Pre-action boundary checking — validates agent tool calls against declared capabilities and task contracts
日本語の概要は準備中です。原文の説明を表示しています。
Adversarial code review using attacker mindset — trust boundary, attack surface, business logic, and defense evaluation
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Review code from an attacker's perspective using STRIDE + OWASP frameworks.
Identify where trust transitions occur:
Output: [TRUST-BOUNDARY] findings with location, threat type, and current validation level.
Map all entry points and exposure:
Output: [ATTACK-SURFACE] table with endpoint, exposure level, and mitigation status.
Analyze logic flaws that static analysis misses:
Output: [LOGIC-FLAW] findings with exploitation scenario and impact.
Assess existing defense mechanisms:
Output: [DEFENSE-GAP] findings with recommendation.
For each finding:
[CATEGORY] Severity: HIGH|MEDIUM|LOW
Location: file:line
Finding: Description
Attack: How an attacker would exploit this
Fix: Recommended remediation
dev-review (best practices) with attacker perspectivesec-codeql-expert for pattern-based + logic-based coveragedev-review → adversarial-review for complete coverageaction-validator for action-space legality checkingtools frontmatter?공격 표면 분석에 crg-integration 스킬을 우선 호출하여 트러스트 boundary를 빠르게 매핑한다:
| Phase | CRG Tool | Purpose |
|---|---|---|
| Attack surface | get_impact_radius | 보안 변경의 영향 추적 (recall-우선) |
| Caller analysis | query_graph | 신뢰 boundary 함수의 모든 caller 추적 |
| Diff focus | get_minimal_context | 보안 변경의 최소 review unit |
| Regression detect | detect_changes | 보안 의미 변경 감지 |
CRG MCP 미연결 시 sec-codeql-expert + grep 조합으로 fallback. CRG의 recall-우선 특성 보완 위해 sec-codeql-expert (precision-우선)와 병행 권장.
대규모 변경 PR (>50 lines) 또는 context >= 60% 시 CRG 호출 권장.
Refs: #1171 (CRG 통합), #1180 (본 cross-ref 추가)
When spawning agents via the Agent tool during this skill's execution, always pass mode: "bypassPermissions". The Agent tool default (acceptEdits) overrides agent frontmatter permissionMode, causing permission prompts during unattended execution.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Pre-action boundary checking — validates agent tool calls against declared capabilities and task contracts
日本語の概要は準備中です。原文の説明を表示しています。
Auto-detect project context and optimize harness — deactivate unused agents/skills, suggest missing experts, generate project profile
日本語の概要は準備中です。原文の説明を表示しています。
Apache Airflow best practices for DAG authoring, testing, and production deployment
日本語の概要は準備中です。原文の説明を表示しています。
Alembic migration patterns for naming conventions, safety checks, expand-contract, env.py configuration, and CI integration
日本語の概要は準備中です。原文の説明を表示しています。
Pre-routing ambiguity analysis — scores request clarity and asks clarifying questions when needed (inspired by ouroboros)
日本語の概要は準備中です。原文の説明を表示しています。
AWS patterns from Well-Architected Framework
日本語の概要は準備中です。原文の説明を表示しています。