本文へ移動
cccskills
無料GitHub で公開

audit-security

Use when asked to audit or harden security in this repo — e.g. "security audit", "auditoría de seguridad", "revisa la seguridad", "is this secure", "hardening", "vulnerabilities". Audits code, config, workflows, and secrets exposure. Covers injection, secrets, TLS, untrusted input, dependency risk, and CI supply-chain hygiene. Runs when the user asks about security, not just for code reviews.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md3.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security Audit

You audit like an attacker and a paranoid maintainer at once. You look for things that would actually get exploited or accidentally leak, not hypothetical theoretical attacks. Every finding is concrete, with evidence and a fix.

Steps

  1. Map the attack surface — what is public/trusted vs internal/input:
    • Code that accepts input (network ports, HTTP, files, URL params).
    • Code that executes things (shell, exec, subprocesses).
    • Anything that stores or reads credentials.
    • Anything deployed or published (workflows, web reader, PDF/EPUB builds).
  2. Scan mechanically first — run these and report raw hits:
    • Secrets: rg -ni '(password|secret|token|api[_-]?key|BEGIN (RSA|OPENSSH|EC) PRIVATE KEY|authorization|bearer)' <scope> — then triage each hit as real secret / placeholder / false positive.
    • Plain HTTP or weak TLS: rg -n 'http://' <scope> | rg -v 'http://localhost|https?://example'.
    • Injection points: rg -n 'exec\.Command|os/exec|eval\b|innerHTML|document\.write|sh -c' <scope>.
    • Unbounded reads: rg -n 'io\.ReadAll|ioutil\.ReadAll|make\(\[\]byte' <scope>.
  3. Audit per area:
    • Code — with the relevant review-* skill lens: bounds, injection, XSS, deserialization, path traversal, resource exhaustion.
    • Config/credentials — no secrets in code, config, workflows, or generated files; no {env:} interpolation exposing tokens to logs; .gitignore covers secrets; nothing secret committed (check git log for historical secrets if asked).
    • Network — TLS enforced where required, no hardcoded internal addresses, timeouts to prevent slowloris/hangs, ports bind to the right interfaces.
    • CI/CD supply chain — pinned action versions (not @main/@master), third-party actions audited, permissions: scoped to minimum, secrets only in the jobs that need them, no secrets echoed in logs, pull_request_target understood, artifact/release signing considered.
    • Dependencies — for dirs with a go.mod/package.json, note the policy: check for known-vulnerable deps if a scanner exists (govulncheck ./..., npm audit) and report, or state that the repo is stdlib-only.
  4. Report — severity-ranked, with the fix for each.

Severity guide

  • Critical — remotely exploitable, secrets exposed, code execution from untrusted input, supply-chain compromise.
  • High — exploitable with some precondition (auth-free endpoint, public port, unvalidated file path).
  • Medium — info disclosure, weak defaults, missing hardening.
  • Low — hygiene (log verbosity, error details leaking internals).

Output format

  1. Attack surface summary — the inputs/executors/secrets inventory.
  2. Mechanical scan results — raw hits, triaged.
  3. Findings — severity, file:line, exploit/what-would-go-wrong, fix as a code/config snippet.
  4. Clean bill — explicitly list what you checked and found safe.
  5. Commands run — the scanners and their output.

Rules: no fear-mongering — a finding must include the concrete path to harm; distinguish "placeholder/example" from real secrets; when asked to fix, apply edits and re-scan before reporting done.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use when asked to analyze a file, a directory, or the whole codebase to understand structure, architecture, dependencies, complexity, duplication, dead code, or technical debt — e.g. "analyze this", "análisis total", "explain this codebase", "mapa del código", "how does X work", "technical debt". Produces a complete, structured picture with verified commands, not guesses. Distinct from review-* skills (which judge quality); this skill explains and maps.

日本語の概要は準備中です。原文の説明を表示しています。

sazardev/networking-with-go582026年8月8日 更新

Use when reviewing the structure, ordering, coherence, and narrative flow of the book as a whole or across chapters. Checks chapter sequencing against the ID scheme, cross-references and forward hooks between chapters, README/index link integrity, exercise-to-chapter pairing, duplicate or contradictory content, and progression of difficulty. Best paired with a full-docs review rather than a single-chapter proofread.

日本語の概要は準備中です。原文の説明を表示しています。

sazardev/networking-with-go582026年8月8日 更新

Use when writing, expanding, rewriting, or drafting any chapter (.mdx) or Go exercise for this book. Encodes the authorial voice, the mdx-pdf-format rules, the ID/naming scheme, the zero-emoji rule, chapter/exercise pairing, and the "theory first, then code" pedagogy so new or edited content reads like the rest of the book and keeps the PDF compiling.

日本語の概要は準備中です。原文の説明を表示しています。

sazardev/networking-with-go582026年8月8日 更新

Use when brainstorming, evaluating ideas, designing architectures, writing technical plans, or choosing between approaches — e.g. "give me ideas", "ideas para", "diseña la arquitectura", "how should I structure this", "compare approaches", "plan". Turns vague ideas into concrete, prioritized, buildable designs with explicit tradeoffs. Use before writing code, not after.

日本語の概要は準備中です。原文の説明を表示しています。

sazardev/networking-with-go582026年8月8日 更新

Use when proofreading, copy-editing, or verifying English in any docs/**/*.mdx chapter or code comment in this repo. Catches grammar, punctuation, spelling, syntax, article/tense/agreement errors, wordiness, tone drift, and style inconsistencies, and rewrites text in the book's confident second-person voice without changing meaning or breaking the mdx/PDF format rules.

日本語の概要は準備中です。原文の説明を表示しています。

sazardev/networking-with-go582026年8月8日 更新

Use when reviewing, writing, or debugging Go code under exercises/part2/ (and matching embedded code in docs/part2/**/*.mdx). Thinks hard about correctness, idiomatic Go, error handling, resource cleanup, concurrency, and — crucially — what the tests would catch: edge cases, races, leaks, timeouts, and port conflicts. Knows the repo's module-mode quirk (GO111MODULE=off) and which dirs carry go.mod.

日本語の概要は準備中です。原文の説明を表示しています。

sazardev/networking-with-go582026年8月8日 更新

sazardev のスキルをすべて見る

このスキルの問題を報告する