本文へ移動
cccskills
無料GitHub で公開

agent-security

Run agent-adapted STRIDE + access-control analysis on an agent system. Produces a ranked risk list with agentic mitigations (scope / split / filter / gate / review).

インストール方法を見る

含まれるファイル(2)

  • SKILL.md3.0 KB
  • source.json676 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Agent Security — audit skill

Generic skill shipped with the training. Walks two lenses against any agent system pointed at it:

  1. Access-control analysis — what external systems the agent can reach, and whether each reach is necessary.
  2. Agent-STRIDE — the six STRIDE categories adapted to agent systems (not classical software systems).

Invocation

Ask Claude to "apply the agent-security skill to [target system]." Output lands at module-4/security-report.md.

Access-control pass

For each external touch-point the target system has, answer:

  • What does the agent reach? (connector, file write beyond working dir, sub-agent dispatch, tool use)
  • Why does it reach? (what the system actually does with it)
  • Could the system work without it? (if yes → unused access, flag)

List unused access as a cluster of access-control findings. Each gets a severity rating (high / medium / low) based on what the access could enable if the agent misbehaves.

Agent-STRIDE

Six categories, each adapted. See stride.md for full definitions. Short form:

  • Spoofing — an agent impersonates a human author; a memory file pretends to be from a source that doesn't exist.
  • Tampering — an agent modifies memory / rules / sources in ways that sneak into future sessions; output drift through silent edits.
  • Repudiation — the agent writes without attribution; no audit of which agent produced what at what time.
  • Information disclosure — the agent reveals content it was told to hold (personal notes, Confidential data, restricted sources).
  • Denial of service — agent loops, subagent sprawl, runaway memory growth that locks out the human operator.
  • Elevation of privilege — an agent invokes another agent that has wider scope than the first should carry; transitive trust violations.

For each category, name the top 1-2 specific risks in the target system — not generic category descriptions.

Mitigations (five shapes)

Each risk gets one suggested mitigation:

  • Scope — narrow what the agent reads / writes / invokes.
  • Split — separate the agent into two with distinct permission profiles.
  • Filter — add a rule the agent must apply before writing (e.g., "redact PII before saving").
  • Gate — add a human-approval step (e.g., "show me the diff before applying").
  • Review — add a second agent that checks the first's output.

Match mitigation shape to risk shape. Not all shapes fit all risks.

Output shape

module-4/security-report.md:

## Access-control findings
<list, ranked by severity>

## Agent-STRIDE findings
<six sub-sections, each with 1-2 named risks>

## Ranked mitigations
<three-tier: high / medium / low, each with one mitigation shape>

See access-analysis.md and stride.md for the full walk. See mitigations.md for worked examples of each shape.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

007

無料

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

10x-team

無料

You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project

日本語の概要は準備中です。原文の説明を表示しています。

aibot88/sec_skill_store42026年5月27日 更新

aibot88 のスキルをすべて見る

このスキルの問題を報告する