AI-optimized browser automation CLI with context-efficient snapshots. Use for long autonomous sessions, self-verifying workflows, video recording, and cloud browser testing (Browserbase).
日本語の概要は準備中です。原文の説明を表示しています。
STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Output style: Follow
process/development-protocols/communication-standards.md— answer-first, plain language, no unexplained jargon, TL;DR on long responses.
Runs a structured STRIDE + OWASP security audit on a given scope. Produces a severity-ranked findings report. With --fix, applies fixes iteratively using the vc-autoresearch guard pattern.
| Mode | Invocation | Behavior |
|---|---|---|
| Audit only | /vc-security <scope> | Scan → categorize → report |
| Audit + Fix | /vc-security <scope> --fix | Scan → categorize → fix iteratively |
| Bounded fix | /vc-security <scope> --fix --iterations N | Limit fix iterations to N |
Expand the provided glob or full keyword into a file list. Read all in-scope files before analysis.
Evaluate each threat category systematically:
Map findings to OWASP categories (A01–A10). See references/stride-owasp-checklist.md for per-category checks.
Run the appropriate package audit tool for the detected stack:
pnpm auditpip-auditgovulncheckbundle auditScan for hardcoded API keys, passwords, tokens, and private keys using regex patterns. See references/stride-owasp-checklist.md → Secret Patterns.
Assign each finding a severity level (see Severity Definitions below).
## Security Audit Report
### Summary
- Files scanned: N
- Findings: X critical, Y high, Z medium, W low, V info
### Findings
| # | Severity | Category | File:Line | Description | Fix Recommendation |
|---|----------|----------|-----------|-------------|-------------------|
| 1 | Critical | Injection | api/users.ts:45 | SQL string concatenation | Use parameterized queries |
| 2 | High | Auth | auth/login.ts:12 | No rate limiting | Add express-rate-limit |
When --fix is provided, apply fixes iteratively after the audit:
security(fix-N): <short description>
d. Advance to next findingvc-autoresearch guard pattern for regression preventionTip: Use
--iterations Nto cap total fix iterations when scope is large.
| Severity | Description | Fix Priority |
|---|---|---|
| Critical | Exploitable now, data breach or RCE risk | Immediate — block release |
| High | Exploitable with moderate effort, significant impact | This sprint |
| Medium | Limited exploitability or impact | Next sprint |
| Low | Theoretical risk, defense-in-depth improvement | Backlog |
| Info | Best practice suggestion, no direct risk | Optional |
vc-predict when the security persona flags concernsvc-autoresearch --fix for automated remediationvc-scenario with --focus authorization for deeper auth flow testinggenerate-plan / plan-agent to schedule Medium/Low findings as sprint tasks# Audit API layer only
/vc-security src/api/**/*.ts
# Audit entire src/ and auto-fix, max 15 iterations
/vc-security src/ --fix --iterations 15
# Full codebase audit (no fix)
/vc-security full
See references/stride-owasp-checklist.md for the detailed per-category checklist and secret detection regex patterns.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
AI-optimized browser automation CLI with context-efficient snapshots. Use for long autonomous sessions, self-verifying workflows, video recording, and cloud browser testing (Browserbase).
日本語の概要は準備中です。原文の説明を表示しています。
Evaluate 4 execution strategies (sequential, parallel-subagents, workflow, agent-team) for a phase or fan-out task. Outputs 7-signal score table, agent count math, cost guards, and strategy recommendation.
日本語の概要は準備中です。原文の説明を表示しています。
Audit project context routing, shared-skill discoverability, and Claude/Codex wiring. Use when context docs or skill surfaces move, split, or drift.
日本語の概要は準備中です。原文の説明を表示しています。
Audit active project plan files for staleness, completion, and routing truth. Use when cleaning up plans, reconciling active work, or archiving completed artifacts.
日本語の概要は準備中です。原文の説明を表示しています。
Audit agent harness health: Claude/Codex agent parity, skill registry consistency, README.md sync, and protocol file wiring. Use when agents, skills, README.md, or development-protocol files move, split, or drift.
日本語の概要は準備中です。原文の説明を表示しています。
Emit and validate the provisional goal block for Autopilot Mode. Owns the 9-field format and resume detection from a pasted goal block.
日本語の概要は準備中です。原文の説明を表示しています。