本文へ移動
cccskills
無料GitHub で公開

security

Standalone security audit on audit tier. Focused review of a feature or file set. Produces severity-ranked findings and remediation tasks for worker-tier /resume.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security Auditor

Standalone audit. Always use audit-tier model. The user selects the tier; do not recommend vendors. Follow AGENTS.md communication + reference-doc rules (grep docs, never load whole mirrors).

Inputs

Scope from user or .agents/tasks/ task file. Locate every in-scope surface with graft first (bin/harness graft ask "<surface>" --source / bin/harness graft grep "<symbol>" / bin/harness graft callers <sym> --depth 2) so nothing related is missed, then each in-scope file read in full.

Checklists

.agents/docs/audit-checklists.md — grep the Security category (shared with qa/reviewer).

Audit coverage

Input sanitization · nonces · REST permissions · output escaping · $wpdb->prepare() · capabilities · multisite · ABSPATH guards · no eval/unserialize on user data · SSRF-safe remote calls.

Deliverable

.agents/notes/YYYY-MM-DD-security-<slug>.md, frontmatter model_tier: audit. Sections: Scope · Summary · Findings · Remediation tasks · Coverage gaps. Finding format: severity, file, surface, description, exploit scenario, remediation. Remediation tasks atomic and executable via worker tier /resume.

Project-specific surfaces

Everything above is the baseline. Surfaces particular to this project — its own REST namespaces, capabilities, custom tables, licensing, updater endpoints — are listed in AGENTS.md, and they are in scope for every audit. If AGENTS.md names a surface this checklist does not, it still gets audited.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

architect

無料

Full dev cycle. Planning tier for clarify and plan; worker tier after approval for autonomous execution, tiered lint, thread rotation, and feedback fixes. Start every change here.

日本語の概要は準備中です。原文の説明を表示しています。

quentin-ld/zenpress92026年10月9日 更新

Writing documents an agent consumes. Use when creating or editing a skill, an AGENTS.md, a README section, a docblock, or any file reached by a pointer.

日本語の概要は準備中です。原文の説明を表示しています。

quentin-ld/zenpress92026年10月9日 更新

graft

無料

This repo is indexed by graft/. For ANY task here, whether understanding how something works, finding where code lives, tracing what calls a symbol or what a change breaks, or scoping an edit, get your context from the graph before grepping or reading source files. Every command runs through `bin/harness graft`.

日本語の概要は準備中です。原文の説明を表示しています。

quentin-ld/zenpress92026年10月9日 更新

grilling

無料

Interviewing the owner to a shared understanding before any work starts. Use when a plan, a decision or an idea needs stress-testing, or when the owner asks to be grilled, interviewed or questioned about one.

日本語の概要は準備中です。原文の説明を表示しています。

quentin-ld/zenpress92026年10月9日 更新

Removing AI tells from French prose without lowering its register. Use when rewriting or reviewing French text — a reply to the owner, a `.po` target, a French post — that reads like a machine wrote it.

日本語の概要は準備中です。原文の説明を表示しています。

quentin-ld/zenpress92026年10月9日 更新

humanizer

無料

Editing English prose that reads as machine-written. Use when reviewing or rewriting a draft for AI tells — a README, a changelog entry, a comment, a user-facing string, a review. French text is `humaniseur-fr`.

日本語の概要は準備中です。原文の説明を表示しています。

quentin-ld/zenpress92026年10月9日 更新

quentin-ld のスキルをすべて見る

このスキルの問題を報告する