Skill for adding or updating educational algorithm guides, ensuring consistent patterns and simple explanations suitable for an 8-year-old.
日本語の概要は準備中です。原文の説明を表示しています。
Scan the repository for hardcoded secrets, exposed API keys, insecure network configurations, and vulnerable dependencies. Use when the user asks for a security audit, secret detection, credential scan, vulnerability check, or wants to find leaked tokens in the codebase.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Detect hardcoded secrets, insecure network patterns, and vulnerable dependencies in the repository using integrated scanning scripts.
Identify whether to scan the entire repo or specific subdirectories based on the user request.
bash .agents/skills/security/scripts/main_scan.sh
The scan checks three categories:
AKIA, sk-, ghp_, Bearer)http:// where https:// is expected)npm audit for vulnerable packagesIf the main script is unavailable, run checks manually:
# Secret patterns
grep -rn "AKIA\|sk-\|ghp_\|password\s*=\|api_key\s*=" --include="*.ts" --include="*.js" --include="*.env" .
# Insecure protocols
grep -rn "http://" --include="*.ts" --include="*.js" . | grep -v localhost
# Dependency vulnerabilities
npm audit --json
Organize results by severity:
| Severity | Examples |
|---|---|
| High | Exposed API keys, hardcoded passwords, leaked tokens |
| Medium | Insecure protocol usage, hardcoded IPs in production code |
| Low | Outdated dependencies with low-severity CVEs |
Provide actionable remediation for each finding (e.g., "Rotate this key and move to environment variable", "Upgrade package X to version Y").
CRITICAL: Never display a full secret in the output. Mask all sensitive values (e.g., AKIA...XXXX, sk-...abcd). Warn the user about the risk of committing secrets to version control.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Skill for adding or updating educational algorithm guides, ensuring consistent patterns and simple explanations suitable for an 8-year-old.
日本語の概要は準備中です。原文の説明を表示しています。
Install and configure PostHog analytics SDK in React Native applications, including event tracking, feature flags, user identification, and error tracking. Use when the user needs to add PostHog analytics, session recording, or feature flags to a React Native app.
日本語の概要は準備中です。原文の説明を表示しています。
PostHog integration for React Router v6 applications
日本語の概要は準備中です。原文の説明を表示しています。
Develop and extend the RulCode technical interview preparation platform built with React, Vite, TypeScript, and Supabase. Use when adding new algorithm problems, building visualization components, implementing DSA topic pages, updating the problem editor, or modifying the interview preparation UI.
日本語の概要は準備中です。原文の説明を表示しています。
Skill for adding or updating system design guides tailored for college students and beginners, using simple analogies and no simulations.
日本語の概要は準備中です。原文の説明を表示しています。
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
日本語の概要は準備中です。原文の説明を表示しています。