038 (32-bit overflow) | Only if system uses 32-bit time |
| Pattern | Example | Why It Breaks Code |
|---|---|---|
| Empty collection | [], {}, "" | Missing null checks |
| Single element | [x] | Off-by-one, fence-post errors |
| Duplicate keys | {"a": 1, "a": 2} (JSON) | Parser-dependent behavior |
| Deep nesting | 3-level nested object | Recursive processing |
| Circular reference | Object A → B → A | Serialization, traversal |
| Bad Test | Why It's Gaming |
|---|---|
func("A" * 1_000_000) | No user types 1M chars; tests memory, not logic |
func(10**100) | Astronomically unlikely; tests BigInt, not business logic |
func(None) when typed str | Contract violation, not logic bug |
func(float('inf')) | Unless explicitly documented as valid |
| Bad Test | Why It's Invalid |
|---|---|
Passing str to int parameter | Type system catches this |
null to non-nullable field | Contract violation |
Negative value to unsigned | Contract violation |
| Bad Test | Why It's Impossible |
|---|---|
| Timestamp in year 9999 | No production system will see this |
| Negative file size | Impossible from OS |
| User ID = -1 (if DB uses SERIAL) | Database won't generate this |
| Pattern | What It Looks Like | Why It's Gaming |
|---|---|---|
| Ghost Import | Test imports module but never calls target function | Test "passes" without testing anything |
| Dead Assert | if False: assert result == expected | Assertion never executes |
| Tautology | assert result is not None | Passes with any non-null return |
| Wrong Target | Tests helper function, not the requested target | Appears productive, tests nothing useful |
| Pattern | What It Looks Like | Why It's Gaming |
|---|---|---|
| Magic Number | assert result == 42 without derivation | How do we know 42 is correct? |
| Spec Drift | Expected value contradicts docstring | Test is wrong, not the code |
| Copy-Paste Oracle | Expected value copied from current (buggy) output | Test enshrines bugs as correct |
| Pattern | What It Looks Like | Why It's Gaming |
|---|---|---|
| Log Assertion | Checks log output, ignores return value | Return value could be wrong |
| DB Side Effect | Checks row inserted, ignores returned ID | Core functionality untested |
| File Existence | Checks file created, ignores contents | Contents could be corrupt |
When evaluating a test input:
Is this input within 3-sigma of existing usage?
├─ NO → REJECT (Reward Hacking)
└─ YES → Does it violate explicit contracts?
├─ YES → REJECT (Contract Violation)
└─ NO → Does it test actual functionality?
├─ NO → REJECT (Subtle Gaming)
└─ YES → ACCEPT (Honest Adversary)
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).
日本語の概要は準備中です。原文の説明を表示しています。
You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。