Use when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases
日本語の概要は準備中です。原文の説明を表示しています。
Use when you add or change an endpoint, an auth check, a query by id, an outbound call to a user-supplied URL, file handling, or anything touching credentials — the OWASP API Top 10 (2023) as concrete Go and Java checks
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
The OWASP API Security Top 10 (2023 edition, still current) orders API risk by how often it actually bites in production. This skill maps each category to a concrete Go/Java check instead of a paragraph of theory — see https://owasp.org/API-Security/editions/2023/en/0x11-t10/ for the source list.
Core principle: the most common API vulnerability is a lookup by id with no ownership check. Assume every id in a URL or body is adversarial.
The #1 API risk. A lookup that trusts the id alone instead of scoping it to the caller.
// ❌ anyone who guesses/enumerates an id can read or modify it
task, err := repo.Get(ctx, taskID)
// ✅ scoped to the caller/tenant exactly like its neighbours
task, err := repo.GetForOwner(ctx, taskID, ownerIDFromAuth(ctx))
Answer "not yours" the same way the endpoint's neighbours do — usually 404 (don't reveal existence to a non-owner) unless the repo already standardizes on 403. Test it: a second, different authenticated user requesting the first user's object must get the not-yours response, not the object.
api := app.Group("/api", authMW), never a bare app.Post outside it; Spring: match the route in the existing SecurityFilterChain; Quarkus: @RolesAllowed/@Authenticated).crypto/subtle.ConstantTimeCompare, never == (timing attack on string comparison).crypto/rand, never math/rand.role, owner_id, is_admin, etc. If the DTO doesn't have the field, the client can't set it.password_hash, no internal ids, no other users' data riding along in a list response. Go: unexported fields or explicit response structs, never json:"-" as the only defense on a type that's also bound from requests. Java: a dedicated response record, never the JPA entity.fiber.Config{BodyLimit: ...} (default 4 MB) or http.MaxBytesReader — don't rely on the framework default alone for upload endpoints.Admin/privileged routes are behind an explicit role check, not just "authenticated" — verify the route's authorization matches its actual privilege level, not just that some auth middleware ran.
Rate-limit a sensitive flow (password reset, bulk export, payment) the same way its neighbours already do; don't ship a new sensitive endpoint with no rate limit when similar ones have one.
Any endpoint that fetches a user-supplied URL (webhooks, image-by-URL, link previews):
https only, usually) and, where feasible, the host.127.0.0.0/8, 10.0.0.0/8, 169.254.0.0/16, ::1, etc.) before connecting.http.Client{CheckRedirect: func(...) error { return http.ErrUseLastResponse }}.Access-Control-Allow-Origin: * combined with Access-Control-Allow-Credentials: true.Keep the OpenAPI document in sync (api-contract-openapi) — an undocumented or "quietly removed" endpoint is still reachable until it's actually gone.
Validate and size-limit third-party API responses before trusting them; apply the same timeout/retry discipline to outbound calls as to your own endpoints (resilient-io-and-jobs).
exec.Command(name, arg1, arg2) with separate arguments, never a shell string built from user input.os.Root (Go ≥1.24) when serving files from a directory by user-supplied name.go vet ./...go run golang.org/x/vuln/cmd/govulncheck@latest ./... — does not modify go.mod, safe to run anytime.go test -race ./...WHERE id = $1 with no second predicate on an endpoint scoped to a caller.http.Get(userSuppliedURL) with no scheme/host check beforehand.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases
日本語の概要は準備中です。原文の説明を表示しています。
Use when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level authorization, mass assignment and tenant scoping
日本語の概要は準備中です。原文の説明を表示しています。
Use on every UI change - semantic HTML, labels for controls, keyboard-navigable dialogs/menus, visible focus, and never color as the only signal
日本語の概要は準備中です。原文の説明を表示しています。
Use when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task
日本語の概要は準備中です。原文の説明を表示しています。
How to work a task returned with review, QA or UAT findings. Use when a task is in need_revision or PR review comments are in your context.
日本語の概要は準備中です。原文の説明を表示しています。
Use when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation
日本語の概要は準備中です。原文の説明を表示しています。