本文へ移動
cccskills
無料GitHub で公開

drupal-security-review

Use when auditing Drupal 11 custom modules/themes for security issues such as unsafe input handling, XSS risks, SQL injection, and access control gaps.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Drupal Security Review Skill

Purpose

Use this skill to perform focused security reviews for Drupal 11 custom modules and themes.

When to apply

  • Reviewing pull requests before merge.
  • Auditing custom code for common web vulnerabilities.
  • Preparing release readiness checks.

Review checklist

  1. Input handling: Validate and sanitize all external input.
  2. Output escaping: Escape output in Twig and PHP render logic.
  3. Database safety: Use query builder or placeholders in all SQL operations.
  4. Access control: Confirm route, entity, and operation permissions are enforced.
  5. Secrets and config: Ensure credentials are never committed and sensitive config is protected.

Common anti-patterns to flag

  • Direct SQL string concatenation with user data.
  • Unescaped raw markup in render arrays.
  • Trusting $_GET, $_POST, or request payloads without validation.
  • Debug leftovers (var_dump, kint, dpm) in production paths.

Useful validation commands

rg "(var_dump|dpm\(|kint\()" web/modules/custom web/themes/custom
rg "\$_(GET|POST|REQUEST)" web/modules/custom web/themes/custom

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Safe deployment workflow for Drupal 10/11 sites: pre-flight checks, backup, the correct update sequence (composer install, database updates, config import, cache rebuild), verification, and rollback plan. Use when deploying to any environment, releasing to production, or when the user asks to "push changes live", "update the server", or run a release. Also use for multisite releases where each site needs its own database update pass.

日本語の概要は準備中です。原文の説明を表示しています。

siva01c/claude-plugins162026年9月26日 更新

Use this skill when authoring or editing Docker Compose files (compose.yaml / docker-compose.yml), running multi-container stacks, or containerizing a Drupal/PHP application — e.g. "set up a local Drupal stack with nginx and MariaDB", "add Redis to my compose file", "why won't my containers start", "split dev and prod compose configuration". Also trigger for compose commands (up, down, logs, exec, watch) and healthcheck/dependency issues between services.

日本語の概要は準備中です。原文の説明を表示しています。

siva01c/claude-plugins162026年9月26日 更新

Use this skill when running local AI models with Docker Model Runner — the `docker model` CLI — e.g. "run an LLM locally with Docker", "pull a model from the ai/ namespace", "connect my app to a local model", "use a local model as backend for the Drupal AI module", or when wiring the `models:` top-level element into a compose.yaml. Covers pulling/running models, OpenAI-compatible endpoints, and Compose integration.

日本語の概要は準備中です。原文の説明を表示しています。

siva01c/claude-plugins162026年9月26日 更新

Use for operational Drupal 11 workflows in DDEV environments, including safe updates, backup-first procedures, and troubleshooting commands.

日本語の概要は準備中です。原文の説明を表示しています。

siva01c/claude-plugins162026年9月26日 更新

Use when creating or extending Drupal 11 custom modules, including scaffolding, service architecture, and dependency injection best practices.

日本語の概要は準備中です。原文の説明を表示しています。

siva01c/claude-plugins162026年9月26日 更新

dry

無料

DRY (Don't Repeat Yourself) review rules for code reviews: find the same knowledge — a rule, a constant, a parser, a validation, a protocol detail — implemented in several places that must change together, and tell it apart from code that merely looks alike. Use when reviewing a diff, a pull request or recent changes for duplication, on "DRY review", "is this duplicated", "copy-paste check", or when a review checklist asks for DRY. Pair it with the solid skill for design and with owasp-asvs for security.

日本語の概要は準備中です。原文の説明を表示しています。

siva01c/claude-plugins162026年9月26日 更新

siva01c のスキルをすべて見る

このスキルの問題を報告する