本文へ移動
cccskills
無料GitHub で公開

dygo-security-engineering

Design, implement, or review security-sensitive dygo behavior across auth, sessions, Permissions, secrets, APIs, database writes, files, Jobs, and Studio. Use when security boundaries are a primary concern.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

dygo Security Engineering

Protect business data at the server boundary and use secure defaults.

Review Areas

  • identity, session creation, expiry, revocation, and cookie settings;
  • Permission checks and Administrator boundaries;
  • secret encryption, redaction, environment selection, and key rotation;
  • input validation, query construction, routes, and API errors;
  • destructive database and CLI operations;
  • Job payloads, Logs, files, and audit data;
  • Studio exposure of protected metadata and Records.

Rules

  • Default to deny.
  • Do not rely on UI hiding for enforcement.
  • Keep secrets out of stdout, Logs, errors, fixtures, and committed plaintext.
  • Use parameterized queries and canonical identifier validation.
  • Make privileged and destructive targets explicit before execution.
  • Preserve tenant or actor context when the runtime contract requires it.
  • Record useful security events without storing sensitive payloads.
  • Do not invent cryptographic protocols. Use the repository's established libraries and formats.
  • Treat public SDK and HTTP surfaces as compatibility and trust boundaries.

Use focused adversarial checks for the changed boundary. Report evidence and impact. Do not expand a normal review into a security audit unless the task calls for it.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Design, implement, or review dygo roles, Entity access metadata, Permissions, and permission-aware Business App behavior. Use when access to Records or business actions is central to the task.

日本語の概要は準備中です。原文の説明を表示しています。

hapyco/dygo162026年10月2日 更新

Design, implement, or review dygo HTTP APIs and public App SDK contracts. Use for Record APIs, metadata and boot endpoints, query behavior, response envelopes, compatibility, and public Go interfaces.

日本語の概要は準備中です。原文の説明を表示しています。

hapyco/dygo162026年10月2日 更新

Diagnose a dygo Business App that does not validate, boot, route, render, authorize, migrate, or execute background work correctly. Use for evidence-first investigation rather than feature implementation.

日本語の概要は準備中です。原文の説明を表示しています。

hapyco/dygo162026年10月2日 更新

Build or extend a dygo Business App using the supported project layout, generators, metadata, SDK, and validation workflow. Use for general app work that is not primarily Entity modeling, access, hooks, Jobs, fixtures, or patches.

日本語の概要は準備中です。原文の説明を表示しています。

hapyco/dygo162026年10月2日 更新

Review a dygo Business App for framework conventions, model quality, access control, SDK boundaries, observability, and safe lifecycle behavior. Use for App audits and pre-merge reviews, not ordinary implementation.

日本語の概要は準備中です。原文の説明を表示しています。

hapyco/dygo162026年10月2日 更新

Design, implement, or review the dygo framework CLI in Go with Cobra. Use for commands, flags, help, prompts, plans, output contracts, completion, and project-aware CLI behavior. Do not use for operating a deployed business through the reserved dygo-cli operator skill.

日本語の概要は準備中です。原文の説明を表示しています。

hapyco/dygo162026年10月2日 更新

hapyco のスキルをすべて見る

このスキルの問題を報告する