Validate WCAG 2.1 Level AA compliance and accessibility best practices. Use when performing accessibility audits and WCAG certification.
日本語の概要は準備中です。原文の説明を表示しています。
Run security verification — SAST pattern scanning, DAST against a running app, OWASP Top 10 compliance, CVSS assessment, and adversarial code audit. Use before commit/push or when checking code for vulnerabilities. Trigger on "security scan", "is this vulnerable", "OWASP check", "security verify", "scan for vulnerabilities".
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Run security verification checks: pattern scanning, OWASP compliance, and vulnerability assessment.
/security-verify # Default: run scan mode
/security-verify scan [path] # Pattern-based security scanning (SAST)
/security-verify dast <url> # Dynamic testing against running app (DAST)
/security-verify owasp # OWASP Top 10 compliance check
/security-verify assess # Vulnerability CVSS scoring + remediation
/security-verify audit # Adversarial logic-level code review (CWE + CVSS + exploit)
/security-verify full # scan + audit combined (use for /health or manual deep check)
Run pattern-based security scanning against the codebase.
Run the scanner script against target path:
# Full scan — manual usage, scans entire directory
bash "$HOME/.claude/skills/security-verify/lib/scanner-runner.sh" "${TARGET_PATH:-.}"
# Staged-only scan — pre-commit context, scans only git-staged files
bash "$HOME/.claude/skills/security-verify/lib/scanner-runner.sh" --staged
Use --staged when invoked from /pre-commit to limit scope to the current commit's changes.
Full-path scanning is for standalone audits.
Review findings, assess severity, and provide fix recommendations.
After pattern scan, check for known CVEs:
# Use filtered requirements file to audit only public packages.
if command -v uv &>/dev/null && ([ -f uv.lock ] || [ -f pyproject.toml ]); then
if uv export --no-hashes --frozen > /tmp/raw-reqs.txt 2>/dev/null; then :; else
uv run pip freeze > /tmp/raw-reqs.txt 2>/dev/null || true
fi
uv run --with pip-audit pip-audit -r /tmp/pip-audit-reqs.txt 2>/dev/null || true
elif command -v pip-audit &>/dev/null; then
pip-audit --local 2>/dev/null || true
else
echo "pip-audit not installed"
fi
npm audit --production 2>/dev/null || echo "No package.json"
Generate a markdown report with severity counts, findings with file:line references, and fix recommendations.
Dynamic Application Security Testing against a running application. Tests live HTTP endpoints rather than reading source files.
curl (always available, zero extra deps)nuclei (optional, for deeper template-based scanning): brew install nucleipython3 (required if using --nuclei, for JSON parsing)Tier 1 — curl-based (always runs):
| # | Category | What it checks | Severity |
|---|---|---|---|
| 1 | HTTP Security Headers | HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy | LOW–HIGH |
| 2 | Cookie Security | Secure, HttpOnly, SameSite flags | MEDIUM–HIGH |
| 3 | CORS | Wildcard origins, evil origin reflection | HIGH–CRITICAL |
| 4 | TLS/SSL | Protocol version (≥TLS 1.2), cert expiry | MEDIUM–HIGH |
| 5 | Information Disclosure | Server version header, X-Powered-By, exposed paths (/.env, /.git, /debug, /admin) | LOW–HIGH |
| 6 | Open Redirects | Redirect parameter injection test | HIGH |
| 7 | HTTP Methods | TRACE enabled, OPTIONS enumeration | LOW |
Tier 2 — nuclei (when installed):
| # | Category | What it checks |
|---|---|---|
| 8 | CVE patterns | Known vulnerability templates for http/, ssl/, misconfiguration/ |
| 9 | Auth bypass | Default credentials, auth misconfiguration templates |
# Tier 1 only (curl-based, zero deps)
bash "$HOME/.claude/skills/security-verify/lib/dast-runner.sh" "http://localhost:8000"
# Tier 1 + Tier 2 (requires nuclei installed)
bash "$HOME/.claude/skills/security-verify/lib/dast-runner.sh" "http://localhost:8000" --nuclei
# Custom per-check timeout (default: 5s)
bash "$HOME/.claude/skills/security-verify/lib/dast-runner.sh" "http://localhost:8000" --timeout 3
Findings are labelled to distinguish confidence level:
ACTIVE — Confirmed by server response. Remediate now. (e.g., server returned missing CSP header)POTENTIAL — Suspicious behavior requiring manual verification. (e.g., redirect parameter exists but may validate destinations)Exit codes: 0 = no critical/high findings, 1 = critical/high found, 2 = URL unreachable.
