本文へ移動
cccskills
無料GitHub で公開

cxc-dev-security

Use for security and trust boundaries. Triggers: auth, secrets, XSS, CSRF, SQL injection, JWT, OAuth, OWASP, PII, uploads, payments, supply chain, CI integrity, agent security, threat model.

インストール方法を見る

含まれるファイル(16)

  • SKILL.md4.0 KB
  • agents/openai.yaml158 B
  • references/01-threat-model.md1.3 KB
  • references/02-access-controls.md3.3 KB
  • references/03-runtime-controls.md3.6 KB
  • references/04-agent-integrity.md3.3 KB
  • references/05-security-review.md4.9 KB
  • references/agent-skill-integrity.md2.2 KB
  • references/agentic-ai-security.md6.0 KB
  • references/asvs-checklist.md3.1 KB
  • references/language-quirks.md5.0 KB
  • references/llm-supply-chain.md7.4 KB
  • references/mcp-supply-chain.md6.9 KB
  • references/owasp-top10.md11.1 KB
  • references/static-analysis.md4.8 KB
  • references/supply-chain-sbom.md6.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Dev-Security — Production Security Hardening

Treat security as a build constraint, not a cleanup step. This skill is the authoritative source for authentication, authorization, input validation, secrets, headers, rate limiting, supply-chain security policy and evidence requirements, PII handling, and agentic AI safety. Validation ownership split: this skill owns what the validation schema enforces (content/policy); placement (boundary-only validation) is owned by dev-architecture §4. dev-backend delegates here for policy and verification depth. dev-frontend remains responsible for UI implementation, but frontend security touchpoints such as CSP compliance, CORS behavior, XSS prevention, and dependency auditing are defined here. This skill activates by change-surface whenever code crosses a trust boundary or changes the blast radius of a failure.

Before security work, read dev for classification, fast paths, rule authority, family invariants, verification, and safety; current CVEs/public evidence follow its Conditional Routes.

Threat Model First

Rule (SEC-THREAT-01): Security-sensitive changes start with a repo-grounded threat model, then controls. Do not begin with a checklist and assume it is sufficient.

Before implementation, read the threat-model procedure; before completion, read the applicable security review and must-pass addenda.

Modular References

ConditionReference
Before security-sensitive implementationThreat model
Input validation, login/session/token/OAuth, authorization, or sensitive flowsAccess controls
Secrets, headers/CSP/CORS, or abuse/rate limitsRuntime controls
AI-suggested dependencies, security claims/static checks, agent configuration, MCP, or sandboxingAgent integrity and scans (SEC-ANTIPATTERN-01)
Security-sensitive completion, deploy/release, uploads/payments/logging/PII, or control ownershipSecurity review and ownership matrix, ASVS checklist
Any security-sensitive codeOWASP Top 10
JS/TS, Python, SQL, or Go security workLanguage quirks
Before claiming code is secureStatic analysis recipes
Tool-using agents or prompt-driven flowsAgentic AI
LLMs, RAG, or tool/agent outputLLM supply chain
Add/vet MCP serversMCP supply chain
Dependency audit or release integritySBOM and signing
Domain implementation, CI credential delivery/signing, frontend, testing, review, RCA, scaffolding, or pipelinesCompanion owners; load the domain skill too

Read only the references relevant to the current task. A small CSS change needs no OWASP reference. Auth, data access, secrets, file uploads, webhooks, or incident response changes do.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use for AST search and codemods. Triggers: ast-grep, sg, function/call/class/import, empty catch, missing await, YAML rules.

日本語の概要は準備中です。原文の説明を表示しています。

lidge-jun/codexclaw452026年10月9日 更新

cxc-dev

無料

Use for coding, PR delivery, scaffolding and QA. Triggers: develop, fix, refactor, test, review, docs, browse, stacked PR, 개발, 수정, 검토, 스택 PR.

日本語の概要は準備中です。原文の説明を表示しています。

lidge-jun/codexclaw452026年10月9日 更新

Use for module boundaries and dependencies. Triggers: circular import, coupling, barrel, re-export, validation placement, 모듈 경계, 순환 참조.

日本語の概要は準備中です。原文の説明を表示しています。

lidge-jun/codexclaw452026年10月9日 更新

Use for APIs, servers and app databases. Triggers: REST, GraphQL, migration, query optimization, middleware, caching, queues, 백엔드, API 작업, 마이그레이션, 쿼리 최적화.

日本語の概要は準備中です。原文の説明を表示しています。

lidge-jun/codexclaw452026年10月9日 更新

Use for code/PR/diff review and refactor audits. Triggers: review this, before merge, antipattern, 리뷰, 코드 리뷰, 머지 전에 확인.

日本語の概要は準備中です。原文の説明を表示しています。

lidge-jun/codexclaw452026年10月9日 更新

Use for analytics and data pipelines. Triggers: ETL, ELT, data quality, SQL optimization, schema drift, backfill, 데이터 파이프라인, 데이터 품질, 백필.

日本語の概要は準備中です。原文の説明を表示しています。

lidge-jun/codexclaw452026年10月9日 更新

lidge-jun のスキルをすべて見る

このスキルの問題を報告する