本文へ移動
cccskills
無料GitHub で公開

sec-security-vulnerability-engineer

Audit and remediate dependency/package vulnerabilities across .NET backend, frontend (npm/pnpm/yarn), and Rust projects with severity-based quality gates. Use when the user asks for SCA checks, dependency hardening, or release security gates.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security Vulnerability Engineer

Load context first

  1. .github/AGENTS.md
  2. .github/copilot-instructions.md
  3. .github/instructions/repository-operating-model.instructions.md

Instruction pack

  • .github/instructions/security-vulnerabilities.instructions.md
  • .github/instructions/ci-cd-devops.instructions.md (when pipeline/release gates are involved)
  • .github/instructions/dotnet-csharp.instructions.md (when .NET is in scope)
  • .github/instructions/frontend.instructions.md (when frontend is in scope)
  • .github/instructions/rust-testing.instructions.md (when Rust crates are in scope)

Claude-native execution

Run as a general-purpose agent within the Super Agent pipeline.

Execution workflow

  1. Identify impacted stacks: .NET backend, frontend, Rust.
  2. Run package vulnerability audits before any build/package step.
  3. Classify findings by severity and enforce fail thresholds.
  4. Apply minimal safe upgrades and rerun audits/tests.
  5. Report artifacts and residual risk explicitly.

Validation examples

pwsh -File ./scripts/validation/validate-security-baseline.ps1
pwsh -File ./scripts/validation/validate-release-provenance.ps1

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use for non-trivial, design-bearing, or architecture-affecting work before execution planning. Creates or updates a versioned spec under planning/specs/active/ with design intent, alternatives, risks, and acceptance criteria.

日本語の概要は準備中です。原文の説明を表示しています。

ThiagoGuislotti/copilot-instructions22026年6月29日 更新

Use for non-trivial feature, behavior, workflow, or architecture work before execution planning. Create or update a versioned spec under planning/specs/active with design intent, alternatives, risks, acceptance criteria, and planning readiness.

日本語の概要は準備中です。原文の説明を表示しています。

ThiagoGuislotti/copilot-instructions22026年6月29日 更新

Assembles the minimal context pack for a given task. Use when the task spans multiple domains or the context set has obvious redundancy. Do not trim required working context by default.

日本語の概要は準備中です。原文の説明を表示しています。

ThiagoGuislotti/copilot-instructions22026年6月29日 更新

Build a minimal context pack and recommend the correct specialist path for token-efficient execution. Use when the task is non-trivial, spans multiple domains, or should reduce token usage before implementation.

日本語の概要は準備中です。原文の説明を表示しています。

ThiagoGuislotti/copilot-instructions22026年6月29日 更新

Route tasks using this repository's static routing catalog and load only the minimal context pack.

日本語の概要は準備中です。原文の説明を表示しています。

ThiagoGuislotti/copilot-instructions22026年6月29日 更新

Route tasks using the repository's static routing catalog and load only the minimal context pack. Use before execution when the task spans multiple domains or the correct instruction set is unclear.

日本語の概要は準備中です。原文の説明を表示しています。

ThiagoGuislotti/copilot-instructions22026年6月29日 更新

ThiagoGuislotti のスキルをすべて見る

このスキルの問題を報告する