<What this skill does>
日本語の概要は準備中です。原文の説明を表示しています。
Reviews GitHub Actions workflow diffs for script injection of untrusted input, pull_request_target with untrusted checkout, over-broad GITHUB_TOKEN permissions, and unpinned third-party actions.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Primary pattern: Reviewer Secondary patterns: Inversion Why: workflow の意味的なセキュリティ判断(権限の必要性・トリガーの用途)に集中し、決定論ツールが見ない文脈を検査する
このスキルは以下の条件がすべて満たされない限りNO_REVIEWを返す。
.github/workflows/ 配下の追加変更が含まれているゲート不成立時の出力: NO_REVIEW: gha-workflow-security — workflow の変更なし
./.github/actions/...、自 org reusable workflow)はピン留め不要とする運用が一般的。minor 以下に留める。actions/* 公式 action の tag 運用は third-party より低リスク。minor 扱い。if: 条件式内の式展開、github.event.*.number / github.sha / github.actor 等の数値・制約付きフィールドは原則安全。pull_request_target は安全パターン。github.event.issue.title/.body、pull_request.title/.body/.head.ref、comment.body、commits.*.message、github.head_ref 等)を run: に直接式展開しない。env: 経由で変数化する。pull_request_target / issue_comment / workflow_run で head.sha / head.ref を checkout して PR 由来コードを実行しない(secrets + write 権限の文脈での RCE)。permissions は top-level を contents: read にし、write は必要な job 単位で昇格する(write-all を避ける)。<file>:<line> で差分に紐づけ、出典(securitylab.github.com / docs.github.com の secure-use)を 1 行で添える。run: 直挿し / pull_request_target + head checkout = critical、permissions 過剰 / public self-hosted = major、tag ピン / persist-credentials = minor。コメントは日本語で返す。
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
<What this skill does>
日本語の概要は準備中です。原文の説明を表示しています。
画像・ボタン・フォーム要素に適切なアクセシブルネームがあるか確認する。
Ensure ADRs capture context, decision, alternatives, tradeoffs, and follow-ups in a way that prevents future drift.
日本語の概要は準備中です。原文の説明を表示しています。
敵対的分析手法を統合したレビューの entry skill。認知バイアス対策の3手法 (Pre-mortem / War Game / Logic Torturing)と、宣言・主張と実態の乖離を突く claim-vs-actual 検出3パターン(Self-Contradiction / Refactor-Claim Audit / Cross-File Leakage)へルーティングし、通常のレビューでは見えない設計の盲点・ 防御の穴・論理の弱点・宣言と実装のズレを可視化する。
Review changes to the Agent Skills import/export bridge for path safety, round-trip fidelity, and validation correctness.
日本語の概要は準備中です。原文の説明を表示しています。
Checks whether AI-assisted work defines review criteria, accessible context, explicit review loop, human judgment boundary, and feedback capture before delegating to an agent.
日本語の概要は準備中です。原文の説明を表示しています。