本文へ移動
cccskills
無料GitHub で公開

security

Stack-specific security implementation guidance (backend, frontend, database, infrastructure, operations) with auto-detection from your changes. Use when implementing a feature securely or hardening code as you write it. Trigger on "how do I secure this", "security best practices", "is this secure", "harden this". For scanning existing code use /security-verify.

インストール方法を見る

含まれるファイル(13)

  • SKILL.md4.8 KB
  • templates/backend/patterns.md2.2 KB
  • templates/backend/summary.md1.0 KB
  • templates/checklist.md3.8 KB
  • templates/database/patterns.md2.0 KB
  • templates/database/summary.md1.0 KB
  • templates/frontend/patterns.md2.0 KB
  • templates/frontend/summary.md1.1 KB
  • templates/infrastructure/patterns.md2.0 KB
  • templates/infrastructure/summary.md1.1 KB
  • templates/matrix.md7.4 KB
  • templates/operations/patterns.md2.2 KB
  • templates/operations/summary.md1.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security — Implementation SOPs

Unified security guidance for your stack. Auto-detects context from edited files or accepts explicit mode.

Usage

/security                     # Auto-detect stack from git changes
/security backend             # Explicit: FastAPI + SQLAlchemy + Redis
/security frontend            # Explicit: Jinja2 + HTMX + TypeScript/Vite
/security database            # Explicit: PostgreSQL + pgvector + Redis
/security infrastructure      # Explicit: Docker + Nginx + Cloudflare
/security operations          # Explicit: Deployment + secrets + monitoring
/security matrix              # Cross-reference matrix (L1/L2/L3)
/security checklist           # L1 essential pre-deployment checklist

Workflow

Step 1: Determine Context

Parse $ARGUMENTS for explicit mode. If no arguments provided, detect context:

DETECTED=$(bash "$HOME/.claude/skills/security/lib/context-detector.sh")

Step 2: Show Relevant Guidance

Based on detected or explicit mode, use progressive disclosure:

Level 1 — Summary (default, ~10 lines): Show the summary template for the detected stack. This is the entry point.

Level 2 — Patterns (on request, ~50 lines): When user asks for more detail, patterns, or "Don't/Do/Best" examples, show the patterns template.

Level 3 — Full SOP (on request, ~500-1100 lines): When user asks for the complete SOP, read the full source skill file.

Step 3: Handle Multiple Stacks

If context-detector returns multiple stacks (e.g., "backend,frontend"):

  • Show summary for each detected stack
  • Let user choose which to dive deeper into

Step 4: No Context Detected

If detection returns "none" and no explicit mode:

  • Show the matrix template as overview
  • List available modes for user to choose

Template Locations

Summary Templates (~10 lines each)

ModeFile
backend~/.claude/skills/security/templates/backend/summary.md
frontend~/.claude/skills/security/templates/frontend/summary.md
database~/.claude/skills/security/templates/database/summary.md
infrastructure~/.claude/skills/security/templates/infrastructure/summary.md
operations~/.claude/skills/security/templates/operations/summary.md

Patterns Templates (~50 lines each, Don't/Do/Best)

ModeFile
backend~/.claude/skills/security/templates/backend/patterns.md
frontend~/.claude/skills/security/templates/frontend/patterns.md
database~/.claude/skills/security/templates/database/patterns.md
infrastructure~/.claude/skills/security/templates/infrastructure/patterns.md
operations~/.claude/skills/security/templates/operations/patterns.md

Reference Templates

ModeFile
matrix~/.claude/skills/security/templates/matrix.md
checklist~/.claude/skills/security/templates/checklist.md

Progressive Disclosure Rules

  1. Always start with summary — don't dump 1,100 lines unprompted
  2. Read templates on demand — use the Read tool to load templates, don't memorize content
  3. User drives depth — "show patterns", "full SOP", "show me the code" trigger deeper levels
  4. Combine when relevant — if user edits both .py and Dockerfile, show both backend + infrastructure summaries

Examples

Auto-detected backend work:

User edited src/auth.py → context-detector returns "backend" → Read and show templates/backend/summary.md → User: "show me password hashing patterns" → Read and show templates/backend/patterns.md

Explicit infrastructure request:

User: /security infrastructure → Read and show templates/infrastructure/summary.md

No context, overview requested:

User: /security → context-detector returns "none" → Read and show templates/matrix.md

Pre-deployment check:

User: /security checklist → Read and show templates/checklist.md

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Validate WCAG 2.1 Level AA compliance and accessibility best practices. Use when performing accessibility audits and WCAG certification.

日本語の概要は準備中です。原文の説明を表示しています。

matteocervelli/llms252026年5月22日 更新

analysis

無料

Analyze feature requirements, dependencies, and security considerations. Use when starting feature implementation from GitHub issues to understand scope, technical feasibility, and risks.

日本語の概要は準備中です。原文の説明を表示しています。

matteocervelli/llms252026年5月22日 更新

analytics

無料

Run SQL queries against psql, BigQuery, or MySQL from the terminal, including natural-language-to-SQL and schema exploration. Use when analyzing data, inspecting DB state, or debugging tables. Trigger on "query the database", "SQL", "show me data from", "explore table".

日本語の概要は準備中です。原文の説明を表示しています。

matteocervelli/llms252026年5月22日 更新

Design REST APIs or function contracts with clear request/response specifications, error handling patterns, authentication strategies, and comprehensive documentation.

日本語の概要は準備中です。原文の説明を表示しています。

matteocervelli/llms252026年5月22日 更新

Generate comprehensive API endpoint tests for REST and GraphQL APIs. Creates tests for all HTTP methods, status codes, authentication, and validation.

日本語の概要は準備中です。原文の説明を表示しています。

matteocervelli/llms252026年5月22日 更新

Design component architecture and module structure using established architectural patterns for clean, maintainable, and scalable systems.

日本語の概要は準備中です。原文の説明を表示しています。

matteocervelli/llms252026年5月22日 更新

matteocervelli のスキルをすべて見る

このスキルの問題を報告する