Use for AST search and codemods. Triggers: ast-grep, sg, function/call/class/import, empty catch, missing await, YAML rules.
日本語の概要は準備中です。原文の説明を表示しています。
Use for security and trust boundaries. Triggers: auth, secrets, XSS, CSRF, SQL injection, JWT, OAuth, OWASP, PII, uploads, payments, supply chain, CI integrity, agent security, threat model.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Treat security as a build constraint, not a cleanup step.
This skill is the authoritative source for authentication, authorization, input validation, secrets, headers, rate limiting, supply-chain security policy and evidence requirements, PII handling, and agentic AI safety.
Validation ownership split: this skill owns what the validation schema enforces (content/policy); placement (boundary-only validation) is owned by dev-architecture §4.
dev-backend delegates here for policy and verification depth.
dev-frontend remains responsible for UI implementation, but frontend security touchpoints such as CSP compliance, CORS behavior, XSS prevention, and dependency auditing are defined here.
This skill activates by change-surface whenever code crosses a trust boundary or changes the blast radius of a failure.
Before security work, read dev for classification, fast paths, rule authority, family invariants, verification, and safety; current CVEs/public evidence follow its Conditional Routes.
Rule (SEC-THREAT-01): Security-sensitive changes start with a repo-grounded threat model, then controls. Do not begin with a checklist and assume it is sufficient.
Before implementation, read the threat-model procedure; before completion, read the applicable security review and must-pass addenda.
| Condition | Reference |
|---|---|
| Before security-sensitive implementation | Threat model |
| Input validation, login/session/token/OAuth, authorization, or sensitive flows | Access controls |
| Secrets, headers/CSP/CORS, or abuse/rate limits | Runtime controls |
| AI-suggested dependencies, security claims/static checks, agent configuration, MCP, or sandboxing | Agent integrity and scans (SEC-ANTIPATTERN-01) |
| Security-sensitive completion, deploy/release, uploads/payments/logging/PII, or control ownership | Security review and ownership matrix, ASVS checklist |
| Any security-sensitive code | OWASP Top 10 |
| JS/TS, Python, SQL, or Go security work | Language quirks |
| Before claiming code is secure | Static analysis recipes |
| Tool-using agents or prompt-driven flows | Agentic AI |
| LLMs, RAG, or tool/agent output | LLM supply chain |
| Add/vet MCP servers | MCP supply chain |
| Dependency audit or release integrity | SBOM and signing |
| Domain implementation, CI credential delivery/signing, frontend, testing, review, RCA, scaffolding, or pipelines | Companion owners; load the domain skill too |
Read only the references relevant to the current task. A small CSS change needs no OWASP reference. Auth, data access, secrets, file uploads, webhooks, or incident response changes do.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use for AST search and codemods. Triggers: ast-grep, sg, function/call/class/import, empty catch, missing await, YAML rules.
日本語の概要は準備中です。原文の説明を表示しています。
Use for coding, PR delivery, scaffolding and QA. Triggers: develop, fix, refactor, test, review, docs, browse, stacked PR, 개발, 수정, 검토, 스택 PR.
日本語の概要は準備中です。原文の説明を表示しています。
Use for module boundaries and dependencies. Triggers: circular import, coupling, barrel, re-export, validation placement, 모듈 경계, 순환 참조.
日本語の概要は準備中です。原文の説明を表示しています。
Use for APIs, servers and app databases. Triggers: REST, GraphQL, migration, query optimization, middleware, caching, queues, 백엔드, API 작업, 마이그레이션, 쿼리 최적화.
日本語の概要は準備中です。原文の説明を表示しています。
Use for code/PR/diff review and refactor audits. Triggers: review this, before merge, antipattern, 리뷰, 코드 리뷰, 머지 전에 확인.
日本語の概要は準備中です。原文の説明を表示しています。
Use for analytics and data pipelines. Triggers: ETL, ELT, data quality, SQL optimization, schema drift, backfill, 데이터 파이프라인, 데이터 품질, 백필.
日本語の概要は準備中です。原文の説明を表示しています。