本文へ移動
cccskills
無料GitHub で公開

secure-code-write

Proactive secure-coding coach scoped to the file or topic you are working on — surfaces relevant SAST rule IDs, CWE patterns, language-specific PASS/FAIL code snippets. Use when about to write auth, crypto, SQL, deserialization, file-handling, or template code; coaching juniors; pair-programming a security-sensitive change.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md3.6 KB
  • evals/evals.json3.2 KB
  • evals/trigger-eval.json1.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Secure Code Write Skill

Use when

  • About to write authentication, crypto, SQL, deserialization, file-handling, or template code.
  • Coaching a junior on a new security-sensitive feature.
  • Pair-programming a security-sensitive change with a reviewer who wants to surface rules upfront.
  • Reviewing a PR and want the rule digest the author should have seen.
  • Cross-referencing the SAST rules that would fail BEFORE writing the code that triggers them.

Don't use for

  • Actually scanning code — use sast-scan.
  • Generic security advice — this skill is rule-grounded, not narrative.
  • Educating non-developer audiences — the rule digest is engineer-targeted.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

A coach, not a scanner. Use this when about to author auth, crypto, SQL, deserialization, file-handling, or templating code — surfaces the rules a reviewer would check, before you write the buggy version.

Step 1: Load capabilities + decide topic

Read .vulnetix/capabilities.yaml. Determine language from derived.primary_package_manager or the file extension of $ARGUMENTS.

If $ARGUMENTS is a topic keyword (auth, crypto, sql, xss, deser, file, template), use it directly. Else infer from file content (Read the file, look for keywords).

Step 2: Pull rule digest

vulnetix scan --list-default-rules -o json | jq '[.rules[] | select(.tags | contains([$topic]))]' --arg topic "$TOPIC"

Plus CWE intel:

vulnetix vdb cwe list --keyword "$TOPIC" -V v2 -o json

Step 3: Render coach

Secure-code coach: <topic> in <language>

Top rules to honor:
1. <rule-id>: <one-line summary>  (CWE-XXX)
2. ...

Common pitfalls:
- ...

Snippets that pass / fail:
PASS:
<code>

FAIL:
<code>

Tailor snippets to the detected language.

Step 4: Optional inline check

If the user is editing a file, offer:

Run `sast-scan --paths <file>` after I finish to confirm.

No memory writes

Coaching only.

Edge cases & gotchas

  • Topic detection from file content uses keyword heuristics — be explicit (--topic crypto) if working with mixed-concern code.
  • Rule digest is vulnetix scan --list-default-rules filtered by tag; the rule set updates with the CLI release, not per-org policy.
  • PASS/FAIL snippets are language-tailored from derived.primary_package_manager. JVM-stack repos with both Java and Kotlin may get snippets in only one.
  • vdb cwe <id> -V v2 returns CWE-specific defensive guidance — use it for educational follow-up, not as the rule source.
  • No memory writes — this is read-only coaching.
  • For green-field projects without a lockfile, the language detection falls back to --topic; pass explicitly.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する