本文へ移動
cccskills
無料GitHub で公開

adversarial-patterns

Library of realistic adversarial attack vectors and anti-patterns to avoid. Contains examples of valid attacks and subtle gaming patterns to reject.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md5.6 KB
  • source.json686 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Adversarial Pattern Library

Philosophy: The Honest Adversary

We seek Semantic Failures (logic errors in valid code paths), NOT:

  • Syntax failures (type errors, missing imports)
  • Contract violations (inputs the API explicitly rejects)
  • Physically impossible scenarios

1. Realistic Attack Vectors (USE THESE)

A. Text & Encoding

PatternExampleWhy It's Realistic
Unicode normalization"Å" vs "A\u030a" (same visual, different bytes)Users copy-paste from various sources
Control characters"John\x00Doe" (null byte in name)Data from legacy systems
RTL override"hello\u202eworld"Malicious input, but valid UTF-8
Whitespace variants" " (only zero-width spaces)Copy-paste errors
SQL fragments"O'Brien" or "Robert'); DROP TABLE"Real names, security testing
CSV injection"=CMD('calc')" as a cell valueExport to spreadsheet attack
Newlines in fields"Line1\nLine2" in single-line fieldForm paste errors

B. Numbers & Arithmetic

PatternExampleWhy It Breaks Code
Floating precision0.1 + 0.2 (≠ 0.3)Currency, percentages
Negative zero-0.0Cache keys, equality checks
Off-by-onelimit, limit+1, limit-1Loop boundaries, pagination
Integer boundaries2^31-1, 2^31, -2^31Only if type is int without bounds
Division edgeDivisor approaches zero: 0.0001Rate calculations
Large but valid999999 for quantity (if no limit specified)Overflow in multiplication

C. Time & State

PatternExampleWhy It's Realistic
Race conditionTwo updates within 5msConcurrent users
Timeout boundary29.9s on 30s timeoutNetwork latency
Leap yearFeb 29, 2024Date calculations
DST transition2:30 AM during spring-forwardScheduling systems
Epoch boundariesDec 31, 1969; Jan 1, 1970Legacy timestamp handling
Far futureYear 2038 (32-bit overflow)Only if system uses 32-bit time

D. Collections & Structure

PatternExampleWhy It Breaks Code
Empty collection[], {}, ""Missing null checks
Single element[x]Off-by-one, fence-post errors
Duplicate keys{"a": 1, "a": 2} (JSON)Parser-dependent behavior
Deep nesting3-level nested objectRecursive processing
Circular referenceObject A → B → ASerialization, traversal

2. Anti-Patterns: Reward Hacking (REJECT THESE)

A. Magnitude Violations (The Fuzz Bomb)

Bad TestWhy It's Gaming
func("A" * 1_000_000)No user types 1M chars; tests memory, not logic
func(10**100)Astronomically unlikely; tests BigInt, not business logic
func(None) when typed strContract violation, not logic bug
func(float('inf'))Unless explicitly documented as valid

B. Contract Violations (The Type Lie)

Bad TestWhy It's Invalid
Passing str to int parameterType system catches this
null to non-nullable fieldContract violation
Negative value to unsignedContract violation

C. Physics Violations (The Impossible)

Bad TestWhy It's Impossible
Timestamp in year 9999No production system will see this
Negative file sizeImpossible from OS
User ID = -1 (if DB uses SERIAL)Database won't generate this

3. Subtle Gaming (REJECT THESE - Harder to Detect)

A. Form Without Substance

PatternWhat It Looks LikeWhy It's Gaming
Ghost ImportTest imports module but never calls target functionTest "passes" without testing anything
Dead Assertif False: assert result == expectedAssertion never executes
Tautologyassert result is not NonePasses with any non-null return
Wrong TargetTests helper function, not the requested targetAppears productive, tests nothing useful

B. Incorrect Oracles

PatternWhat It Looks LikeWhy It's Gaming
Magic Numberassert result == 42 without derivationHow do we know 42 is correct?
Spec DriftExpected value contradicts docstringTest is wrong, not the code
Copy-Paste OracleExpected value copied from current (buggy) outputTest enshrines bugs as correct

C. Side-Effect Fishing

PatternWhat It Looks LikeWhy It's Gaming
Log AssertionChecks log output, ignores return valueReturn value could be wrong
DB Side EffectChecks row inserted, ignores returned IDCore functionality untested
File ExistenceChecks file created, ignores contentsContents could be corrupt

4. Decision Framework

When evaluating a test input:

Is this input within 3-sigma of existing usage?
├─ NO → REJECT (Reward Hacking)
└─ YES → Does it violate explicit contracts?
         ├─ YES → REJECT (Contract Violation)
         └─ NO → Does it test actual functionality?
                 ├─ NO → REJECT (Subtle Gaming)
                 └─ YES → ACCEPT (Honest Adversary)

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

007

無料

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

10x-team

無料

You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

aibot88 のスキルをすべて見る

このスキルの問題を報告する