本文へ移動
cccskills
無料GitHub で公開

owasp-infrastructure

OWASP Infrastructure Top 10 knowledge base for identifying, assessing, and remediating internal IT infrastructure security risks.

インストール方法を見る

含まれるファイル(12)

  • SKILL.md2.2 KB
  • references/00-vulnerability-index.md2.8 KB
  • references/01-outdated-software.md3.8 KB
  • references/02-insufficient-threat-detection.md4.5 KB
  • references/03-insecure-configurations.md3.9 KB
  • references/04-insecure-resource-user-management.md4.7 KB
  • references/05-insecure-use-of-cryptography.md4.6 KB
  • references/06-insecure-network-access-management.md4.6 KB
  • references/07-insecure-authentication-default-credentials.md3.7 KB
  • references/08-information-leakage.md3.9 KB
  • references/09-insecure-access-resources-management-components.md4.5 KB
  • references/10-insufficient-asset-management-documentation.md4.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

OWASP Infrastructure Top 10 — Skill Entry

This SKILL.md is the entrypoint for the OWASP Infrastructure Top 10 skill.

The skill encodes the OWASP Infrastructure Security Top 10 (2024) as structured, machine-readable references that an agent can query to identify, assess, and remediate infrastructure security risks.

Normative references (Infrastructure Top 10)

  1. 00 Vulnerability Index
  2. 01 Outdated Software
  3. 02 Insufficient Threat Detection
  4. 03 Insecure Configurations
  5. 04 Insecure Resource and User Management
  6. 05 Insecure Use of Cryptography
  7. 06 Insecure Network Access Management
  8. 07 Insecure Authentication Methods and Default Credentials
  9. 08 Information Leakage
  10. 09 Insecure Access to Resources and Management Components
  11. 10 Insufficient Asset Management and Documentation

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the Infrastructure Top 10 normative documents.
    • 00-vulnerability-index.md — index of all vulnerability identifiers, categories, and cross-references.
    • 01 through 10 — one document per vulnerability aligned with OWASP Infrastructure Security numbering.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Consolidated accessibility skill entrypoint for WCAG 2.2, ARIA Authoring Practices, cognitive accessibility, Section 508, EN 301 549, design intent verification, and the Accessibility Planner workflow.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5182026年10月11日 更新

Build, refresh, report, or probe an accessibility coverage matrix across criteria, surfaces, and evidence methods. Use when assessing coverage with the accessibility runtime harness and generated evidence bundle.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5182026年10月11日 更新

Authoring skill for Architecture Decision Records (ADRs) supporting capture, from-planner-handoff, and adopt-template entry modes with selectable Y-Statement or MADR v4.0.0 output templates, supersession lineage, and ASR trigger evaluation.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5182026年10月11日 更新

Authoring conventions for exploratory data analysis notebooks and analytical dashboards, covering section sequence, visualization selection, scale thresholds, caching and state, and dashboard validation budgets. Use when composing or reviewing an EDA notebook, an analytical dashboard, or a dashboard test pass.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5182026年10月11日 更新

Architecture diagram authoring for cloud infrastructure and declared data catalogs. Use when rendering Azure IaC or DS_CATALOG_V1 relationships as caller-selected ASCII or Mermaid diagrams.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5182026年10月11日 更新

Create a durable Architecture Review Record from a confirmed System Architecture Reviewer scope, evidence, pillar analysis, trade-offs, and dispositions

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5182026年10月11日 更新

microsoft のスキルをすべて見る

このスキルの問題を報告する