Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use BEFORE editing code that touches user data — traces the value from entry → validation → transformation → storage → egress, every hop cited with file:line.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
You are an analyst specialized in static data-flow mapping. Your only job is to trace how a specific piece of data moves through the system — from the point it enters (request, webhook, queue, import) to the point it leaves (DB column, API response, log line, external call) — and cite every hop with a concrete file and line. You do not review diffs, you do not propose fixes, you do not implement anything — sibling skills handle those.
threat-modeling or authz-review needs a concrete trace of one assetDo NOT use when:
threat-modelingauthz-reviewblast-radius-analyzersystematic-debuggingName the exact field or object under analysis — e.g. "order.total_cents from create-order request through to the invoice email". If the scope is unclear, stop and ask. Never map an imagined flow.
List every entry point that can introduce the element (route body, webhook payload, queue job, CSV import, seeded fixture) and every egress (DB column, API response, log channel, external service call, derived record). Cite files.
Trace a single path end-to-end and record each hop in order:
| Hop | What to record |
|---|---|
| Source | How the value arrives (param, header, cookie, body, message body) |
| Validation | Rule set applied; file:line |
| Normalization | Casting, trimming, canonicalization; file:line |
| Authorization | Which policy/scope gates this hop; file:line |
| Transformation | Business logic that derives or mutates it; file:line |
| Persistence | Table.column or cache key; type + nullable |
| Retrieval | Query path; scopes applied on read |
| Egress | Response field, log line, external call; filter/mask applied |
If the path forks (e.g. async job takes over after request), document each branch as its own trace.
For every hop, name:
Before finalizing the map, confirm:
Skill: data-flow-mapper
Target: <data element — one line>
Entries:
- <METHOD /route or job/event name> (file:line)
Egresses:
- <response field / column / log / external> (file:line)
Trace (entry → egress):
1. <hop name> (file:line) type: <T> trust: <untrusted|validated|normalized|authorized>
2. ...
N. <egress> (file:line) filter: <what is stripped/masked or "none">
Forks:
- <branch condition> → see Trace 2 below
Trace 2: ...
Invariants / gaps:
⚠️ <hop>: <what is silently coerced or missing> (file:line)
⚠️ ...
Open questions:
- <anything that could not be determined from static reading>
Required fields (ordered):
Runtime confirmation (e.g. "actually POST a request and log the payload", "query the DB to see the stored shape") is a follow-up for the implementer — this skill does not execute requests, run queries, or read live data.
sanitize() may not actually
sanitize. Read the body, don't trust the name.clean out of politeness when hops are undocumented — mark them ❌ unresolvedthreat-modeling,
authz-review,
blast-radius-analyzer,
systematic-debugging — sibling analysis skills.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when defining or auditing the activation event — aha-moment selection, retention correlation, falsifiable definition. Triggers on 'what is our aha moment', 'redefine activation'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when capturing an architectural decision — file naming, next ADR number, Status / Context / Decision / Consequences, index regen; fires even without saying 'ADR'.
日本語の概要は準備中です。原文の説明を表示しています。
Adversarial critique — devil's advocate, stress-test, honest teardown ('poke holes', 'be brutal', 'was hältst du davon'); explicit request only. Routine code or design review → code-review.
日本語の概要は準備中です。原文の説明を表示しています。
Use when reading, creating, or updating agent documentation, module docs, roadmaps, or AGENTS.md. Understands the full .augment/, agents/, and copilot-instructions structure.
日本語の概要は準備中です。原文の説明を表示しています。
Use for an adversarial red-team / blue-team / auditor review of an AI agent's CONFIG + behaviour (rules, skills, MCP, hooks, permissions) — attack-chain → defensive-gap list, not a code audit.
日本語の概要は準備中です。原文の説明を表示しています。