007
無料Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Detect project tech stack and configure Claude Code hooks for mechanical enforcement of linting and security rules. Use this skill when a user wants to set up hooks, configure auto-linting, add security guards, or move from advisory CLAUDE.md rules to mechanical enforcement.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Version: 1.0.0 Category: Enforcement Type: Conversational (generates configuration) Duration: 1-3 minutes
CLAUDE.md rules are advisory -- Claude can ignore them. Hooks are mechanical -- they execute automatically and cannot be bypassed. This skill detects a project's tech stack and available linters, then generates a .claude/settings.json with PostToolUse (lint) and PreToolUse (security) hooks configured.
"The difference between 'I told it not to' and 'it physically cannot' is everything."
Determine the path to the Artifex hooks directory. Check in order:
~/.claude/hooks/ (if installed via installer)hooks/ directory (if running from source)Verify both post-write-lint.sh and pre-command-security.sh exist and are executable. If not found, report the issue and offer to create them.
Set HOOKS_DIR to the resolved path for use in settings.json.
Use Glob and file existence checks to identify the project's technologies:
| File/Pattern | Technology | Linter to check |
|---|---|---|
package.json, *.js, *.ts, *.jsx, *.tsx | JavaScript/TypeScript | biome, eslint |
*.py, pyproject.toml, setup.py, requirements.txt | Python | ruff, flake8 |
*.sh, *.bash | Shell scripts | shellcheck |
*.go, go.mod | Go | go vet |
Cargo.toml, *.rs | Rust | cargo clippy |
For each detected technology, check if the corresponding linter is installed:
command -v biome >/dev/null 2>&1 && echo "biome available" || echo "biome not found"
command -v eslint >/dev/null 2>&1 && echo "eslint available" || echo "eslint not found"
command -v ruff >/dev/null 2>&1 && echo "ruff available" || echo "ruff not found"
command -v flake8 >/dev/null 2>&1 && echo "flake8 available" || echo "flake8 not found"
command -v shellcheck >/dev/null 2>&1 && echo "shellcheck available" || echo "shellcheck not found"
command -v go >/dev/null 2>&1 && echo "go available" || echo "go not found"
command -v cargo >/dev/null 2>&1 && echo "cargo available" || echo "cargo not found"
Show the user what was detected:
Tech Stack Detection
====================
Detected technologies:
- JavaScript/TypeScript (found package.json, *.ts files)
- Shell scripts (found *.sh files)
Available linters:
- eslint (for JS/TS) ........... installed
- biome (for JS/TS) ............ not found
- shellcheck (for shell) ....... installed
- ruff (for Python) ............ not applicable
Hooks to configure:
1. PostToolUse: Auto-lint after Write/Edit
- Will run eslint on JS/TS files
- Will run shellcheck on shell scripts
2. PreToolUse: Security guard on Bash commands
- Blocks catastrophic deletes (rm -rf /, ~, $HOME)
- Blocks force-push to main/master
- Blocks reading .env files
- Blocks chmod 777
- Blocks pipe-to-shell (curl | sh)
Read .claude/settings.json if it exists. If it already has hooks configured:
If .claude/settings.json does not exist, note that it will be created.
Create or update .claude/settings.json with the hooks configuration:
{
"hooks": {
"PostToolUse": [
{
"matcher": "Write|Edit",
"hook": "HOOKS_DIR/post-write-lint.sh $TOOL_INPUT_FILE $TOOL_OUTPUT_FILE"
}
],
"PreToolUse": [
{
"matcher": "Bash",
"hook": "HOOKS_DIR/pre-command-security.sh $TOOL_INPUT"
}
]
}
}
Replace HOOKS_DIR with the actual resolved path from Step 1.
If existing settings have other keys (not hooks), preserve them when writing.
After writing the configuration:
.claude/settings.json was written successfullyIf any detected technology has no linter available, suggest installation:
| Technology | Recommended linter | Install command |
|---|---|---|
| JavaScript/TypeScript | biome | npm install --save-dev @biomejs/biome |
| JavaScript/TypeScript | eslint | npm install --save-dev eslint |
| Python | ruff | pip install ruff or brew install ruff |
| Python | flake8 | pip install flake8 |
| Shell | shellcheck | brew install shellcheck or apt install shellcheck |
| Go | go vet | Included with Go installation |
| Rust | cargo clippy | rustup component add clippy |
If the user asks to customize, support these operations:
Ask for:
Then edit pre-command-security.sh to add the new check before the final exit 0:
# User-defined rule: <description>
if echo "$COMMAND" | grep -qE '<pattern>'; then
block "<explanation>"
fi
Show the current rules in pre-command-security.sh and ask which to remove. Comment out or delete the corresponding if block.
Ask for:
Then edit post-write-lint.sh to add a new case in the run_lint() function.
Remove or comment out the corresponding case in post-write-lint.sh.
hooks section.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).
日本語の概要は準備中です。原文の説明を表示しています。
You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。