SAST (scan) | DAST (dast) | |
|---|---|---|
| Input | Source files | Running server |
| Finds | Potential vulnerabilities | Active misconfigurations |
| Deps | None (bash grep) | curl + optional nuclei |
| When | Any time | App must be running |
| Pre-commit | Yes (default) | Optional (--dast <url>) |
Systematic OWASP Top 10 2021 compliance verification.
| ID | Category | Key Checks |
|---|---|---|
| A01 | Broken Access Control | Authorization on every endpoint, no IDOR, CORS config |
| A02 | Cryptographic Failures | TLS 1.2+, Argon2/bcrypt hashing, no weak algorithms |
| A03 | Injection | Parameterized SQL, safe subprocess usage |
| A04 | Insecure Design | Rate limiting, account lockout, threat model |
| A05 | Security Misconfiguration | Debug off, security headers, no defaults |
| A06 | Vulnerable Components | No critical CVEs, deps up to date |
| A07 | Auth Failures | Strong passwords, session timeout, MFA |
| A08 | Integrity Failures | Safe deserialization, yaml.safe_load |
| A09 | Logging Failures | Auth events logged, no PII in logs |
| A10 | SSRF | URL validation, private IPs blocked |
For each category:
Deep vulnerability analysis with CVSS scoring and remediation strategies.
| Score | Severity |
|---|---|
| 0.0 | None |
| 0.1-3.9 | Low |
| 4.0-6.9 | Medium |
| 7.0-8.9 | High |
| 9.0-10.0 | Critical |
| Priority | SLA | Criteria |
|---|---|---|
| P0 | 24 hours | Critical+Easy or High+Easy |
| P1 | 7 days | Critical+Hard or High+Medium |
| P2 | 30 days | Medium or High+Hard |
| P3 | 90 days | Low severity |
Adversarial logic-level code review. Reads code deeply to find vulnerabilities that grep-based SAST misses — auth bypass, IDOR, race conditions, session fixation, missing ownership checks.
Run as a focused subagent (spawn fresh context to avoid polluting the main conversation with large finding sets). When invoked, spawn an Agent with subagent_type: general-purpose, model: sonnet, and pass the target scope.
Assume the code is hostile until proven otherwise. Find vulnerabilities a real attacker would exploit. "If you can't write the exploit scenario in one sentence, downgrade severity."
text(), op.execute(), f-strings in queries). Alembic rule: each op.execute() must be a single statement — two statements separated by ; fail on asyncpg.Depends(get_current_user) or equivalent. Routes missing auth on sensitive operations (write, delete, admin functions) are CRITICAL.General checks (adapt to target):
SameSite set?yaml.load() without Loader=yaml.SafeLoader; no unsafe deserialization of untrusted binary dataALLOWED_HOSTS not *, verbose error messages suppressedEach finding must include:
SEC-NNN (sequential)CWE-XXX — Name (e.g., CWE-89 — SQL Injection)CRITICAL / HIGH / MEDIUM / LOW with CVSS-ish reasoningfile.py:line/health security (scan passes but audit finds logic flaws)NOT for pre-commit — use scan there. audit takes minutes; scan takes seconds.
Runs scan + audit sequentially. Use for /health full or when you want complete security coverage in one command.
1. Run scan (SAST grep patterns + dependency audit)
2. Run audit (adversarial logic-level review)
3. Merge findings into unified report ordered by severity
Recommended security workflow:
/security [mode] — get implementation guidance/security-verify scan — SAST: fast grep-based check (seconds, runs in pre-commit)/security-verify audit — adversarial logic review (minutes, run manually or via /health)/security-verify dast <url> — DAST: test running app (staging/local)/security-verify owasp — verify OWASP Top 10 compliance/security-verify assess — CVSS score and prioritize findings/security-verify full — scan + audit combined (use for /health full)/security-verify scan is called by /pre-commit automatically. /security-verify dast is optional — use --dast <url> with /pre-commit when a local dev server is running. /security-verify audit and full are called by /health security and /health full.
.s/.n AST attributes; bandit ≤1.8.x crashes on every file and silently reports 0 findings. Use python3.13 -m bandit (bandit 1.9.4 installed there).scanner-runner.sh --staged requires bash 4+ (mapfile); macOS ships bash 3.2 — use full scan mode instead of --staged on macOS.projects/ (JSONL session transcripts), .archive/, and .venv/ — assess as FP, do not report as real issues.pnpm audit --audit-level=critical); HIGH vulns in transitive/dev deps (ReDoS in build tools, prototype pollution in bundlers) are noise, not runtime-exploitable — surface them informationally but do not block.pip-audit runs with no severity threshold (all vulns surfaced + gated) — different ecosystem from JS, more conservative CVE scoring, smaller dep trees.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Validate WCAG 2.1 Level AA compliance and accessibility best practices. Use when performing accessibility audits and WCAG certification.
日本語の概要は準備中です。原文の説明を表示しています。
Analyze feature requirements, dependencies, and security considerations. Use when starting feature implementation from GitHub issues to understand scope, technical feasibility, and risks.
日本語の概要は準備中です。原文の説明を表示しています。
Run SQL queries against psql, BigQuery, or MySQL from the terminal, including natural-language-to-SQL and schema exploration. Use when analyzing data, inspecting DB state, or debugging tables. Trigger on "query the database", "SQL", "show me data from", "explore table".
日本語の概要は準備中です。原文の説明を表示しています。
Design REST APIs or function contracts with clear request/response specifications, error handling patterns, authentication strategies, and comprehensive documentation.
日本語の概要は準備中です。原文の説明を表示しています。
Generate comprehensive API endpoint tests for REST and GraphQL APIs. Creates tests for all HTTP methods, status codes, authentication, and validation.
日本語の概要は準備中です。原文の説明を表示しています。
Design component architecture and module structure using established architectural patterns for clean, maintainable, and scalable systems.
日本語の概要は準備中です。原文の説明を表示しています。