安全性
2492 skills in 測試與安全 > 安全性
agentuity-cli-cloud-env-list
List all environment variables. Requires authentication. Use for Agentuity cloud platform operations
identity-access
Implement identity and access management. Use when designing authentication, authorization, or user management. Covers OAuth2, OIDC, and RBAC.
code-review
Review code for quality, security vulnerabilities, and best practices compliance
securityfilesystem
Filesystem Security security skill
go-web-apis
Build production REST APIs with Go - handlers, middleware, security
django-framework
Build production-ready web applications with Django MVC, ORM, authentication, and REST APIs
agentuity-cli-cloud-db-sql
Execute SQL query on a database. Requires authentication. Use for Agentuity cloud platform operations
agentuity-cli-cloud-keyvalue-keys
List all keys in a keyvalue namespace. Requires authentication. Use for Agentuity cloud platform operations
infra-validator
Validate infrastructure configuration - run Terraform validate, check syntax, verify resource configurations,validate security settings, and ensure compliance with best practices. Reports validation errors and warnings.
security-scan
Perform comprehensive security analysis to identify vulnerabilities.Integrates with codex-review for automatic security checks.Covers OWASP Top 10, common vulnerabilities, and secure coding practices.Output: Japanese
security-prompts-auth
Authentication and authorization prompt templates for RBAC implementation, permissions systems, ownership verification, and authorization testing. Use when setting up roles, implementing access control, or testing authorization logic. Triggers include "RBAC", "role-based access", "permissions", "ownership", "authorization", "access control", "user roles", "auth testing".
openapi-contract-validator
Validates Django REST Framework endpoints against OpenAPI specification. This skill should be used when implementing or modifying API endpoints to ensure request/response schemas, status codes, authentication, and parameters match the contract specification.
trivy
This skill should be used when scanning container images, filesystems, or repositories for vulnerabilities using Trivy. Use for CVE detection, security analysis, vulnerability comparison across image versions, understanding scan output (severity levels, status fields), and batch scanning multiple images.
securitythreat-model
Threat Modeling security skill
authentication-authorization-vulnerabilities-ai-code
Understand authentication and authorization defects in AI-generated code including insecure password storage, broken session management, and access control bypasses. Use this skill when you need to learn about auth vulnerabilities in AI code, understand why AI suggests MD5/plaintext passwords, recognize broken session patterns, or identify access control gaps. Triggers include "auth vulnerabilities AI", "password storage AI", "session management", "broken access control", "authentication defects", "MD5 passwords", "session hijacking", "authorization bypass".
security-scanning
CI security scanning: secrets, deps, SAST, triage, expiring exceptions
csrf-protection
Implement Cross-Site Request Forgery (CSRF) protection for API routes. Use this skill when you need to protect POST/PUT/DELETE endpoints, implement token validation, prevent cross-site attacks, or secure form submissions. Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation".
building-mcp-servers
Expert at integrating Model Context Protocol (MCP) servers into Claude Code plugins. Auto-invokes when the user wants to add external tool integrations, configure MCP servers, set up stdio/SSE/HTTP/WebSocket connections, or needs help with MCP authentication and security. Also auto-invokes proactively when Claude is about to write MCP configuration files (.mcp.json) or add mcpServers to plugin manifests.
agentuity-cli-cloud-sandbox-create
Create an interactive sandbox for multiple executions. Requires authentication. Use for Agentuity cloud platform operations
agentuity-cli-cloud-sandbox-snapshot-tag
Add or update a tag on a snapshot. Requires authentication. Use for Agentuity cloud platform operations