Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when applying security best practices — authentication, authorization, CSRF protection, input sanitization, rate limiting, or secure coding — stack-agnostic.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Use when implementing authentication, authorization, or any security-sensitive functionality.
Do NOT use when:
laravel-validation for Laravel; otherwise the framework-native primitive — Zod / class-validator, Pydantic, struct-tag validators).security-audit.threat-modeling.authz-review.The procedure below is stack-agnostic. For framework-specific primitives (Laravel Policies / Gates / FormRequests, Symfony voters, NestJS guards, Next.js middleware), defer to:
| Stack | Carve-out |
|---|---|
| Laravel | laravel, laravel-validation, laravel-middleware |
| Symfony | symfony-workflow |
| Next.js / TS | nextjs-patterns |
agents/authentication.md, docs/auth.md, or framework docs).app/Policies/, Symfony src/Security/Voter/, NestJS *.guard.ts).config/auth.php, next-auth.config.ts, Symfony security.yaml, FastAPI dependency).multi-tenancy.authorize(), controller / route-handler dependency, middleware chain).For security-sensitive changes, run adversarial-review.
Focus on: attack surface, trusting user input, authorization gaps.
→ For PHP / Laravel specifics (auth helpers, mass assignment, Blade escaping, CSRF middleware): see guideline docs/guidelines/php/security.md.
→ For other stacks, follow the framework's hardening guide and the carve-outs above.
This skill carries no cryptographic parameter, key size, work factor, cipher suite, or TLS version floor: such a value is authoritative-looking long after it stops being true. Take it from https://cheatsheetseries.owasp.org/ at the moment you need it — never from memory, never from this file. Rationale and reopening condition: ADR-238.
Gate::authorize() throws vs Gate::allows() returns bool in Laravel; CanActivate in NestJS throws; FastAPI dependencies throw HTTPException). Pick based on how the framework expects failure to surface.$fillable / $guarded, DTO mapping, Pydantic model).まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when defining or auditing the activation event — aha-moment selection, retention correlation, falsifiable definition. Triggers on 'what is our aha moment', 'redefine activation'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when capturing an architectural decision — file naming, next ADR number, Status / Context / Decision / Consequences, index regen; fires even without saying 'ADR'.
日本語の概要は準備中です。原文の説明を表示しています。
Adversarial critique — devil's advocate, stress-test, honest teardown ('poke holes', 'be brutal', 'was hältst du davon'); explicit request only. Routine code or design review → code-review.
日本語の概要は準備中です。原文の説明を表示しています。
Use when reading, creating, or updating agent documentation, module docs, roadmaps, or AGENTS.md. Understands the full .augment/, agents/, and copilot-instructions structure.
日本語の概要は準備中です。原文の説明を表示しています。
Use for an adversarial red-team / blue-team / auditor review of an AI agent's CONFIG + behaviour (rules, skills, MCP, hooks, permissions) — attack-chain → defensive-gap list, not a code audit.
日本語の概要は準備中です。原文の説明を表示しています。